712-50 exam dumps

712-50 practice question 367 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 367

Single answerDiagnose and resolve IA problems in response to reported incidents

A global manufacturer's security operations center reports that several engineers can no longer access a product design repository that contains export-controlled technical data. At the same time, SIEM alerts show a service account authenticated successfully from an unusual geographic location and then modified access control lists on the repository. The CISO is informed that production deadlines depend on restoring access quickly, but legal counsel warns that the incident may involve both unauthorized disclosure and integrity issues. As the executive overseeing incident response, what is the MOST appropriate immediate course of action to diagnose and resolve the information assurance problem while preserving the organization's ability to investigate and meet compliance obligations?

  1. A

    Restore the last known-good access control configuration immediately so engineers can resume work, and investigate the suspicious activity after operations stabilize

  2. B

    Disable the affected service account, isolate the repository and related identity systems from further administrative changes, preserve relevant logs and system images, and initiate a prioritized impact assessment before restoring access

  3. C

    Force password resets for all engineering staff and publicly revoke all active sessions across the enterprise because credential compromise is the most likely explanation

  4. D

    Shut down the entire design environment and rebuild all repository servers from backup to eliminate any chance of continued attacker presence

Show answer and explanation

Correct answer: B

Explanation

The key leadership task in this scenario is to diagnose and resolve an information assurance problem in a way that addresses confidentiality, integrity, and availability simultaneously. The reported symptoms include loss of authorized access, suspicious privileged authentication, and ACL changes. That combination suggests more than an operational outage; it indicates a likely security incident involving identity misuse and possible unauthorized disclosure or tampering. The most appropriate immediate response is to contain the likely attack path, preserve evidence, and assess impact before recovery actions change the environment. This approach is consistent with established incident response guidance such as NIST SP 800-61 Rev. 2, which emphasizes containment, evidence handling, analysis, and carefully managed recovery, and with NIST SP 800-53 control families related to incident response, audit logging, and access control. Because the repository contains export-controlled technical data, legal and regulatory considerations make forensic preservation especially important. A CISO should avoid reflexively restoring service or executing enterprise-wide resets without first confirming scope, preserving records, and coordinating technical, legal, and business priorities.

  • A. Incorrect.

    This is not the best immediate action because it prioritizes availability over containment and evidence preservation. Although restoring access may reduce business disruption, making changes before scoping the incident can destroy forensic evidence, mask attacker actions, and potentially re-enable unauthorized access if the malicious service account or related pathways remain active. In an incident with possible confidentiality and integrity impact, the first executive decision should support containment, preservation, and validated recovery rather than rapid rollback alone.

  • B. Correct.

    This is the best answer because it balances incident containment, evidence preservation, and business restoration planning. Disabling the suspicious service account addresses the most likely unauthorized access vector. Isolating the repository and related identity administration paths prevents additional ACL tampering. Preserving logs and system images supports forensic analysis, legal review, and compliance obligations. A prioritized impact assessment helps determine whether the issue is limited to access denial, includes data exposure, or also involves integrity compromise. This sequence aligns with widely accepted incident response practice: contain first, preserve evidence, analyze scope and impact, then recover in a controlled manner.

  • C. Incorrect.

    This is plausible but too broad and not sufficiently targeted. Password resets and session revocations may be part of later remediation, especially if credential theft is confirmed, but the scenario specifically identifies a service account performing suspicious administrative changes. Resetting all engineering users may create significant disruption without addressing the compromised privileged account or preserving the current state for investigation. It also risks delaying focused diagnosis of the actual control failure.

  • D. Incorrect.

    This is an overly disruptive response at this stage. Full shutdown and rebuild may be warranted if widespread compromise is confirmed, but the scenario does not yet establish that all repository servers are compromised. Prematurely rebuilding can destroy volatile evidence, increase downtime, and complicate determination of whether export-controlled data was viewed or exfiltrated. Executive leadership should direct proportionate containment and evidence preservation before undertaking broad eradication measures.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam