ExamRange

CCISO (712-50) Executive Decision Simulation

Master identity governance and risk mitigation. This simulation trains you to define and defend precise policy metrics during board-level discussions regarding credential lifecycle management.

Executive Briefing

You are the Chief Information Security Officer (CISO) for a regional healthcare provider. Following a recent HIPAA compliance audit, the organization was cited for inadequate controls surrounding credential rotation and session hijacking vulnerabilities.

You are presenting the revised Identity and Access Management (IAM) Governance Framework to the Risk and Compliance Committee. The framework introduces strict quantitative metrics to govern how user credentials are managed, rotated, and enforced across the enterprise.

Business Context

  • Risk Tolerance: Low. The organization cannot afford account takeovers (ATO) that lead to Electronic Health Record (EHR) data breaches.
  • Audit Finding: The previous system allowed users to leave password-reset prompts open indefinitely, creating "orphaned sessions" that attackers could exploit.
  • Board Objective: The Board wants assurance that the new policy utilizes precise, enforceable metrics to eliminate the window of vulnerability during credential changes.

Decision Scenario

During the presentation, the Chief Legal Officer (CLO) reviews the proposed Key Performance Indicators (KPIs) dashboard. She points to a specific metric labeled "Password Aging".

"In standard IT, I thought this just meant making people change their passwords every 90 days," she states. "But our external auditor mentioned that in our new strict enforcement model, this term represents a highly specific, active security control designed to stop session hijacking. Can you clarify what exactly this metric governs in our new policy?"

You must provide the exact definition that aligns with the specific, active control mechanism being implemented to satisfy the audit finding.

Question

What is meant by password aging?

A. An expiration date set for passwords
B. A Single Sign-On requirement
C. Time in seconds a user is allocated to change a password
D. The amount of time it takes for a password to activate