712-50 exam dumps

712-50 practice question 17 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 17

Single answerUnderstand the role of the governing board and the CISO's role in supporting the board

A newly appointed CISO is preparing for her first quarterly briefing to the governing board of a global manufacturing company. The board has recently asked management to demonstrate stronger cyber oversight after a ransomware incident at a peer organization. Several board members are not technical, but they want assurance that cyber risk is being managed in line with business objectives. Which approach should the CISO take to BEST support the board in fulfilling its governance responsibilities?

  1. A

    Provide a detailed presentation of firewall rules, endpoint tool configurations, and vulnerability scan outputs so the board can verify technical control effectiveness directly.

  2. B

    Present a business-focused view of cyber risk, including top enterprise risk scenarios, risk appetite alignment, material control gaps, incident readiness, and management's recommended actions requiring board oversight or decision.

  3. C

    Ask the board to approve day-to-day security operations metrics such as patching schedules, SIEM correlation logic, and privileged access review exceptions to ensure direct accountability.

  4. D

    Limit the update to compliance status against security standards and avoid discussing residual risk unless the board specifically requests it, because operational risk treatment is a management responsibility.

Show answer and explanation

Correct answer: B

Explanation

The governing board's role is to provide oversight, set strategic direction, approve risk appetite, and hold management accountable for managing material risks, including cybersecurity risk. The CISO supports the board by translating technical security issues into business terms, highlighting enterprise risk scenarios, control effectiveness at an appropriate level, resilience and incident readiness, and decisions or escalations that require board attention. The board should not be drawn into operational security management, but it should receive enough information to evaluate whether management's actions align with business objectives and risk tolerance. This approach is consistent with widely recognized governance practices reflected in frameworks and guidance such as NIST Cybersecurity Framework 2.0's Govern function, NIST SP 800-100 on information security governance, COBIT governance-management distinctions, and board-level cyber risk guidance from organizations such as NACD and the World Economic Forum. In practice, the strongest board reporting is concise, risk-based, decision-oriented, and tied to business impact rather than technical control detail alone.

  • A. Incorrect.

    This is incorrect because it focuses the board on operational and technical detail rather than governance. Governing boards are responsible for oversight, strategic direction, and understanding whether management is effectively handling material risk. While technical evidence may support management reporting, board-level communication should be translated into business impact, risk exposure, and decision points. A common misconception is that more technical detail equals better assurance; in reality, excessive detail can obscure the information the board needs.

  • B. Correct.

    This is correct because it aligns the CISO's role with executive management support and board governance. The board should receive clear, business-relevant information on significant cyber risks, how those risks compare to the organization's risk appetite, whether important control gaps remain, whether incident response and resilience are adequate, and which matters require oversight, escalation, or resource decisions. This enables the board to challenge management appropriately without becoming involved in operations.

  • C. Incorrect.

    This is incorrect because it improperly shifts operational management responsibilities to the board. Boards are accountable for governance and oversight, but they do not manage daily security activities. Asking the board to approve patch schedules, SIEM logic, or access-review exceptions confuses governance with management and can weaken accountability structures. Candidates may choose this option if they misunderstand the difference between board oversight and operational control.

  • D. Incorrect.

    This is incorrect because compliance reporting alone does not provide the board with an adequate view of cyber risk. Boards need to understand residual risk, business impact, resilience, and whether management actions are sufficient. Although management owns day-to-day risk treatment, the board still has a duty to oversee material risk exposure and ensure it remains within approved tolerance. A compliance-only update can create false assurance.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam