712-50 exam dumps

712-50 practice question 435 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 435

Single answer

A global enterprise is procuring a managed endpoint detection and response (EDR) service and supporting agent software for deployment across regulated business units. The CISO has found that previous contracts focused heavily on price and functionality, but lacked clear criteria for security testing, delivery acceptance, and handling of unresolved weaknesses. As the executive responsible for improving contract administration policy, which action would BEST ensure that delivered security products and services are evaluated and accepted in a way that reduces procurement risk and supports accountability?

  1. A

    Require the contract to include measurable security acceptance criteria, evidence obligations from the supplier, and a formal process for conditional acceptance or rejection based on testing results and remediation timelines.

  2. B

    Rely on the vendor's SOC 2 report and industry reputation as the primary basis for acceptance, since independent attestations reduce the need for organization-specific security validation.

  3. C

    Defer all technical security evaluation activities until after production deployment so operational teams can assess the product in the live environment with full functionality enabled.

  4. D

    Accept the product once the legal team confirms contract terms are satisfied, and address any security gaps through future change requests and compensating controls.

Show answer and explanation

Correct answer: A

Explanation

The best answer is Option 1 because an effective contract administration policy for IT security procurement must define how delivered products and services will be evaluated, what evidence is required, who approves acceptance, and what happens when security requirements are only partially met. Strong policies typically include: pre-defined security requirements in the solicitation and contract, supplier evidence requirements, test and validation procedures, acceptance thresholds, exception handling, remediation timelines, and documented roles for procurement, security, legal, and service owners. This approach supports accountability and preserves leverage before final acceptance. Relevant best practices are reflected in NIST SP 800-161 on supply chain risk management, NIST SP 800-53 controls related to acquisition and supply chain protection such as SA and SR families, and general supplier governance practices in ISO/IEC 27001 and ISO/IEC 27036. These sources emphasize integrating security into acquisition, validating delivered components and services against defined requirements, and managing supplier risk through documented criteria rather than relying solely on trust, reputation, or post-deployment fixes.

  • A. Correct.

    Correct. This is the strongest contract administration approach because it establishes objective, auditable acceptance criteria before delivery and ties acceptance to evidence rather than vendor assurances. In practice, this should include required security documentation such as architecture and data flow details, secure development and vulnerability management evidence, results of agreed testing, remediation thresholds, service-level expectations, and explicit acceptance gates. A formal process for conditional acceptance is especially important when some deficiencies are identified but can be tolerated temporarily under documented risk treatment and remediation deadlines. This aligns with sound procurement governance and supplier assurance practices.

  • B. Incorrect.

    Incorrect. A SOC 2 report or similar attestation can be a useful input, but it is not a substitute for contract-specific security evaluation and acceptance criteria. Such reports are point-in-time or period-based assessments scoped by the vendor and may not address the enterprise's exact deployment model, regulatory obligations, integration risks, or product-specific weaknesses. This option reflects the common misconception that third-party assurance automatically satisfies internal acceptance requirements.

  • C. Incorrect.

    Incorrect. Deferring security evaluation until after production deployment creates avoidable exposure and weakens the organization's acceptance leverage. Security evaluation should occur before final acceptance and, where feasible, before production use, through activities such as document review, configuration validation, test environment assessment, and verification of remediation commitments. Production deployment should not be the first meaningful security checkpoint for procured security technology.

  • D. Incorrect.

    Incorrect. Legal sufficiency of contract terms does not prove that the delivered product or service meets security requirements. Acceptance should be based on fulfillment of contractual security obligations and verification of controls, not merely execution of paperwork. Relying on future change requests and compensating controls after acceptance reduces accountability, can increase cost, and may leave the organization operating with unassessed or unmitigated risk.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam