712-50 exam dumps

712-50 practice question 105 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 105

Single answerCommunicating Change

A newly appointed CISO is leading a company-wide rollout of mandatory phishing-resistant multi-factor authentication (MFA) after several credential-based incidents. The change will affect executives, remote employees, third-party contractors, and the customer support team, which is concerned about increased call volume and user frustration. The CEO has approved the initiative, but several business unit leaders say the rollout timeline is too aggressive and that previous security communications were too technical and poorly received. Which action should the CISO take FIRST to improve the likelihood of successful adoption while maintaining executive support?

  1. A

    Send a single enterprise-wide email from the CEO announcing the MFA deadline and warning that access will be revoked for anyone who does not comply

  2. B

    Delay the rollout until every business unit fully agrees with the plan, to avoid resistance and ensure complete alignment before any communication is sent

  3. C

    Develop a stakeholder-specific communication and change plan that explains business rationale, impacts, support channels, training, and phased adoption milestones, then socialize it with business leaders before launch

  4. D

    Publish a detailed technical standard for MFA enrollment on the security intranet and require managers to distribute it to their teams

Show answer and explanation

Correct answer: C

Explanation

The strongest initial action is to create and socialize a stakeholder-specific communication and change plan. In a CCISO context, communicating change is not merely announcing a control; it is aligning stakeholders, translating security objectives into business outcomes, preparing support functions, and sequencing messages so adoption risk is managed proactively. Established change-management practices, such as stakeholder analysis, targeted messaging, sponsor engagement, training, feedback loops, and phased rollout, are consistent with guidance from widely recognized frameworks and best practices, including ISACA change enablement concepts, ITIL organizational change management principles, and NIST guidance emphasizing user awareness, role-based communication, and operational planning. In this scenario, the CISO already knows prior communications failed because they were too technical, and key groups have concerns about timing and operational burden. Therefore, the first priority is not more technical documentation or a punitive executive memo, but a structured communication strategy tailored to stakeholder needs and tied to clear business rationale, support mechanisms, and implementation milestones.

  • A. Incorrect.

    This is not the best first action. Executive sponsorship is valuable, and a CEO message can reinforce importance, but a single top-down announcement that emphasizes punishment without tailored messaging, support, or readiness planning often increases resistance. It does not address the known issue that prior communications were too technical and poorly received, nor does it prepare affected groups for operational impact.

  • B. Incorrect.

    This is incorrect because waiting for complete agreement from every business unit is unrealistic and can stall a needed risk-reduction initiative. Effective change communication requires engagement and feedback, but not unanimous approval before action. A CISO should manage resistance through structured stakeholder engagement, not create indefinite delay.

  • C. Correct.

    This is the best answer because it addresses the core communication and change-management problem before broad deployment. A stakeholder-specific plan allows the CISO to tailor messages for executives, end users, support teams, and contractors; explain why the change matters in business terms; identify expected impacts; provide training and support; and use phased milestones to reduce disruption. Socializing the plan with business leaders first also builds local sponsorship and prepares them to answer questions, which is critical when prior communications were ineffective.

  • D. Incorrect.

    This is insufficient as a first action. Technical standards are necessary for implementation teams, but publishing a detailed standard on an intranet does not constitute effective change communication for diverse stakeholders. It assumes users and managers can translate technical content into business impact and adoption behavior, which is a common mistake in security programs.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam