712-50 exam dumps

712-50 practice question 18 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 18

Single answerUnderstand the role of the governing board and the CISO's role in supporting the board

A newly appointed CISO is preparing for the first quarterly cyber risk update to the governing board of a multinational company. Recent internal audits found inconsistent third-party risk reviews and delayed remediation of critical vulnerabilities in several business units. The board has asked the CISO to clarify management's security posture and identify where board attention is needed. Which approach should the CISO take to best support the governing board while respecting the board's oversight role?

  1. A

    Provide a business-focused summary of enterprise cyber risk, including risk trends, material exposures, management's remediation plans, and specific decisions or risk acceptance items requiring board oversight

  2. B

    Present detailed firewall rule changes, vulnerability scan outputs, and security tool configurations so the board can directly validate whether technical controls are implemented correctly

  3. C

    Ask the board to approve the operational remediation schedule for each affected business unit so accountability for execution is shared at the board level

  4. D

    Limit the presentation to compliance status against security policies because the board's primary responsibility is to confirm that management is following internal standards

Show answer and explanation

Correct answer: A

Explanation

The best answer is the option that frames cybersecurity in terms the board can govern: enterprise risk, business impact, trends, remediation status, and matters requiring oversight or decision. In widely accepted governance practice, the board is accountable for oversight of strategy, risk appetite, and major risk decisions, while management is responsible for designing, implementing, and operating controls. The CISO's role is to support the board by providing timely, accurate, and decision-useful reporting, not to shift operational execution to directors or overwhelm them with technical detail. This approach aligns with common governance principles reflected in sources such as the NIST Cybersecurity Framework 2.0 Govern function, ISO/IEC 27014 guidance on governance of information security, and board governance practices that distinguish oversight from management responsibility.

  • A. Correct.

    Correct. The governing board's role is oversight, direction, and risk governance rather than day-to-day security operations. A strong board-level update should translate technical issues into enterprise risk, business impact, trend information, management actions, and any matters requiring board review such as risk appetite concerns, material residual risk, resource trade-offs, or formal risk acceptance above management thresholds. This enables the board to fulfill its governance duty without pulling it into operational management.

  • B. Incorrect.

    Incorrect. This reflects a common misconception that effective board reporting should be highly technical. Boards generally need concise, decision-oriented information tied to business risk, strategic impact, and governance implications. Technical artifacts such as raw scan outputs and firewall rules are appropriate for security operations or audit teams, not for board oversight except in rare deep-dive situations.

  • C. Incorrect.

    Incorrect. While the board should oversee whether management is effectively addressing significant cyber risk, approving detailed remediation schedules for each business unit moves the board into management's operational role. The CISO should preserve management accountability for execution and escalate only material issues, exceptions, or decisions that exceed delegated authority or risk tolerance.

  • D. Incorrect.

    Incorrect. Compliance reporting may be one input, but board oversight is broader than policy conformance. Boards are concerned with enterprise risk exposure, resilience, legal and regulatory implications, strategic alignment, and whether management's security program is adequate for the organization's risk appetite. Focusing only on internal compliance can obscure material business risk.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam