712-50 exam dumps

712-50 practice question 186 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 186

Single answerLeading with Problem Solving

A newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weak asset visibility and inconsistent decision-making across business units. The CEO wants rapid improvement, but plant leaders are resisting security controls that could interrupt production. The board has asked the CISO to demonstrate leadership through problem solving rather than simply issuing mandates. Which action should the CISO take FIRST to address the problem in a way that is most likely to gain support and produce sustainable risk reduction?

  1. A

    Implement a uniform set of enterprise security controls immediately across all plants to eliminate inconsistency and show decisive leadership

  2. B

    Facilitate a cross-functional risk assessment with operations, IT, and business leaders to identify critical assets, analyze production-impact scenarios, and prioritize remediation based on business risk

  3. C

    Escalate the resistance from plant leaders to the CEO and request a directive requiring full compliance with the security program

  4. D

    Launch a companywide security awareness campaign focused on ransomware so employees understand the importance of following security policies

Show answer and explanation

Correct answer: B

Explanation

The best answer is to begin with a cross-functional, business-aligned risk assessment. In CCISO practice, leading with problem solving means moving beyond technical fixes or authority-based directives and instead structuring decisions around business objectives, risk appetite, and stakeholder engagement. In this scenario, the CISO must first establish a common understanding of the problem: what assets are critical, where visibility gaps exist, how ransomware would affect production, and which controls reduce risk without unacceptable operational impact.

This approach is consistent with widely accepted security and governance practices. NIST Cybersecurity Framework emphasizes identifying critical assets and business context before selecting and prioritizing protective actions. NIST SP 800-30 supports risk assessment as the basis for informed risk response. ISO/IEC 27001 and ISO 31000 also reinforce risk-based, business-driven decision-making and stakeholder involvement. From a governance perspective, senior security leaders are expected to balance protection with operational realities and obtain buy-in through communication, influence, and prioritization rather than relying first on mandates.

Therefore, the first and most effective leadership action is to convene the right stakeholders, assess risk in business terms, and use that shared analysis to prioritize sustainable remediation.

  • A. Incorrect.

    This is not the best first step. Although standardization can be a long-term objective, immediately imposing uniform controls without understanding operational dependencies, asset criticality, and plant-specific constraints can create business disruption and increase resistance. In a manufacturing environment, abrupt changes may affect safety, uptime, or industrial control processes. This option reflects a command-and-control approach rather than structured problem solving.

  • B. Correct.

    This is correct. Leading with problem solving requires defining the problem collaboratively, understanding root causes, and aligning security action with business priorities. A cross-functional risk assessment helps the CISO identify which assets and processes are most critical, evaluate realistic threat and impact scenarios, and build a remediation roadmap that leaders can support because it is tied to production resilience and enterprise objectives. This approach also strengthens stakeholder ownership and supports risk-based decision-making expected of senior security leadership.

  • C. Incorrect.

    This is plausible but premature. Executive escalation may be appropriate if governance breaks down, but using it as the first move bypasses diagnosis and stakeholder engagement. It may secure short-term compliance, yet it often weakens trust and reduces the quality of local input needed to solve the actual problem. A CCISO-level leader is expected to resolve complex issues through analysis, influence, and alignment before relying on authority.

  • D. Incorrect.

    This is helpful as a supporting measure, but it does not address the central leadership problem. The issue is not primarily lack of awareness; it is competing business priorities, weak asset visibility, and inconsistent risk decisions. Awareness training alone would not identify critical operational assets, clarify acceptable downtime, or determine which security investments should come first. It treats a symptom rather than the core problem.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam