712-50 exam dumps

712-50 practice question 68 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 68

Single answer

A newly appointed CISO at a mid-sized healthcare company reviews the latest internal audit and finds several control gaps: privileged accounts are shared by administrators, quarterly access reviews are not being performed, and critical database backups are completed but restoration testing has not occurred in over a year. The company has a limited security budget for the current fiscal year, and the CEO wants a remediation plan that reduces business risk quickly without major infrastructure replacement. Which action should the CISO prioritize FIRST to create the most practical and cost-effective improvement plan?

  1. A

    Implement a risk-based remediation plan that immediately assigns individual privileged accounts, reinstates periodic access reviews for high-risk systems, and schedules backup restoration testing based on business-critical assets

  2. B

    Purchase a new enterprise security platform that includes identity governance, privileged access management, and backup orchestration so all gaps can be addressed through a single strategic program

  3. C

    Accept the risks temporarily because backups do exist and the audit findings do not yet indicate an active breach or regulatory action

  4. D

    Focus first on encrypting all database backups and defer identity and access issues until the next budget cycle because encryption is a visible technical control improvement

Show answer and explanation

Correct answer: A

Explanation

The best answer is the risk-based remediation plan in Option 1 because it addresses multiple high-impact exposures quickly and affordably. In this scenario, the CISO must evaluate both likelihood and business impact. Shared privileged accounts create serious accountability and segregation-of-duties problems, making it difficult to attribute actions and detect abuse. Missing access reviews undermine least privilege and can allow former employees, contractors, or over-privileged users to retain unnecessary access. Untested backups are a classic resilience gap: organizations often discover during an incident that backups are incomplete, corrupted, or too slow to restore.

A mature CISO should translate these findings into a prioritized treatment plan rather than jumping immediately to expensive tooling. This aligns with widely recognized practices from frameworks such as NIST Cybersecurity Framework (identify, protect, detect, respond, recover), NIST SP 800-53 controls related to account management, access enforcement, least privilege, audit accountability, and contingency planning, ISO/IEC 27001 and 27002 guidance on access control and backup, and CIS Controls emphasizing account management, access control management, and data recovery. In healthcare, these gaps may also affect HIPAA Security Rule expectations around access control, unique user identification, and contingency planning.

The practical leadership takeaway is that effective security improvement starts with identifying control deficiencies, assessing the business exposure they create, and selecting targeted corrective actions that deliver measurable risk reduction within budget constraints.

  • A. Correct.

    Correct. This option reflects sound executive security leadership: assess the exposures, prioritize the highest-risk control failures, and implement practical compensating or corrective actions using existing capabilities where possible. Shared privileged accounts weaken accountability and increase insider threat and misuse risk; missing access reviews increase the chance of excessive or orphaned access; untested backups create false assurance and can severely affect resilience during ransomware or system failure. A risk-based plan targeting these areas is both cost-effective and aligned to established practices in governance, access control, and business continuity.

  • B. Incorrect.

    Incorrect. Although a consolidated platform may be beneficial in the long term, it is not the most practical FIRST step for a budget-constrained organization seeking immediate risk reduction. Large platform purchases typically require procurement time, integration effort, process redesign, and change management. The scenario specifically asks for a practical and cost-effective improvement plan without major infrastructure replacement.

  • C. Incorrect.

    Incorrect. This response underestimates the exposure. The presence of backups alone does not mitigate recovery risk if restorations are untested. Likewise, shared privileged accounts and missing access reviews are significant control failures that can result in unauthorized access, fraud, inability to attribute actions, and compliance deficiencies. Waiting for a breach or regulator to act is not an acceptable risk treatment approach for a CISO.

  • D. Incorrect.

    Incorrect. Backup encryption can be valuable for confidentiality, especially for protected health information, but it does not address the most urgent control weaknesses described. The larger misconception is treating a visible technical improvement as higher priority than controls that directly affect accountability, least privilege, and recoverability. Deferring identity and access issues leaves major exposure unaddressed.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam