712-50 exam dumps

712-50 practice question 181 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 181

Single answerAdaptability, Resilience, and Agility

A global manufacturing company is accelerating cloud adoption and launching connected products in new markets. The board has asked the CISO to improve the security program's adaptability, resilience, and agility after several recent disruptions: a ransomware incident at a regional supplier, a sudden regulatory change affecting data residency, and a critical vulnerability that required emergency patching across hybrid environments. Budget is limited, and business leaders are concerned that additional security controls could slow product releases. Which action should the CISO take FIRST to best strengthen the organization across all three objectives while maintaining business alignment?

  1. A

    Implement a risk-based operating model that defines critical business services, maps dependencies across suppliers and technology platforms, and uses tested playbooks with decision thresholds for rapid response and recovery

  2. B

    Purchase a best-of-breed security toolset for cloud, OT, and endpoint environments before revising existing governance, because technology modernization is the fastest path to resilience

  3. C

    Standardize on a single global security policy and require all business units to follow identical controls and recovery objectives regardless of local regulations or service criticality

  4. D

    Shift most of the security budget from preventive controls to cyber insurance and crisis communications so the organization can absorb disruption without affecting release velocity

Show answer and explanation

Correct answer: A

Explanation

For a CCISO, the most effective first move is to establish a business-aligned, risk-based resilience model rather than defaulting to a technology purchase or broad policy standardization. Adaptability means the organization can adjust to regulatory, threat, and business changes. Resilience means it can continue or quickly restore critical services during disruption. Agility means decisions and responses can occur rapidly without excessive bureaucracy. A service-centric approach achieves all three by identifying mission-critical processes, setting recovery priorities, mapping dependencies including third parties, and preparing tested response and recovery playbooks.

This aligns with widely accepted practices in operational resilience and cybersecurity governance. NIST Cybersecurity Framework 2.0 emphasizes governance, risk-based prioritization, and response/recovery outcomes rather than only technical controls. NIST SP 800-61 highlights prepared incident handling procedures and playbooks. NIST SP 800-160 and SP 800-34 support engineering and contingency planning for resilient systems and recovery. ISO 22301 and ISO/IEC 27001 also reinforce business impact awareness, continuity planning, and risk-based control selection. From a leadership perspective, the CISO should ensure security investments are driven by critical business services and decision-ready processes so the enterprise can adapt to change, absorb shocks, and continue delivering value.

  • A. Correct.

    Correct. A risk-based operating model centered on critical business services is the strongest first step because it improves adaptability, resilience, and agility together. Identifying critical services and mapping business, technology, data, and third-party dependencies allows the CISO to prioritize what must be protected and restored first. Tested playbooks and decision thresholds support agile response to regulatory changes, supplier incidents, and emergency vulnerabilities without relying on ad hoc decisions. This approach also aligns security with business priorities and limited budget by focusing investment where disruption would be most harmful.

  • B. Incorrect.

    Incorrect. Modern tools can help, but buying technology before clarifying governance, critical services, recovery priorities, and dependency mapping is a common mistake. Resilience failures often stem from unclear ownership, poor prioritization, and untested response processes rather than the absence of tools. Without an operating model, new tools may increase complexity and cost without materially improving the organization's ability to adapt or recover.

  • C. Incorrect.

    Incorrect. A uniform global policy may appear efficient, but it reduces adaptability and can conflict with varying regulatory, operational, and business requirements. Criticality-based controls and recovery objectives are more effective than treating all systems and regions the same. Resilience depends on proportionality and context, not rigid standardization where different legal and operational environments exist.

  • D. Incorrect.

    Incorrect. Cyber insurance and communications are supporting mechanisms, not substitutes for operational resilience. Over-shifting budget away from preventive and responsive capabilities weakens the organization's ability to withstand and recover from real incidents. Insurance may offset some financial loss, but it does not restore critical services, manage dependencies, or enable rapid adaptation to changing threats and regulations.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam