712-50 exam dumps

712-50 practice question 169 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 169

Single answerBuilding Leadership Networks

A newly appointed CISO has been asked by the CEO to improve executive alignment on cyber risk after several business units bypassed security review to meet aggressive launch deadlines. The CISO has limited formal authority over those units and needs to build a leadership network that will increase cooperation, speed decision-making, and improve accountability. Which action is the MOST effective first step?

  1. A

    Create a cross-functional executive steering committee with representatives from product, legal, operations, finance, and IT, and define shared risk decision and escalation responsibilities

  2. B

    Require all business units to submit security exceptions directly to the CISO for approval so that decisions remain centralized and consistent

  3. C

    Launch a mandatory security awareness campaign for all vice presidents before discussing governance changes with the executive team

  4. D

    Ask internal audit to assess each business unit's compliance with security policy and publish the results to drive executive support

Show answer and explanation

Correct answer: A

Explanation

In CCISO practice, building leadership networks is about extending influence beyond the security department by forming strong relationships with executives and business leaders who own processes, budgets, products, and operational outcomes. A CISO often lacks direct authority over business units, so success depends on governance, communication, and trust. The most effective first move in this scenario is to establish a cross-functional executive forum with clearly defined roles for risk acceptance, prioritization, and escalation. This approach is consistent with widely accepted governance principles found in frameworks and guidance such as COBIT governance structures, the NIST Cybersecurity Framework's emphasis on organizational governance and risk communication, and ISO/IEC 27014 guidance on information security governance. These sources support the idea that cyber risk decisions should be integrated into enterprise governance and owned collaboratively by business leadership, not handled as isolated technical approvals by the CISO alone.

  • A. Correct.

    Correct. Building a leadership network at the executive level starts with creating durable relationships, shared accountability, and formal channels for decision-making across business functions. A cross-functional executive steering committee helps the CISO influence peers without relying solely on hierarchical authority. It also aligns with good governance practice by clarifying who owns risk decisions, how exceptions are evaluated, and when issues are escalated. This is the strongest first step because it establishes the structure through which trust, collaboration, and business-aligned risk management can occur.

  • B. Incorrect.

    Incorrect. Centralizing all exception approvals with the CISO may appear to improve consistency, but it weakens shared ownership and can create a bottleneck. In a leadership-network context, the goal is not to absorb all authority into the security function, but to build influence and accountability across the enterprise. This option also risks reinforcing the perception that security is an obstacle rather than a business partner.

  • C. Incorrect.

    Incorrect. Executive education can be useful, but awareness training alone does not create the peer relationships, governance mechanisms, or decision rights needed to resolve cross-functional conflict. It treats the problem as a knowledge gap when the scenario primarily reflects a coordination, accountability, and leadership alignment issue.

  • D. Incorrect.

    Incorrect. Internal audit can provide valuable independent assurance, but using audit findings as the initial mechanism to gain support is often reactive and may create defensiveness among business leaders. It does not by itself build the collaborative leadership network needed for ongoing risk-based decision-making. Audit is generally more effective after governance expectations and leadership engagement structures are already defined.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam