712-50 exam dumps

712-50 practice question 370 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 370

Single answerDevelop guidelines to determine whether a security incident is indicative of a violation of law that requires special legal action

A global manufacturer’s SOC detects that an employee in the finance department used valid credentials to access payroll records for 3,000 employees outside normal working hours. Within minutes, the same account compressed the records and sent them to a personal webmail address. The employee is based in a country with strict employee privacy laws, and some of the affected records belong to staff in the EU and the United States. The CEO wants the CISO to decide whether this incident should be handled as an internal policy violation only or escalated for special legal action. Which action should the CISO include in the incident classification guideline to make that determination most effectively?

  1. A

    Require legal counsel review when an incident involves indicators of criminal conduct, regulated personal data, cross-border impact, or a need to preserve evidence for potential law-enforcement or litigation use

  2. B

    Classify any incident caused by a current employee as an HR matter first, and involve legal counsel only after HR completes its internal investigation

  3. C

    Escalate to law enforcement only when the financial loss exceeds a predefined threshold, because smaller incidents are unlikely to qualify as legal violations

  4. D

    Treat incidents using valid credentials as non-criminal unless malware or external attackers are involved, since authorized access typically does not trigger special legal action

Show answer and explanation

Correct answer: A

Explanation

The best guideline is one that identifies legal-escalation triggers based on the character of the incident rather than simplistic factors such as employee status, malware presence, or loss amount. In practice, a CISO should ensure incident classification criteria include: suspected criminal acts such as theft, fraud, sabotage, or unauthorized disclosure; incidents involving regulated or sensitive data; cross-border data subjects or systems; employment and privacy-law considerations; and situations requiring defensible evidence preservation for litigation or law enforcement. In this case, payroll data contains personal information, the actor appears to have intentionally exfiltrated it, and the incident spans multiple jurisdictions, all of which strongly support immediate legal review. This is consistent with widely recognized incident response and governance practices, including NIST SP 800-61 guidance to involve legal counsel in incidents with potential legal implications, and with general privacy compliance principles requiring organizations to assess breach notification, jurisdictional obligations, and chain-of-custody requirements early in the response.

  • A. Correct.

    Correct. A sound guideline should trigger legal review based on legal-risk indicators, not just technical severity. Indicators such as suspected theft or fraud, misuse of personal data, insider misuse, cross-border data transfer, privacy and employment-law implications, and the need for forensic evidence preservation are precisely the factors that may make an incident a violation of law requiring special legal action. In this scenario, potential unauthorized disclosure of payroll data, insider misconduct, and multiple jurisdictions all make early legal involvement essential. This approach aligns with common incident response best practices, including involving counsel to determine notification obligations, law-enforcement engagement, privilege strategy, and evidence handling requirements.

  • B. Incorrect.

    Incorrect. This reflects a common misconception that insider incidents are primarily HR issues. While HR may need to participate, delaying legal review until after an HR investigation can jeopardize evidence integrity, create employment-law issues, and miss breach-notification or criminal-referral obligations. Insider misuse involving regulated personal data and exfiltration may require immediate legal assessment in parallel with HR, not after it.

  • C. Incorrect.

    Incorrect. Financial impact alone is not the correct threshold for legal escalation. Many incidents require special legal action because of the nature of the data, the actor’s intent, statutory obligations, or jurisdictional issues, even if direct monetary loss is unclear or initially low. For example, privacy-law obligations and potential criminal misconduct may apply regardless of the immediate dollar amount.

  • D. Incorrect.

    Incorrect. The use of valid credentials does not make an act non-criminal or purely administrative. Authorized access can become unauthorized use when the user exceeds permitted purpose or violates law or policy, such as stealing personal data or committing fraud. Insider exfiltration of payroll records can create criminal, privacy, labor, and civil liability issues even without malware or an external attacker.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam