712-50 exam dumps

712-50 practice question 394 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 394

Single answer

A global manufacturing company is modernizing its business by moving several customer-facing applications to the cloud, connecting factory IoT systems to corporate analytics platforms, and integrating a recently acquired subsidiary into the enterprise network. The board has approved a security strategy centered on protecting intellectual property, maintaining production uptime, and meeting regional regulatory obligations. The CISO finds that business units are selecting technologies independently, network segmentation is inconsistent across sites, and security controls are being added late in projects, causing delays and exceptions. Which action should the CISO take FIRST to design and maintain an effective enterprise information security architecture (EISA) aligned with the organization's strategy?

  1. A

    Develop an enterprise security architecture framework that maps business processes, critical assets, trust zones, and target-state security principles to technology standards and project governance

  2. B

    Purchase a single enterprise security platform to standardize controls quickly across cloud, factory networks, and the acquired subsidiary

  3. C

    Require each business unit to perform its own risk assessment and implement compensating controls based on local operational needs

  4. D

    Begin a companywide penetration testing program to identify the most urgent weaknesses before defining architecture standards

Show answer and explanation

Correct answer: A

Explanation

The best first step is to create a business-aligned enterprise security architecture framework and governance approach. In CCISO practice, EISA is not just about selecting controls; it is about ensuring business processes, software, hardware, networks, people, operations, and projects are aligned to the enterprise security strategy. In this scenario, the root cause is architectural fragmentation: independent technology selection, inconsistent segmentation, and late security involvement. A target-state architecture defines security principles, reference architectures, trust zones, asset criticality, integration patterns, and mandatory standards for initiatives such as cloud adoption, OT/IoT connectivity, and M&A onboarding. This provides a repeatable basis for project review and exception handling. Relevant best practices include SABSA for business-driven security architecture, TOGAF for architecture governance, NIST SP 800-160 for engineering trustworthy secure systems, NIST Cybersecurity Framework for aligning business outcomes to security outcomes, and Zero Trust guidance such as NIST SP 800-207 for defining trust boundaries and access principles. Once the architecture is defined, the organization can select technologies, conduct targeted assessments, and validate implementations in a way that is consistent with enterprise objectives.

  • A. Correct.

    This is correct because an enterprise information security architecture should begin with a business-aligned target state, not isolated technology decisions. Mapping business processes, crown-jewel assets, trust boundaries, and regulatory drivers to architecture principles allows the CISO to align people, operations, networks, platforms, and projects under one governance model. It also helps embed security early in initiatives such as cloud migration, OT/IoT integration, and M&A integration. This is consistent with enterprise architecture and security architecture practices such as SABSA's business-driven approach, TOGAF-style architecture governance, and NIST concepts of integrating security into system development and enterprise risk management.

  • B. Incorrect.

    This is incorrect because tool standardization can be useful, but buying a platform first is a technology-led response rather than an architecture-led one. A single platform may not address the different requirements of cloud workloads, operational technology environments, acquired networks, and regulatory obligations. Without defined architecture principles, trust zones, integration patterns, and governance, the organization may simply automate inconsistency at scale.

  • C. Incorrect.

    This is incorrect because decentralized risk assessments alone will likely reinforce the current fragmentation. Business units may optimize for local priorities rather than enterprise objectives such as IP protection, uptime, and regulatory consistency. While local risk input is important, the CISO's first priority is to establish an overarching architecture and governance model so that local decisions fit within enterprise standards and acceptable variation.

  • D. Incorrect.

    This is incorrect because penetration testing identifies vulnerabilities in existing implementations, but it does not establish the architectural blueprint needed to align future business transformation with security strategy. Testing can support prioritization later, but if done first, it risks producing a list of tactical issues without solving the root problem of inconsistent design, segmentation, and late-stage security integration.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam