712-50 exam dumps

712-50 practice question 65 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 65

Single answer

A newly appointed CISO receives an internal audit report on the organization's identity and access management (IAM) controls for several business-critical systems. The audit was performed using a risk-based audit plan aligned to established audit standards, and the report notes that 18% of sampled privileged accounts had no documented quarterly access review, while all sampled accounts required multi-factor authentication and showed no evidence of unauthorized use. The audit criteria require quarterly recertification of privileged access by system owners. Business leaders argue that because there is no sign of compromise, the issue should be classified as low priority and addressed during the next annual review cycle. What is the MOST appropriate action for the CISO?

  1. A

    Accept the business leaders' position because the control appears operationally effective and no incident has occurred

  2. B

    Reclassify the finding as an observation rather than a control deficiency because compensating controls exist

  3. C

    Treat the issue as a control design or operating effectiveness deficiency against defined criteria, assess the risk of unauthorized or excessive access, and require timely remediation with management action plans

  4. D

    Delay remediation until a larger sample confirms whether the exception rate exceeds materiality thresholds used in financial audits

Show answer and explanation

Correct answer: C

Explanation

The key skill being tested is the ability to execute and interpret the audit process in accordance with established standards and evaluate results against defined criteria, rather than against outcome bias such as whether a breach happened. In this scenario, the audit criterion is explicit: privileged access must be reviewed quarterly by system owners. Failure to meet that criterion for 18% of the sample indicates a control weakness in governance and operating effectiveness. A CISO should not dismiss such a finding simply because MFA is in place or because there has been no known incident.

This approach is consistent with generally accepted audit and control practices reflected in frameworks such as ISACA audit guidance, the IIA's risk-based internal audit principles, and control frameworks like COBIT and NIST SP 800-53. For example, NIST access control guidance emphasizes periodic review of accounts and privileges, especially for privileged users. Effective audit interpretation requires assessing whether controls are designed appropriately, operating as intended, and supporting business objectives. The most appropriate executive response is to document the deficiency, evaluate business impact and likelihood, assign remediation ownership, set deadlines, and track closure through governance processes.

  • A. Incorrect.

    This is incorrect because audit conclusions are measured against defined criteria, not only against evidence of actual compromise. The absence of a known incident does not mean the control objective is being achieved. Quarterly privileged access recertification is a preventive and detective governance control designed to reduce the risk of excessive or inappropriate access. Deferring action simply because no incident has yet occurred reflects a reactive rather than risk-based interpretation of audit results.

  • B. Incorrect.

    This is incorrect because the existence of compensating controls such as multi-factor authentication does not automatically eliminate a deficiency in another required control. MFA helps validate authentication, but it does not address whether privileged access remains appropriate, approved, and aligned with job responsibilities over time. If the audit criterion explicitly requires quarterly recertification and that requirement was not met for a meaningful portion of the sample, the exception should still be evaluated as a control deficiency.

  • C. Correct.

    This is correct because the audit identified nonconformance with established criteria: privileged accounts lacked required quarterly recertification. The CISO should interpret the result against the defined control objective and assess the residual risk, including the possibility of dormant, excessive, or no-longer-authorized privileged access. The proper response is to ensure management ownership, formal remediation plans, timelines, and follow-up validation. This approach aligns with risk-based auditing and governance expectations for control effectiveness.

  • D. Incorrect.

    This is incorrect because financial audit materiality concepts should not be applied mechanically to security control testing. In information security audits, significance is based on risk, control objective impact, scope, and exposure, not only on sample size thresholds. An 18% exception rate in privileged access governance is already meaningful enough to warrant management attention, particularly because privileged access poses elevated risk. Waiting for more evidence before acting may unnecessarily extend exposure.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam