712-50 exam dumps

712-50 practice question 114 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 114

Single answerManaging Down and Supporting

A newly appointed CISO inherits a security organization with high analyst turnover, uneven incident response quality, and frequent complaints from business units that security is "blocking work". Exit interviews show analysts feel they receive conflicting priorities from different managers, while business stakeholders say they do not understand why certain controls are required. The CEO has asked the CISO to improve both team performance and internal customer support without increasing headcount this fiscal year. Which action should the CISO take FIRST to address the root cause while strengthening both managing down and supporting across the organization?

  1. A

    Implement a clearer operating model with defined roles, decision rights, and escalation paths for the security team, and require managers to translate control objectives into business-relevant guidance for internal stakeholders

  2. B

    Increase the number of security tools used by analysts so they can automate more tasks and reduce the need for coordination with business units

  3. C

    Move all security control approval decisions to the CISO so business units receive faster and more consistent answers

  4. D

    Require all analysts to complete advanced technical training before revising team processes or stakeholder communication methods

Show answer and explanation

Correct answer: A

Explanation

This question tests the CCISO candidate's ability to manage down and support effectively by diagnosing organizational dysfunction rather than reacting tactically. In this case, the strongest first action is to establish a clear operating model: who owns what, how priorities are set, how conflicts are escalated, and how security expectations are communicated to internal customers. In CCISO practice, managing down includes setting direction, clarifying accountability, developing managers, and creating an environment where staff can execute consistently. Supporting includes enabling the business through understandable, risk-based guidance rather than acting as an opaque control gate.

The facts point to three connected issues: unclear internal governance, inconsistent management messages, and weak business-facing support. Best practices from information security governance and service management support this approach. ISO/IEC 27001 and ISO/IEC 27014 emphasize governance, assignment of responsibilities, and alignment of security with organizational objectives. NIST Cybersecurity Framework 2.0 highlights governance, roles, responsibilities, and communication with stakeholders. ITIL-style service management principles also reinforce the need for clear ownership, escalation, and customer-oriented communication. A mature CISO addresses these foundational leadership and operating-model gaps before assuming that more tools, more centralization, or more technical training will solve the problem.

  • A. Correct.

    Correct. The scenario points to management and service-delivery problems more than a pure technology or skills gap. Conflicting priorities indicate unclear governance, weak role clarity, and poor decision authority within the security function. Complaints from business units show that the team is not effectively supporting internal customers by explaining requirements in operational terms. A CISO managing down effectively should create clear accountability, align managers on priorities, establish escalation paths, and ensure staff communicate security requirements in business language. This addresses both employee frustration and stakeholder dissatisfaction without requiring additional headcount.

  • B. Incorrect.

    Incorrect. Tooling may improve efficiency in some environments, but it does not directly solve the root causes described: conflicting priorities, unclear management expectations, and poor stakeholder communication. Adding tools often increases complexity, training burden, and process fragmentation if the operating model is already weak. This option reflects the common misconception that technology can compensate for leadership and organizational design failures.

  • C. Incorrect.

    Incorrect. Centralizing all approval decisions with the CISO may appear to improve consistency, but in practice it creates a bottleneck, weakens delegation, and limits management development beneath the CISO. Effective managing down requires empowering subordinate leaders with clear decision rights, not pulling all operational authority upward. This option also reduces scalability and could worsen stakeholder support by slowing routine decisions.

  • D. Incorrect.

    Incorrect. Training can be valuable, especially if analysts lack communication or process discipline, but the scenario does not indicate that technical competence is the primary issue. Requiring advanced technical training before fixing role ambiguity and communication problems delays needed organizational improvements. This is a plausible but incomplete response because it addresses symptoms rather than the main leadership and service-management issues.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam