712-50 exam dumps

712-50 practice question 63 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 63

Single answer

A newly appointed CISO is asked by the board audit committee to redesign the annual IT audit plan after the company experienced a ransomware incident originating from a third-party remote access connection. The organization has limited internal audit capacity, a rapidly expanding cloud footprint, and several business-critical applications supporting revenue recognition and customer data processing. Previous audit plans were largely cyclical, giving similar coverage to all systems each year. To design a more effective risk-based IT audit strategy, which action should the CISO take FIRST?

  1. A

    Prioritize audit coverage by performing a formal risk assessment that maps critical business processes, key assets, threat exposure, control maturity, recent incidents, and regulatory impact

  2. B

    Schedule immediate technical audits of every internet-facing system and all cloud workloads because these are the most likely attack paths

  3. C

    Retain the existing rotational audit plan but add one targeted review of third-party remote access controls to address the recent incident

  4. D

    Begin by selecting audit procedures from prior years so the team can preserve year-over-year consistency in control testing

Show answer and explanation

Correct answer: A

Explanation

The key principle in a thorough risk-based IT audit strategy is that audit universe, scope, and frequency should be driven by risk to the business rather than by rotation, convenience, or only the latest incident. In this scenario, the organization has constrained resources, increased cloud adoption, critical applications, and a third-party-related security event. The best first step is to perform a formal risk assessment that ranks audit candidates using factors such as business criticality, inherent risk, control maturity, results of prior audits, threat intelligence, incident history, regulatory obligations, and reliance on vendors. This enables the CISO to justify the audit plan to the board and align assurance work with enterprise risk management. This approach is consistent with recognized practices from ISACA on risk-based audit planning, COBIT governance and management objectives related to risk optimization and assurance, and NIST risk management guidance emphasizing asset categorization, risk assessment, and control evaluation before assurance prioritization.

  • A. Correct.

    This is correct because a risk-based IT audit strategy should begin with a structured risk assessment tied to business objectives and risk drivers, not with predetermined audit subjects. Mapping critical processes, systems, data, threats, control maturity, prior incidents, third-party dependencies, and compliance obligations allows the CISO to allocate scarce audit resources to the areas of highest residual risk. This approach aligns with established audit practice in frameworks such as ISACA's risk-based audit planning guidance, COBIT's governance focus on enterprise goals and risk optimization, and NIST concepts of categorizing assets and assessing risk before selecting assurance activities.

  • B. Incorrect.

    This is incorrect because it jumps directly to a technical focus based on likely attack surface without first determining enterprise-wide risk priorities. Internet-facing and cloud systems may be important, but the audit plan must be driven by business impact and residual risk, not just exposure. This option reflects a common misconception that the most externally exposed assets should automatically dominate the audit plan, even when financial systems, privileged access processes, or third-party governance may present equal or greater organizational risk.

  • C. Incorrect.

    This is incorrect because adding a single review to an otherwise cyclical plan does not fundamentally redesign the audit strategy into a risk-based one. It overweights the most recent incident without considering whether other areas now carry greater residual risk due to business criticality, control weakness, cloud expansion, or regulatory requirements. This is a common error known as recency bias, where recent events disproportionately drive planning decisions.

  • D. Incorrect.

    This is incorrect because reusing prior-year procedures may support efficiency later in the planning process, but it should not be the first step in establishing audit priorities. Consistency has value for trend analysis, yet a risk-based plan must first determine what should be audited and why. Starting with legacy procedures risks perpetuating outdated scope and may fail to address changes in architecture, threat landscape, outsourcing, or cloud adoption.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam