nerdexam
EC-Council

312-50V12 · Question #266

A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before…

The correct answer is B. Determine the impact of enabling the audit feature. Before enabling a new auditing feature on a critical system, the initial and most crucial step is to understand and assess its potential impact on system performance and operations.

Submitted by akirajp· Mar 4, 2026Information Security and Ethical Hacking Overview

Question

A bank stores and processes sensitive privacy information related to home loans. However, auditing has never been enabled on the system. What is the first step that the bank should take before enabling the audit feature?

Options

  • APerform a vulnerability scan of the system.
  • BDetermine the impact of enabling the audit feature.
  • CPerform a cost/benefit analysis of the audit feature.
  • DAllocate funds for staffing of audit log review.

How the community answered

(23 responses)
  • A
    4% (1)
  • B
    91% (21)
  • C
    4% (1)

Why each option

Before enabling a new auditing feature on a critical system, the initial and most crucial step is to understand and assess its potential impact on system performance and operations.

APerform a vulnerability scan of the system.

A vulnerability scan identifies security weaknesses within the system but does not address the operational or performance impact of enabling a new feature like auditing, which is a different concern.

BDetermine the impact of enabling the audit feature.Correct

Enabling auditing, especially on a system where it has never been active, can significantly impact system resources such as CPU, disk I/O, network bandwidth, and storage due to the volume of logs generated. Determining this impact beforehand is essential to prevent performance degradation or system outages and to plan for necessary resource adjustments or mitigation strategies.

CPerform a cost/benefit analysis of the audit feature.

While a cost/benefit analysis is important for business decisions, it typically follows an understanding of the technical impact (which influences costs) and is not the very first technical step before enabling a feature.

DAllocate funds for staffing of audit log review.

Allocating funds for staffing to review audit logs is a crucial step for the ongoing operation of the auditing process, but it is not the immediate first step before technically enabling the feature and assessing its initial system impact.

Concept tested: System impact assessment for feature implementation

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-128.pdf

Topics

#auditing#system security#impact assessment#security controls

Community Discussion

No community discussion yet for this question.

Full 312-50V12 Practice