712-50 exam dumps

712-50 practice question 109 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 109

Single answerLeading through Education and Awareness and Guarding from Misinformation

A global company experiences a surge in employee reports after a false social media post claims that the organization has suffered a major data breach and that staff must immediately reset passwords through a link in an email that appears to come from IT. Some employees have already clicked the link, while others are sharing unverified screenshots internally, increasing confusion. The CISO must lead the response in a way that both reduces immediate risk and strengthens long-term resilience against misinformation-driven attacks. Which action should the CISO prioritize FIRST?

  1. A

    Launch a company-wide disciplinary review to identify employees who shared the screenshots and clicked the link

  2. B

    Coordinate a verified internal communication through trusted channels that clarifies the facts, instructs employees how to report suspicious messages, and reinforces the approved password reset process

  3. C

    Wait until the full technical investigation is complete before communicating, to avoid spreading incomplete information

  4. D

    Block access to all social media platforms from the corporate network and postpone awareness activities until the incident is contained

Show answer and explanation

Correct answer: B

Explanation

In a misinformation-fueled security event, the CISO must lead through timely, credible communication and awareness, not just technical containment. Best practice is to use established crisis communication channels, provide a clear statement of known facts, identify approved reporting paths, and remind employees of authorized processes such as the official password reset workflow. This approach aligns with core security awareness principles promoted by frameworks and guidance such as NIST SP 800-50 on building an IT security awareness and training program, NIST SP 800-61 on incident response communications, and broader organizational resilience practices reflected in NIST Cybersecurity Framework guidance around awareness, communications, and response coordination. The leadership objective is to reduce harm immediately while strengthening trust, reporting behavior, and resistance to future misinformation and social engineering campaigns.

  • A. Incorrect.

    This is incorrect because a punitive response is not the best first action in a misinformation-driven event. While accountability may matter later, leading with discipline discourages reporting, increases fear, and weakens the security culture. Effective awareness leadership emphasizes rapid reporting, psychological safety, and clear behavioral guidance so employees act as sensors rather than hide mistakes.

  • B. Correct.

    This is correct because the CISO's first priority is to quickly establish a single source of truth and interrupt the misinformation cycle. A verified internal message through trusted channels reduces confusion, counters social engineering, and gives employees concrete actions: do not use unapproved links, report suspicious emails, and use the organization's official password reset process. This combines incident response with security awareness leadership and directly addresses both the immediate phishing risk and the broader misinformation problem.

  • C. Incorrect.

    This is incorrect because delaying communication allows rumors, screenshots, and attacker narratives to spread unchecked. In crisis communications, leaders should communicate early with confirmed facts, even if some details remain under investigation. Waiting for complete technical certainty is a common mistake that creates an information vacuum, which misinformation quickly fills.

  • D. Incorrect.

    This is incorrect because broad social media blocking does not address the core issue: employees need authoritative guidance on what is true and what action to take. It may also disrupt legitimate business operations and does not stop phishing messages already in inboxes or internal rumor propagation. Postponing awareness efforts is especially flawed, because this is precisely when targeted education and reinforcement are most needed.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam