712-50 exam dumps

712-50 practice question 185 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 185

Single answerNegotiation, Mediation, and Alternative Conflict Resolution

A newly appointed CISO is leading a high-stakes dispute between the security team and the head of product development. Security wants to delay the launch of a customer-facing application until critical authentication and logging weaknesses are remediated. Product development argues that missing the quarter-end launch will trigger contractual penalties and loss of market credibility. The CEO instructs the CISO to resolve the conflict quickly without damaging long-term collaboration between the teams. What is the MOST appropriate course of action for the CISO?

  1. A

    Escalate the issue immediately to the board and request a binding decision, since senior leadership authority is the fastest way to end the dispute.

  2. B

    Use an interest-based negotiation approach: clarify each side's underlying business and risk concerns, develop compensating controls and phased remediation options, and seek a mutually acceptable decision aligned to risk appetite.

  3. C

    Allow product development to proceed with launch because revenue impact is more tangible than security risk, then document security's objection for audit purposes.

  4. D

    Act as a neutral mediator by avoiding any recommendation, limiting discussion to each side's stated position, and letting the teams resolve the matter without reference to enterprise risk tolerance.

Show answer and explanation

Correct answer: B

Explanation

The strongest executive response is to use principled or interest-based negotiation to move the conversation from positional conflict ('delay launch' versus 'launch now') to enterprise interests such as acceptable risk, contractual exposure, customer trust, and operational feasibility. In practice, the CISO should identify the severity of the weaknesses, determine whether compensating controls can reduce risk temporarily, evaluate phased rollout options, and ensure that any residual risk is accepted by the correct authority under the organization's governance model. This reflects established security governance and risk management practices found in frameworks such as NIST's risk management guidance and ISACA/COBIT governance principles, which emphasize informed decision-making, accountability, and alignment of security with business objectives. Mediation and alternative conflict resolution are most effective when the executive addresses interests, not just positions, and seeks a durable resolution rather than a forced short-term win.

  • A. Incorrect.

    This is not the most appropriate first step. Escalation to the board may be necessary if risk exceeds management authority or if executives remain deadlocked, but immediate escalation bypasses negotiation and can damage working relationships. In executive conflict resolution, the CISO should first attempt structured resolution at the appropriate management level, using enterprise risk criteria and business context. Going straight to the board also suggests failure to perform due diligence in evaluating alternatives such as phased release, compensating controls, or formal risk acceptance.

  • B. Correct.

    This is the best answer. Interest-based negotiation focuses on underlying interests rather than fixed positions. In this scenario, security's interest is reducing material risk, while product's interest is meeting commercial commitments. A strong CISO should reframe the dispute around enterprise objectives, quantify the risk, identify compensating controls, consider phased deployment or feature restriction, and ensure any decision aligns with approved risk appetite and governance processes. This approach preserves collaboration, supports informed decision-making, and reflects executive leadership rather than purely technical objection.

  • C. Incorrect.

    This is incorrect because it subordinates risk management to short-term business pressure without demonstrating that the residual risk is understood, accepted by the proper authority, or reduced through alternatives. While business impact is a legitimate consideration, the CISO's role is not to yield automatically to revenue concerns. Simply documenting an objection may protect the security team procedurally, but it does not resolve the conflict responsibly or support enterprise risk governance.

  • D. Incorrect.

    This is incorrect because the CISO, while needing to facilitate resolution constructively, is not merely a passive mediator in this context. As an executive responsible for cyber risk leadership, the CISO should provide risk-informed recommendations and connect the discussion to business objectives, control requirements, and risk tolerance. Restricting the discussion to stated positions tends to harden conflict rather than resolve it, and excluding reference to risk appetite removes the core decision criterion.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam