712-50 exam dumps

712-50 practice question 171 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 171

Single answerLeading with Contextual Communication

A newly appointed CISO is preparing to brief the board after a ransomware incident that disrupted customer-facing systems for eight hours. Technical teams have already contained the attack, but the board is divided: some directors want a deep technical explanation, while others only want to know whether leadership handled the event effectively and what investments are now required. The CISO wants to demonstrate strong leadership through contextual communication. Which approach is MOST appropriate for the board briefing?

  1. A

    Present a detailed timeline of indicators of compromise, malware behavior, and forensic artifacts so the board can independently assess the technical quality of the response

  2. B

    Frame the discussion around business impact, decision points, regulatory and customer implications, risk reduction priorities, and executive actions needed, while keeping technical details available in an appendix

  3. C

    Limit the presentation to a high-level assurance that the incident is contained and avoid discussing financial exposure until the investigation is completely finished

  4. D

    Use the same incident response presentation prepared for the security operations team to ensure message consistency across all stakeholder groups

Show answer and explanation

Correct answer: B

Explanation

The best answer is the one that demonstrates audience-centered leadership communication. In CCISO practice, a CISO is expected to communicate cyber risk in business terms appropriate to executive and board stakeholders, not merely relay technical findings. Boards typically need to understand business impact, legal and regulatory exposure, customer and reputational implications, management effectiveness, residual risk, and the strategic decisions requiring oversight or funding. This aligns with broadly accepted governance and security leadership practices reflected in resources such as NIST Cybersecurity Framework guidance on communicating risk, NIST SP 800-61 on incident handling and stakeholder communication, and governance principles found in board-level cybersecurity oversight guidance. Effective contextual communication does not mean hiding technical facts; it means organizing them so each audience can make informed decisions based on its responsibilities.

  • A. Incorrect.

    This is not the best approach for a board audience. While technical accuracy matters, board members are responsible for governance, oversight, risk, and strategic decisions rather than reviewing forensic artifacts in depth. Overloading the briefing with indicators of compromise and malware details can obscure the decisions the board must make. A candidate might choose this option because it appears transparent and thorough, but it reflects poor audience tailoring.

  • B. Correct.

    This is the correct answer. Contextual communication means translating cybersecurity events into business-relevant terms for the intended audience. For a board briefing, the CISO should explain operational disruption, financial and regulatory implications, customer trust impact, management's response, residual risk, and the decisions or investments that require board input. Keeping technical details in an appendix preserves credibility and supports follow-up questions without making the main message overly technical.

  • C. Incorrect.

    This is incorrect because it withholds key context the board needs for oversight. Even if some details are still evolving, leadership should communicate known business impacts, ranges of exposure, and decision timelines. Avoiding financial exposure entirely can undermine trust and delay governance decisions. Someone might select this option out of concern for accuracy, but effective executive communication includes clearly labeling what is known, unknown, and pending.

  • D. Incorrect.

    This is incorrect because different stakeholders require different levels of abstraction and emphasis. Consistency of facts is important, but contextual communication requires tailoring the message to the audience's role, responsibilities, and decision-making needs. A technical operations deck usually focuses on detection, containment, and remediation tasks, which is misaligned with board-level governance and strategic oversight.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam