712-50 exam dumps

712-50 practice question 182 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 182

Single answerUsing Time and Priorities Decisions

A newly appointed CISO is preparing the annual security plan during a period of constrained budget and limited staff availability. Three issues are competing for immediate attention: (1) an external audit found weak third-party access review controls that could affect regulatory compliance within 60 days, (2) the SOC has requested additional threat-hunting tooling to improve long-term detection capability, and (3) several business units are asking for faster approval of new cloud services to support revenue growth this quarter. The CEO has asked the CISO to demonstrate sound executive decision-making on time and priorities. Which action should the CISO take FIRST?

  1. A

    Prioritize remediation of the third-party access review control gap because it has a defined compliance deadline and potential business impact if left unresolved

  2. B

    Approve the threat-hunting tooling request first because improving detection maturity reduces enterprise risk across all business units

  3. C

    Accelerate cloud service approvals first because revenue-generating initiatives should take precedence over security process improvements

  4. D

    Split resources equally across all three initiatives to show fairness and avoid creating dissatisfaction among stakeholders

Show answer and explanation

Correct answer: A

Explanation

In CCISO-level decision-making, using time and priorities effectively means allocating attention and resources based on risk, urgency, business impact, and mandatory obligations rather than treating all requests as equal. A near-term compliance or audit issue with a defined deadline should generally be addressed before longer-term capability enhancements or noncritical business enablement requests. This aligns with risk-based prioritization principles found in common security governance practices and frameworks such as NIST CSF and NIST SP 800-53, where remediation of identified control deficiencies and governance obligations should be managed according to impact and required timelines. Executive leadership expects the CISO to make defensible tradeoff decisions, communicate sequencing clearly, and ensure that urgent, high-impact issues are handled first.

  • A. Correct.

    Correct. Effective executive prioritization requires balancing urgency, impact, and organizational obligations. A control deficiency tied to a regulatory or audit deadline within 60 days creates a time-bound risk with potential legal, financial, and reputational consequences. In a CCISO context, the CISO should first address items with clear business impact, mandatory timelines, and governance implications. This does not mean the other two issues are unimportant, but time-sensitive compliance gaps generally take precedence when resources are constrained.

  • B. Incorrect.

    Incorrect. Enhancing threat-hunting capability may improve the organization's long-term security posture, but this is primarily a strategic maturity investment rather than the most urgent item in the scenario. A common mistake is to prioritize broadly beneficial technical improvements over a near-term control deficiency with a defined deadline and direct compliance exposure.

  • C. Incorrect.

    Incorrect. Supporting business growth is important, and the CISO should enable the business where possible. However, prioritizing cloud approvals first would underweight a known compliance issue with a specific deadline. The misconception here is that revenue requests should automatically outrank governance and risk obligations; executive prioritization requires considering both strategic value and immediate exposure.

  • D. Incorrect.

    Incorrect. Dividing resources evenly can appear politically balanced, but it is not effective prioritization. Time and priority decisions require deliberate sequencing based on urgency, risk, and business impact. Equal distribution of scarce resources often delays critical remediation and can increase the likelihood of missing mandatory deadlines.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam