712-50 exam dumps

712-50 practice question 174 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 174

Single answerAsking for Feedback

A newly appointed CISO has completed the first 90 days in role and presented a draft 18-month security transformation roadmap to the executive committee. The roadmap includes identity modernization, third-party risk improvements, and security awareness redesign. Several business unit leaders privately say the roadmap is technically strong but may face resistance because it was developed with limited business input. The CEO asks the CISO to refine the plan and improve executive buy-in without delaying critical risk reduction activities. What is the BEST approach for the CISO to take when asking for feedback?

  1. A

    Send the roadmap to all executives and ask for any comments they may have, then incorporate the most frequently mentioned suggestions.

  2. B

    Hold structured feedback sessions with key stakeholders, ask targeted questions tied to business objectives and risk tolerance, and use the input to adjust priorities and communication while preserving urgent risk treatments.

  3. C

    Ask the security leadership team to collect feedback from business leaders on the CISO's behalf so that executives can speak more freely without direct CISO involvement.

  4. D

    Delay roadmap execution until every business unit leader agrees with the plan, ensuring consensus before any major initiative begins.

Show answer and explanation

Correct answer: B

Explanation

In the CCISO context, asking for feedback is a leadership and governance competency, not merely a communication task. The strongest approach is to solicit structured, decision-oriented feedback from relevant stakeholders and use that input to improve alignment, sequencing, and executive sponsorship. Effective CISOs ask questions that connect security initiatives to business goals, operational realities, risk tolerance, budget constraints, and change capacity. They also distinguish between elements of the roadmap that are negotiable, such as timing or communication, and those that are not, such as urgent remediation of significant risk exposures. This reflects widely accepted governance and leadership practices found in frameworks and guidance such as NIST Cybersecurity Framework governance outcomes, NIST SP 800-37's emphasis on ongoing stakeholder engagement in risk management, and COBIT's alignment of enterprise goals, risk, and stakeholder needs. The key principle is that feedback should be intentional, specific, and actionable, enabling better decisions and stronger organizational commitment without surrendering accountability for timely risk reduction.

  • A. Incorrect.

    This is not the best approach because broad, unstructured requests for comments often produce uneven, low-quality input and can bias decisions toward the loudest or most politically influential voices rather than the most material business and risk concerns. While inviting comments is useful, effective executive feedback gathering should be deliberate, aligned to strategy, and designed to elicit input on priorities, constraints, dependencies, and risk appetite.

  • B. Correct.

    This is the best answer because it reflects executive-level leadership and governance practice. A CISO should actively seek structured feedback from stakeholders using focused questions such as business impact, implementation constraints, sequencing, risk acceptance thresholds, and success measures. This approach improves buy-in, demonstrates collaboration, and helps the CISO recalibrate messaging and prioritization without abandoning urgent controls needed to address significant risk. It balances stakeholder engagement with the CISO's responsibility to lead risk-informed decision-making.

  • C. Incorrect.

    This is plausible but suboptimal. Delegating all feedback collection can distort the message, reduce trust, and signal avoidance of difficult conversations. While staff can help organize and document feedback, the CISO should directly engage senior stakeholders when refining strategic plans. Executive relationships and credibility are core parts of the role, and hearing concerns firsthand often reveals context that intermediaries may miss.

  • D. Incorrect.

    This is incorrect because waiting for full consensus can create unnecessary delay and expose the organization to ongoing risk. In security leadership, stakeholder alignment is important, but complete agreement across all business units is rarely achievable. The CISO should seek meaningful input and negotiate trade-offs, not allow consensus-seeking to stall action on material risks.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam