712-50 exam dumps

712-50 practice question 153 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 153

Single answerRole Modeling Ethical Leadership

A newly appointed CISO discovers that a high-performing security operations manager routinely bypasses the formal exception process to let urgent business projects go live with unresolved control gaps. The manager argues that documenting exceptions would 'slow innovation' and notes that senior executives have informally supported this approach when deadlines are tight. The CISO wants to strengthen the organization's ethical culture without undermining delivery commitments or creating the appearance of selective enforcement. What is the BEST action for the CISO to take to role model ethical leadership?

  1. A

    Privately instruct the manager to continue using informal approvals for critical projects, but require monthly verbal updates so the CISO can monitor the risk.

  2. B

    Immediately remove the manager from decision-making authority and announce a zero-tolerance policy for any future deviations, regardless of business impact.

  3. C

    Establish and personally follow a transparent risk acceptance and exception process, require documented approvals at the appropriate business level, and communicate that deadlines do not override accountability.

  4. D

    Allow the practice to continue temporarily for revenue-generating projects while the CISO drafts a future policy update to address the issue more gradually.

Show answer and explanation

Correct answer: C

Explanation

The best answer is to establish and personally adhere to a transparent exception and risk acceptance process with documented approval by the appropriate business owner. In CCISO practice, role modeling ethical leadership means the security leader sets the tone through consistent conduct, not merely through statements or punitive actions. The CISO should demonstrate that governance processes apply equally under pressure, that risk acceptance is a business decision informed by security, and that accountability must be documented and auditable.

This aligns with widely accepted governance and ethics principles found in frameworks such as ISO/IEC 27001 and ISO/IEC 27002, which emphasize defined policies, assigned responsibilities, and formal treatment of information security risk. It is also consistent with governance concepts in COBIT, which stress accountability, transparency, and decision rights. From an ethics perspective, the CISO should avoid creating a culture where results excuse process violations. Ethical leadership in practice means showing that urgency does not eliminate the need for integrity, documentation, and appropriate authorization.

  • A. Incorrect.

    This is incorrect because it normalizes undocumented risk acceptance and reinforces a double standard between written policy and actual behavior. Ethical leadership requires the CISO to model transparency, accountability, and proper governance, not to create informal side channels for exceptions. Monthly verbal updates do not provide auditable evidence, clear ownership, or consistent treatment across the enterprise.

  • B. Incorrect.

    This is incorrect because, although accountability matters, an immediate punitive response without reinforcing a principled governance mechanism can appear reactionary and may damage trust. Ethical leadership is not only about punishment; it is about setting the tone, creating fair and repeatable processes, and ensuring the business understands how risk decisions should be made. A zero-tolerance message without context can also discourage legitimate escalation and transparency.

  • C. Correct.

    This is correct because it demonstrates the core elements of ethical leadership: the CISO personally models the expected behavior, applies standards consistently, makes risk decisions transparent, and ensures accountability sits with the appropriate risk owner. Documented exceptions and formal risk acceptance align security governance with business decision-making while avoiding hidden compromises. This approach also addresses culture by showing that business pressure does not justify bypassing controls or governance.

  • D. Incorrect.

    This is incorrect because it continues inconsistent enforcement and signals that commercial pressure can justify circumventing governance. Even if intended as a transitional measure, selectively allowing undocumented exceptions for favored projects undermines integrity and weakens the CISO's credibility. Ethical role modeling requires visible consistency, especially when business incentives create pressure to cut corners.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam