712-50 exam dumps

712-50 practice question 155 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 155

Single answerLead with empathy

A newly appointed CISO inherits a security program after a disruptive ransomware incident. In the first executive steering committee meeting, the heads of Operations and Sales push back on several planned controls, arguing that employees are exhausted, morale is low, and additional restrictions will hurt revenue and productivity. The board still expects measurable risk reduction within the quarter. Which action should the CISO take FIRST to demonstrate empathetic leadership while still advancing the security agenda?

  1. A

    Pause all new security initiatives until employee sentiment improves, to avoid further resistance and rebuild trust

  2. B

    Reaffirm that security requirements are non-negotiable, direct immediate implementation of all planned controls, and address morale issues later

  3. C

    Engage business leaders and affected teams to understand operational pain points, validate workforce concerns, and jointly prioritize a phased set of controls that reduce the highest risks with the least business disruption

  4. D

    Escalate the disagreement to the board and request a mandate forcing business units to accept the security roadmap as designed

Show answer and explanation

Correct answer: C

Explanation

The best answer is to engage stakeholders, understand their concerns, and jointly prioritize a phased set of controls based on risk and business impact. In the CCISO context, leading with empathy is not about lowering standards; it is about understanding stakeholder perspectives, workforce fatigue, and operational realities so security decisions are more effective and sustainable. This reflects core executive responsibilities such as influencing senior leaders, aligning security with business objectives, and managing organizational change.

A risk-based, collaborative approach is consistent with widely accepted security governance and leadership practices. NIST Cybersecurity Framework 2.0 emphasizes governance, organizational context, and stakeholder communication when managing cybersecurity outcomes. NIST SP 800-53 also highlights the importance of tailoring controls based on organizational mission and operational needs. In parallel, change management good practices recognize that involving affected stakeholders improves adoption and reduces resistance. From a leadership perspective, empathetic engagement helps the CISO build trust, surface practical constraints early, and avoid implementing controls in ways that create undue friction or workarounds.

In this scenario, the FIRST action should be to listen, validate concerns, and co-develop a prioritized roadmap that addresses the highest risks quickly while minimizing unnecessary disruption. That is the clearest demonstration of empathetic leadership combined with executive accountability.

  • A. Incorrect.

    This is incorrect because empathetic leadership does not mean avoiding difficult decisions or suspending risk treatment indefinitely. While listening to employee concerns is important, pausing all initiatives after a ransomware event would leave material risks unaddressed and fail to meet executive and board expectations for timely remediation. A CCISO is expected to balance human factors with business resilience, not defer action entirely.

  • B. Incorrect.

    This is incorrect because it reflects an authoritarian approach rather than empathetic leadership. Although some controls may indeed be mandatory, imposing all planned controls immediately without understanding operational impact is likely to deepen resistance, reduce adoption, and create shadow practices. In executive leadership, empathy improves influence, change acceptance, and alignment across business units.

  • C. Correct.

    This is correct because it demonstrates empathy in a way that is aligned with executive responsibility. The CISO is acknowledging stakeholder concerns, seeking to understand the operational and human impact, and using that insight to prioritize risk-reducing actions pragmatically. A phased, risk-based implementation is consistent with sound governance and change management: address the most significant threats first while preserving business operations and workforce engagement. This approach also supports stronger long-term buy-in because stakeholders are involved in shaping practical controls.

  • D. Incorrect.

    This is incorrect because immediate escalation to the board is premature and can damage peer relationships. Board escalation may be appropriate if risk acceptance decisions cannot be resolved through governance channels, but using it first bypasses collaborative leadership. An empathetic CCISO should initially work to understand concerns, align on business priorities, and present options before seeking top-down enforcement.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam