712-50 exam dumps

712-50 practice question 168 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 168

Single answerBuilding Leadership Networks

A newly appointed CISO at a global manufacturing company has found that security initiatives repeatedly stall because business unit leaders view cybersecurity as an IT issue rather than a shared business responsibility. Recent incidents have shown inconsistent executive support during crisis response, and the board has asked the CISO to improve cross-functional alignment. To build an effective leadership network that will strengthen security governance and influence enterprise decision-making, which action should the CISO take FIRST?

  1. A

    Establish regular engagement with key business leaders, including operations, legal, HR, finance, and internal audit, to understand their objectives and create a coalition around shared risk priorities

  2. B

    Request that the CEO issue a directive mandating that all business units adopt the security team's standards immediately, without further discussion

  3. C

    Focus on expanding technical reporting to the SOC and infrastructure teams so security metrics are more detailed before engaging senior leadership

  4. D

    Create a separate security steering process composed only of security managers to accelerate decision-making and avoid business resistance

Show answer and explanation

Correct answer: A

Explanation

In CCISO-aligned leadership practice, building a leadership network means creating trusted, ongoing relationships with senior stakeholders who influence business priorities, funding, crisis response, and risk acceptance. The most effective first step is to engage cross-functional leaders and align security to their objectives so cybersecurity is positioned as an enterprise risk and business enabler rather than a narrow IT function. This approach supports stronger governance, better incident coordination, and more sustainable executive sponsorship. It is consistent with widely accepted security leadership practices reflected in governance frameworks and guidance such as NIST Cybersecurity Framework governance principles, NIST SP 800-100 on information security governance, and ISACA governance concepts emphasizing stakeholder engagement, accountability, and alignment with organizational objectives.

  • A. Correct.

    Correct. Building a leadership network begins with establishing trusted relationships across business and control functions, not just within IT. A CISO must understand stakeholder goals, pain points, and risk tolerance, then connect security objectives to business outcomes. This creates influence, improves sponsorship during incidents, and strengthens enterprise governance. In CCISO practice, effective leadership depends on collaboration, executive communication, and coalition-building across functions.

  • B. Incorrect.

    Incorrect. Executive sponsorship is valuable, but relying first on top-down mandates without stakeholder engagement often produces superficial compliance, resistance, and weak long-term support. This approach does not build a leadership network; it attempts to substitute authority for influence and partnership. A CISO needs durable peer-level relationships, not just directives.

  • C. Incorrect.

    Incorrect. Better technical reporting may help operational teams, but it does not address the core issue: insufficient business ownership and executive alignment. The scenario is about cross-functional leadership and governance, not a lack of technical detail. Starting with technical metrics before establishing business relationships is a common mistake for security leaders transitioning from technical roles.

  • D. Incorrect.

    Incorrect. A security-only steering structure may speed internal security decisions, but it further isolates security from the business and weakens enterprise buy-in. The problem described is that business leaders already see security as someone else's issue. Excluding them reinforces that misconception rather than correcting it.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam