712-50 exam dumps

712-50 practice question 144 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 144

Single answerManaging Difficult Conversations

A newly appointed CISO learns that the head of Sales has repeatedly bypassed the formal security exception process to accelerate deployment of a customer analytics platform. The platform processes regulated customer data, and internal audit has now flagged the issue. The CEO wants the conflict resolved quickly without damaging the relationship with Sales, which is critical to quarterly revenue. As the CISO prepares for a meeting with the Sales executive, which approach is MOST effective for managing this difficult conversation while protecting the organization?

  1. A

    Begin the meeting by citing policy violations and audit findings, then require the Sales executive to immediately stop the project until all security controls are implemented.

  2. B

    Frame the discussion around shared business objectives, clarify the regulatory and risk implications, listen to the Sales executive's constraints, and jointly agree on compensating controls and a formal remediation timeline.

  3. C

    Escalate the issue directly to the board risk committee before speaking with the Sales executive, because repeated bypassing indicates intentional noncompliance.

  4. D

    Avoid discussing the audit findings in detail to prevent defensiveness, and focus only on preserving the relationship so the Sales executive remains cooperative.

Show answer and explanation

Correct answer: B

Explanation

The most effective approach in this scenario is to combine executive communication, active listening, and risk-based negotiation. Senior security leaders are expected to influence peers without relying solely on authority. In difficult conversations, especially with revenue-generating business leaders, the CISO should avoid accusatory language, focus on shared organizational goals, explain business impact and compliance exposure clearly, and seek a workable path such as compensating controls, documented risk acceptance where appropriate, and a formal remediation plan. This aligns with widely accepted security leadership and governance practices found in frameworks and guidance such as NIST Cybersecurity Framework governance principles, NIST SP 800-37 risk management concepts, and ISO/IEC 27001 governance expectations around risk treatment, accountability, and exception handling. Escalation is appropriate when collaboration fails or risk exceeds tolerance, but not as the default first move.

  • A. Incorrect.

    This response is too confrontational as an opening strategy and is less effective for a difficult executive-level conversation. While policy violations and audit findings are important, leading with blame and unilateral demands often creates defensiveness and reduces the chance of sustained cooperation. A CISO should protect the organization, but also use influence, negotiation, and risk-based communication to achieve compliance in a business context.

  • B. Correct.

    This is the best answer because it balances risk management, regulatory obligations, and executive relationship management. In a difficult conversation, an effective CISO should anchor the discussion in business objectives, communicate risk in language the other executive understands, and actively listen to operational pressures. Jointly defining compensating controls and a time-bound remediation plan reflects mature governance, supports accountability, and is often the most practical path when immediate shutdown is not required by law or incident response necessity.

  • C. Incorrect.

    This is premature. Escalation may become necessary if the executive refuses to cooperate or if the risk is intolerable, but effective leaders typically attempt direct engagement first unless the issue is urgent, illegal, or requires immediate formal escalation. Going straight to the board risk committee can damage trust, reduce opportunities for resolution, and signal weak executive conflict-management skills.

  • D. Incorrect.

    This prioritizes harmony over governance and risk transparency, which is inappropriate. Avoiding the substance of the audit issue may preserve short-term rapport, but it fails to address the root problem and could expose the organization to regulatory, legal, and operational consequences. Effective difficult conversations require candor, clarity, and constructive problem-solving rather than conflict avoidance.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam