712-50 exam dumps

712-50 practice question 371 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 371

Single answerDevelop guidelines to determine whether a security incident is indicative of a violation of law that requires special legal action

A global manufacturing company discovers that a senior engineer used approved remote access tools to download large volumes of proprietary design files to a personal cloud storage account over several weeks. Initial review shows the employee recently accepted a role with a direct competitor in another country. The incident response team has contained access and preserved system logs, but executives are divided on whether this should be handled purely as an internal HR matter or escalated for legal action. As the CISO, which guideline should you establish as the PRIMARY decision criterion for determining whether the incident is indicative of a legal violation requiring special legal action?

  1. A

    Escalate when there is a reasonable indication that the incident involves unlawful acts such as theft of intellectual property, fraud, privacy violations, or other offenses, and ensure legal counsel directs preservation, reporting, and law-enforcement coordination

  2. B

    Escalate only after the internal investigation proves beyond doubt that criminal intent existed and the employee successfully used the stolen information at the competitor

  3. C

    Escalate only if the financial loss already exceeds the organization’s preapproved materiality threshold for regulatory disclosure

  4. D

    Escalate whenever a security incident involves a privileged user, because privileged access alone is sufficient evidence of a criminal violation

Show answer and explanation

Correct answer: A

Explanation

In CCISO practice, the CISO should define incident classification guidelines that distinguish ordinary policy violations from matters that may require special legal action. The key principle is early escalation to legal counsel when available facts indicate potential criminal, civil, regulatory, contractual, employment, or cross-border legal implications. In the scenario, indicators include exfiltration of proprietary data, possible trade secret theft, insider threat behavior, and movement of data to personal storage before joining a competitor. Those facts are enough to warrant legal review even if the full motive and damages are not yet proven.

A sound guideline typically includes triggers such as suspected intellectual property theft, fraud, privacy or data protection violations, insider abuse, extortion, destruction of evidence, incidents involving protected or regulated data, and cases with cross-jurisdictional elements. It should also specify that legal counsel oversees matters such as litigation hold, chain of custody, privilege, employee interview strategy, notification obligations, and decisions about law-enforcement engagement. This approach is consistent with generally accepted incident response guidance, including NIST SP 800-61 Computer Security Incident Handling Guide, which emphasizes coordination with legal counsel and law enforcement where appropriate, and with common enterprise governance practices for preserving evidence and managing regulatory exposure.

  • A. Correct.

    Correct. The most defensible guideline is to trigger legal review when facts reasonably suggest the incident may constitute a violation of law, not only a policy breach. In this scenario, potential trade secret theft, unauthorized exfiltration, cross-border issues, employment law implications, and possible referral to law enforcement all justify immediate legal involvement. Legal counsel should guide evidence handling, privilege, preservation notices, jurisdictional analysis, notification obligations, and contact with law enforcement or regulators. This aligns with common incident response best practices, which distinguish between operational containment and legal assessment when criminal, civil, contractual, or regulatory exposure may exist.

  • B. Incorrect.

    Incorrect. Requiring proof beyond doubt is far too high a threshold for escalation and would delay necessary legal action. Organizations should involve counsel when there is credible evidence of potential illegality, especially where evidence could be lost, disclosure obligations could be triggered, or law-enforcement coordination may be beneficial. Waiting until criminal intent and downstream use are conclusively proven risks spoliation, mishandled interviews, loss of privilege, and missed reporting windows.

  • C. Incorrect.

    Incorrect. Financial materiality for public disclosure or internal reporting is not the primary criterion for deciding whether an incident may involve a legal violation. Some incidents require legal action even before losses are quantified, such as theft of trade secrets, unauthorized access, privacy breaches, sanctions issues, insider misconduct, or extortion. Limiting escalation to a monetary threshold confuses legal exposure analysis with financial reporting thresholds.

  • D. Incorrect.

    Incorrect. Privileged access may increase risk and the potential impact of an incident, but it does not by itself establish that a law has likely been violated. A privileged user may be involved in policy violations, negligence, or authorized administrative activity that appears suspicious initially. The guideline should focus on indicators of unlawful conduct and legal exposure, not the user’s role alone.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam