712-50 exam dumps

712-50 practice question 67 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 67

Single answerEvaluate audit results, weighing the relevancy, accuracy, and perspective of conclusions against the accumulated audit evidence

A newly appointed CISO is reviewing the results of an external security audit before presenting them to the board. The audit report concludes that the organization has an 'ineffective vulnerability management program' because 18% of sampled servers were missing critical patches. During review, the CISO learns that: (1) the sample excluded the cloud environment that hosts 40% of production workloads, (2) 6 of the 9 cited critical patches were already deployed before fieldwork ended but were not reflected in the auditor's evidence, and (3) several sampled servers were legacy systems covered by formally approved risk exceptions. What should the CISO do FIRST to properly evaluate the audit conclusion against the accumulated audit evidence?

  1. A

    Accept the audit conclusion as written because external auditors provide an independent perspective that should not be challenged before board reporting

  2. B

    Request the audit team validate the timeliness, completeness, and scope of the evidence, and then reassess whether the conclusion accurately reflects enterprise-wide vulnerability management effectiveness

  3. C

    Reject the audit conclusion immediately because the presence of approved risk exceptions invalidates any negative finding related to patching performance

  4. D

    Present the finding to the board unchanged, but add a management response stating that cloud assets and compensating controls will be reviewed later

Show answer and explanation

Correct answer: B

Explanation

This question focuses on a core CCISO responsibility: evaluating audit results by weighing the relevancy, accuracy, and perspective of conclusions against the supporting evidence. A sound audit conclusion should be based on sufficient, appropriate, and current evidence, and its scope should be representative of the environment being assessed. In the scenario, the audit conclusion may be overstated because the sample excluded a major portion of production workloads, some evidence was outdated by the end of fieldwork, and approved risk exceptions may materially affect interpretation of noncompliance. The CISO should not dismiss the finding outright, but should first reconcile evidence quality and scope with the auditors. This approach aligns with generally accepted audit principles found in frameworks such as ISO 19011 guidance on auditing, which emphasizes objective evidence, accurate reporting, and context, and with governance expectations in control frameworks like COBIT and the IIA's standards that require conclusions to be supported by sufficient, reliable, relevant evidence. For executive reporting, the CISO's role is to ensure that audit results are both independent and decision-useful, meaning materially accurate, properly scoped, and framed in business context.

  • A. Incorrect.

    This is incorrect. Auditor independence is valuable, but audit conclusions must still be evaluated for relevancy, accuracy, and perspective against the underlying evidence. A CISO has a governance responsibility to ensure material conclusions presented to leadership are supported by current, complete, and appropriately scoped evidence. Accepting a potentially outdated or non-representative conclusion without challenge is a common mistake.

  • B. Correct.

    This is correct. The first step is to test whether the evidence is accurate, complete, timely, and representative of the environment before accepting the conclusion. In this scenario, there are three red flags: incomplete scope because cloud workloads were excluded, evidence accuracy issues because several patches were already deployed before fieldwork ended, and context issues because some systems had formally approved risk exceptions. Revalidating these points allows the organization and auditors to determine whether the conclusion should be narrowed, revised, or upheld.

  • C. Incorrect.

    This is incorrect. Approved risk exceptions provide context, but they do not automatically invalidate a finding. The CISO still needs to determine whether the exceptions were properly authorized, current, and within stated risk tolerance, and whether the remaining population still supports the audit conclusion. This option reflects the misconception that any compensating governance artifact negates control weakness evidence.

  • D. Incorrect.

    This is incorrect. Adding a management response without first validating the evidence leaves the board with a potentially misleading conclusion. The issue here is not just remediation planning; it is whether the stated conclusion is supported by the audit evidence in the first place. Governance best practice is to resolve factual and scope discrepancies before escalation to senior leadership whenever possible.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam