712-50 exam dumps

712-50 practice question 139 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 139

Single answerTeam Building, Consensus Building, and Building Commitment

A newly appointed CISO is leading a cross-functional initiative to implement stricter privileged access controls after an internal audit identified excessive administrator rights across IT, cloud operations, and application support teams. Although executives support the initiative in principle, several operational managers resist because they fear service delays, increased ticket volume, and loss of autonomy. The CISO has technical evidence and could mandate the change through policy, but wants durable adoption and shared accountability across departments. Which action is the BEST first step to build consensus and commitment while maintaining progress?

  1. A

    Issue an immediate enterprise-wide directive requiring all departments to remove privileged access within 30 days, with exceptions approved only by the CISO

  2. B

    Convene key stakeholders from affected teams to review business impacts, define common success criteria, and jointly agree on a phased implementation plan with metrics and escalation paths

  3. C

    Allow each department to design and execute its own privileged access approach independently so they feel ownership of the outcome

  4. D

    Delay the project until all managers fully agree with the security rationale, so the rollout does not create organizational tension

Show answer and explanation

Correct answer: B

Explanation

In CCISO-level leadership, team building and consensus building are not about avoiding hard decisions; they are about creating the conditions for sustained execution across business and technical functions. The strongest first step is to engage the right stakeholders in a structured discussion of business impact, risk priorities, success measures, and implementation sequencing. This builds trust, clarifies trade-offs, and increases the likelihood that managers will commit resources and reinforce the change with their teams. A phased rollout with agreed metrics and escalation mechanisms also reflects sound governance and change management principles. This aligns with widely accepted practices in security leadership and governance, including the need for stakeholder engagement, risk-based prioritization, and accountable implementation reflected in frameworks such as NIST Cybersecurity Framework governance outcomes, NIST SP 800-53 control governance concepts, and ISACA/COBIT principles emphasizing stakeholder needs, governance alignment, and enterprise-wide ownership.

  • A. Incorrect.

    This is not the best first step if the goal is consensus building and lasting commitment. A top-down directive may achieve compliance, but it often creates passive resistance, workarounds, and weak ownership from operational leaders. In a cross-functional change effort, especially one affecting operations, the CISO should first seek alignment on impacts, objectives, and implementation realities before moving to enforcement. Candidates may choose this because policy authority exists, but authority alone does not build commitment.

  • B. Correct.

    This is the best answer because it balances leadership, stakeholder engagement, and execution discipline. Bringing affected leaders together helps surface operational concerns early, aligns the group on shared objectives such as risk reduction and service continuity, and creates joint ownership of the rollout. A phased plan with measurable outcomes and escalation paths demonstrates that the CISO is not merely seeking agreement in theory, but is structuring accountable collaboration. This approach is consistent with effective executive leadership, change management, and governance practices.

  • C. Incorrect.

    This is incorrect because it sacrifices enterprise consistency and governance in the name of ownership. While local input is valuable, allowing each department to define its own approach independently can lead to fragmented controls, inconsistent risk treatment, duplicated effort, and audit gaps. Stakeholder involvement should occur within a centrally governed framework, not through fully decentralized decision-making. Someone might choose this option because empowerment is important, but empowerment without alignment undermines security leadership.

  • D. Incorrect.

    This is incorrect because waiting for full agreement is unrealistic and can stall needed risk reduction. Effective consensus building does not require unanimity before action; it requires sufficient alignment, transparent trade-off discussion, and a workable plan. A CISO must facilitate commitment and address objections, but also maintain momentum on material risks. Candidates may select this because they equate consensus with complete agreement, which is a common leadership misconception.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam