712-50 exam dumps

712-50 practice question 368 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 368

Single answerDesign incident response procedures including testing, tabletop exercises, and playbooks

A newly appointed CISO is redesigning the organization's incident response capability after a ransomware event exposed major coordination failures. During the incident, technical teams knew how to isolate hosts, but executives, legal counsel, HR, and communications staff were unclear on decision authority, notification thresholds, and external messaging. The CISO has budget for only one major improvement this quarter and wants the change most likely to improve cross-functional readiness for a future high-impact cyber incident. Which action should the CISO prioritize first?

  1. A

    Develop role-based incident playbooks for key scenarios and validate them through cross-functional tabletop exercises involving executive leadership and business stakeholders

  2. B

    Acquire a new endpoint detection and response platform so the security operations team can automate containment decisions during future incidents

  3. C

    Require all incident responders to complete advanced malware reverse-engineering training before the next annual audit

  4. D

    Increase the frequency of vulnerability scanning and patching to reduce the chance of another ransomware infection

  5. E

    Outsource all external communications to a public relations firm and allow them to make breach notification decisions during incidents

Show answer and explanation

Correct answer: A

Explanation

The best choice is to build role-based incident playbooks and test them through cross-functional tabletop exercises. In mature incident response programs, playbooks translate policy into actionable procedures for specific scenarios, defining triggers, roles, decision points, escalation paths, communications, evidence handling, and recovery steps. Tabletop exercises are then used to validate whether the procedures are practical, whether stakeholders understand their responsibilities, and whether gaps exist in authority, coordination, or communications. This is especially important for executive, legal, HR, privacy, and public affairs participants, whose decisions significantly affect regulatory compliance, business continuity, and reputational outcomes.

This approach aligns with recognized best practices such as NIST SP 800-61 Rev. 2, which emphasizes establishing incident response plans, clearly defined roles and responsibilities, communication and reporting structures, and exercising the capability regularly. It also aligns with SANS incident response guidance and common crisis management practice, where scenario-specific playbooks and tabletop exercises improve readiness more effectively than isolated technical improvements when the main weakness is organizational coordination.

In this scenario, the organization already had technical responders capable of isolating hosts. The documented failure was decision authority and coordination among nontechnical stakeholders. Therefore, the CISO should first address process maturity and exercise discipline rather than prioritize new tools or narrow technical training.

  • A. Correct.

    Correct. The core failure described is not primarily a lack of technical tooling, but weak coordination, unclear roles, and poor decision-making across business functions. Role-based playbooks define responsibilities, escalation paths, approval authorities, communication workflows, and decision criteria for specific scenarios such as ransomware, data breach, or business email compromise. Tabletop exercises then test whether those procedures actually work under realistic conditions and expose gaps before a real event occurs. This directly addresses the identified weaknesses in governance, communication, and incident command.

  • B. Incorrect.

    Incorrect. Better detection and containment tooling may improve technical response speed, but it does not solve the stated issue: executives, legal, HR, and communications did not understand their roles or decision authority. A common misconception is to respond to an incident primarily with more technology, when the more serious problem is often process and coordination. Tools support incident response, but they do not replace tested procedures and cross-functional rehearsals.

  • C. Incorrect.

    Incorrect. Specialized reverse-engineering training may benefit a small subset of analysts, but it is not the highest-priority control for an organization whose main failure was enterprise-wide coordination. This option overemphasizes deep technical skill at the expense of governance and crisis management. In a ransomware scenario, many of the most critical decisions involve legal, operational, and executive judgment rather than malware analysis alone.

  • D. Incorrect.

    Incorrect. Improving vulnerability management is valuable for prevention, but the question asks for the action most likely to improve readiness for a future high-impact incident. Incident response readiness focuses on preparation to detect, coordinate, decide, communicate, and recover when prevention fails. This option addresses risk reduction, not the observed breakdown in incident response procedures and stakeholder alignment.

  • E. Incorrect.

    Incorrect. External communications support can be useful, but delegating breach notification decisions to a PR firm is inappropriate because such decisions typically require legal, regulatory, executive, and incident leadership input. Public relations should not own notification thresholds or legal determinations. This option reflects a misunderstanding of governance and accountability in incident response.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam