712-50 exam dumps

712-50 practice question 62 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 62

Single answer

A newly appointed CISO at a global manufacturing company is redesigning the IT audit approach after two recent incidents: an ERP configuration change caused incorrect financial reporting, and a third-party remote access pathway was used to move laterally into the production network. Internal audit currently follows a fixed annual schedule that gives equal coverage to all systems, regardless of business impact. The board has asked for a risk-based IT audit strategy that will provide better assurance over the most significant technology and application risks. Which action should the CISO take FIRST to design the most effective audit strategy?

  1. A

    Build the audit plan around the systems with the highest inherent and residual risk by mapping critical business processes, key applications, privileged access paths, recent incidents, and regulatory obligations before defining audit scope and frequency

  2. B

    Increase the frequency of all existing audits from annual to quarterly so that control failures are detected earlier across the environment

  3. C

    Prioritize audits of systems that had findings in the previous year because repeat issues are the strongest predictor of future control weakness

  4. D

    Start with technical vulnerability scans and penetration tests across all internet-facing assets, then use the scan results as the primary basis for the enterprise IT audit strategy

Show answer and explanation

Correct answer: A

Explanation

The best first step in designing a thorough risk-based IT audit strategy is to establish and rank the audit universe according to business and technology risk. In practice, this means identifying critical processes and assets, understanding how applications and infrastructure support those processes, evaluating threat exposure and control maturity, and incorporating inputs such as incident trends, major changes, external dependencies, and regulatory requirements. Only then should audit scope, objectives, methodology, and frequency be set. This aligns with widely accepted audit principles reflected in ISACA risk-based audit planning practices, the IIA Standards' emphasis on risk-based internal audit planning, and control frameworks such as COBIT and NIST guidance that tie assurance activities to enterprise risk and business objectives. In the scenario, a uniform annual plan failed because it ignored where the organization's risk was actually concentrated: ERP change control and third-party access into sensitive environments.

  • A. Correct.

    Correct. A risk-based IT audit strategy should begin with understanding the business context and risk universe, then ranking auditable entities based on factors such as business criticality, threat exposure, control maturity, change activity, incident history, third-party dependency, privileged access, and compliance requirements. In this scenario, the recent ERP change failure and third-party access incident indicate elevated risk in change management, identity/access management, network segmentation, and vendor connectivity. Mapping these to critical business processes and applications allows the CISO to define scope, timing, and depth of audits based on risk rather than a uniform cycle.

  • B. Incorrect.

    Incorrect. Increasing all audits to quarterly changes frequency but does not make the program risk-based. It also misallocates limited audit resources by giving low-risk systems the same attention as high-risk systems. A mature risk-based strategy adjusts coverage according to risk, not simply calendar cadence.

  • C. Incorrect.

    Incorrect. Prior-year findings are an important input to risk assessment, but they are only one factor. New systems, major changes, third-party connections, business-critical applications, and emerging threats may present greater risk than areas with historical findings alone. Using prior findings as the main driver would be too narrow for enterprise audit planning.

  • D. Incorrect.

    Incorrect. Vulnerability scans and penetration tests are useful assessment techniques, but they are not sufficient as the primary basis for an IT audit strategy. A thorough risk-based audit strategy must also address governance, application controls, change management, logical access, third-party risk, data integrity, and process-level controls. Technical testing should support, not replace, enterprise risk assessment and audit planning.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam