712-50 exam dumps

712-50 practice question 157 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 157

Single answerMentoring and Coaching Teams

A newly appointed CISO inherits a security operations team with high turnover, inconsistent incident escalation decisions, and several technically strong analysts who have recently been promoted into lead roles without prior people-management experience. The board has asked for measurable improvement in team capability within six months, but budget for external training is limited. Which action should the CISO take FIRST to build leadership depth and improve team performance in a sustainable way?

  1. A

    Establish a structured mentoring and coaching program for the new leads, including defined development goals, regular one-on-one coaching sessions, and evaluation tied to operational metrics such as escalation quality and response consistency

  2. B

    Replace the newly promoted leads with experienced external managers who already have formal supervisory backgrounds, even if this causes short-term disruption

  3. C

    Require all analysts and leads to complete the same generic annual management training module and use completion rates as the primary measure of leadership improvement

  4. D

    Focus on rewriting incident response procedures in greater detail so that individual leadership capability becomes less important to team outcomes

Show answer and explanation

Correct answer: A

Explanation

The most effective first step is to implement a structured mentoring and coaching program for newly promoted leaders. In a CCISO context, mentoring and coaching are not informal extras; they are core mechanisms for building bench strength, improving retention, and aligning people capability with operational performance. The scenario points to leadership transition risk: technically strong individuals were promoted without management experience, leading to inconsistent escalation decisions and turnover. A mature executive response is to create a development framework with clear competencies, regular coaching cadence, and measurable outcomes tied to business-relevant security metrics.

Best practices in leadership development and workforce capability management emphasize targeted coaching, role-specific development plans, and measurable outcomes rather than one-time training alone. This aligns with broader governance and people-management principles found across recognized guidance such as NIST NICE Workforce Framework concepts for role capability development, as well as leadership and competence development principles reflected in ISO/IEC 27001 supporting organizational competence requirements. From a practical standpoint, mentoring internal leads is also more sustainable and cost-effective than replacing them or relying solely on procedural controls. The strongest answer therefore combines coaching, defined goals, and operational measurement to build leadership depth while improving security team performance.

  • A. Correct.

    This is the best answer because it addresses the root problem: capable technical staff were promoted without leadership preparation, and the organization needs measurable improvement under budget constraints. A structured mentoring and coaching program is a practical, high-value approach that builds internal leadership capability, improves consistency in decision-making, and supports retention by investing in employees. Defining development goals and linking progress to operational outcomes such as escalation quality, response consistency, and team performance aligns leadership development with business and security objectives. This reflects sound executive practice in talent development, succession planning, and performance management.

  • B. Incorrect.

    This is plausible because hiring experienced managers can sometimes improve supervisory maturity quickly. However, it is not the best first action here. It is costly, likely inconsistent with the limited training budget, and risks damaging morale and retention by signaling that internal promotions are not supported. It also fails to develop existing talent sustainably. A CCISO-level leader should strengthen the pipeline and coach current leaders before defaulting to replacement unless there is evidence of persistent unsuitability or misconduct.

  • C. Incorrect.

    This is incorrect because generic annual training is usually too broad and passive to address specific leadership gaps in a security operations context. Completion rates are activity metrics, not outcome metrics, and do not demonstrate improved coaching ability, judgment, delegation, or escalation quality. Someone might choose this because it appears scalable and easy to measure, but it does not provide the individualized feedback and reinforcement needed for newly promoted leaders.

  • D. Incorrect.

    This is incorrect because process clarity is important, but detailed procedures alone do not solve deficiencies in leadership, mentoring, judgment, or team development. In security operations, leads still need to coach analysts, make decisions under ambiguity, handle performance issues, and reinforce standards. A candidate might choose this option because standardization can reduce variability, but overreliance on procedures is a common misconception when the underlying issue is capability development.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam