712-50 exam dumps

712-50 practice question 369 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 369

Single answerDesign incident response procedures including testing, tabletop exercises, and playbooks

A newly appointed CISO is redesigning the organization's incident response program after a ransomware event exposed several weaknesses. During the incident, technical teams knew how to isolate systems, but business leaders were unclear on who could authorize shutdown of critical services, legal counsel was engaged too late, and external communications were inconsistent. The CISO wants to improve both the procedures and the organization's readiness to execute them. Which action should the CISO prioritize FIRST to create an effective and testable incident response capability?

  1. A

    Develop scenario-specific playbooks that define decision points, roles, escalation paths, and communication triggers, then validate them through tabletop exercises involving technical, legal, HR, executive, and communications stakeholders

  2. B

    Purchase a new SOAR platform so the security operations team can automate containment steps before revising policies and procedures

  3. C

    Mandate quarterly penetration tests focused on ransomware techniques to ensure the incident response team can detect every possible attack path

  4. D

    Require every business unit to create its own standalone incident response process so each department can act independently during an incident

Show answer and explanation

Correct answer: A

Explanation

The best answer is to prioritize scenario-based playbooks and validate them through cross-functional tabletop exercises. In mature incident response programs, the incident response plan provides overarching governance, while playbooks provide operational guidance for specific scenarios such as ransomware, business email compromise, insider threat, or cloud compromise. The scenario indicates that the root problem is not merely lack of technical response capability, but lack of predefined authority, coordination, and communication. Tabletop exercises are especially valuable because they test assumptions, dependencies, and decision rights without the cost and disruption of live simulations. They also surface issues around executive involvement, legal review, regulatory reporting, customer notification, crisis communications, and business continuity coordination. This approach is consistent with NIST SP 800-61 Rev. 2, which emphasizes incident response policy, plans, procedures, and training/exercises, and with common practices in SANS incident handling guidance and ISO/IEC 27035, which stress documented procedures, roles, communications, and continual improvement through testing. From a CCISO perspective, the CISO's first priority should be designing a governed, repeatable, and testable response capability that integrates business and technical stakeholders rather than focusing first on tools or isolated technical assessments.

  • A. Correct.

    Correct. The scenario highlights governance and coordination failures rather than only technical deficiencies. Scenario-specific playbooks translate the high-level incident response plan into actionable steps for common incidents such as ransomware, including authority to make decisions, escalation criteria, legal and regulatory engagement, and internal/external communications. Validating these playbooks through tabletop exercises with cross-functional stakeholders is the most effective first step because it tests whether roles, decision rights, and dependencies work in practice. This aligns with established guidance from NIST SP 800-61 on incident response planning and exercising, and with good executive-level governance expected in CCISO contexts.

  • B. Incorrect.

    Incorrect. SOAR can improve speed and consistency for some operational steps, but automation does not fix unclear decision authority, legal escalation gaps, or communication breakdowns. Implementing tooling before defining procedures risks automating incomplete or poorly governed processes. A CISO should first establish and validate the playbooks and decision model, then determine where automation adds value.

  • C. Incorrect.

    Incorrect. Penetration testing can help identify technical weaknesses and improve detection engineering, but it is not the best first action for the problems described. The organization already demonstrated difficulty with executive decisions, legal involvement, and communications management during the incident. Those are better addressed through incident response design, playbooks, and exercises rather than adversarial technical testing alone.

  • D. Incorrect.

    Incorrect. Department-specific standalone processes typically create inconsistency, conflicting decisions, and fragmented communications during enterprise incidents. While business units may need tailored procedures or contact lists, they should operate within a centrally governed incident response framework with common escalation, reporting, and communication standards. Independent processes would likely worsen the coordination issues exposed by the ransomware event.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam