712-50 exam dumps

712-50 practice question 176 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 176

Single answerCourage of Your Convictions

A newly appointed CISO at a rapidly growing financial services firm learns that the CEO wants to launch a customer-facing mobile payment feature before the holiday season. Internal security testing has identified unresolved weaknesses in authentication flows and inadequate fraud-monitoring controls. The CEO argues that delaying the launch will cause major revenue loss and asks the CISO to 'document the concerns and move forward anyway.' The board has historically deferred to executive management on product timing, and the CISO is worried that continued resistance may damage the relationship with the CEO. In demonstrating courage of conviction expected of a senior security leader, what is the BEST course of action?

  1. A

    Approve the launch after sending an email summarizing the risks, since final business ownership rests with executive management

  2. B

    Refuse to participate further in the launch and resign if the CEO does not immediately cancel the project

  3. C

    Escalate the issue through formal governance channels with a clear risk statement, business impact, compensating control gaps, and recommended options, while documenting risk acceptance at the appropriate authority level

  4. D

    Allow the launch to proceed quietly, then prioritize remediation in the next development cycle to avoid conflict with senior leadership

Show answer and explanation

Correct answer: C

Explanation

The best answer is Option 3 because CCISO-level leadership requires more than identifying technical issues; it requires ethical resolve, executive communication, and disciplined governance. 'Courage of your convictions' means the CISO must not dilute or suppress material security concerns due to political pressure or fear of damaging relationships. At the same time, the CISO should not act outside governance by making unilateral business decisions or reacting emotionally. The proper response is to present the risk clearly, translate technical weaknesses into business impact, recommend treatment options, and ensure risk acceptance is formally made by the appropriate authority.

This aligns with widely accepted governance and risk management practices reflected in frameworks such as ISO/IEC 27001 and ISO 31000, which emphasize risk treatment, accountable ownership, and informed decision-making. It also aligns with board-level governance principles found in sources like COBIT, where management decisions on risk must be transparent, documented, and aligned with enterprise objectives. In regulated sectors such as financial services, unresolved weaknesses in authentication and fraud controls may also create legal, regulatory, and consumer protection concerns, increasing the importance of escalation and documented accountability.

A mature CISO demonstrates courage not by being combative, but by being steadfast, evidence-driven, and willing to elevate uncomfortable truths through proper channels when pressure is applied.

  • A. Incorrect.

    This is incorrect because merely sending an email is not sufficient demonstration of executive-level risk leadership. A CCISO is expected to ensure material risks are presented through established governance and risk management processes, especially when customer trust, fraud exposure, and potentially regulatory obligations are involved. Deferring without ensuring proper review and formally authorized risk acceptance reflects passive compliance rather than principled leadership.

  • B. Incorrect.

    This is incorrect because immediate resignation is typically an extreme response and not the best first action. Courage of conviction does not mean acting impulsively or abandoning governance responsibilities. A strong CISO should first use formal escalation, articulate the business and security implications, recommend risk treatment options, and ensure accountable decision-making. Resignation may become relevant only if leadership repeatedly demands unethical or unlawful conduct and governance mechanisms fail.

  • C. Correct.

    This is correct because it reflects the balance expected from a chief information security officer: principled resistance to unsafe decisions, use of enterprise governance, and clear accountability. Courage of conviction in a CCISO context means standing by evidence-based security concerns, communicating them in business terms, and escalating appropriately when pressure is applied. It also means not unilaterally blocking the business without process, but ensuring that any residual risk is knowingly accepted by the proper authority, such as a risk committee, executive committee, or board depending on the organization's governance model.

  • D. Incorrect.

    This is incorrect because allowing a known high-risk launch to proceed without formal escalation undermines the CISO's duty to protect the enterprise and advise leadership. This option reflects conflict avoidance rather than leadership. It also increases the chance of preventable fraud, customer harm, compliance issues, and reputational damage. Postponing remediation until later is a common but flawed rationalization when material control deficiencies are already known.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam