712-50 exam dumps

712-50 practice question 190 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 190

Single answerBehavioral decision making

A newly appointed CISO is reviewing the company's cyber investment process after two consecutive years of overspending on highly visible security tools while basic control gaps remained unresolved. In the latest budget meeting, business executives pushed for a large investment in an advanced threat hunting platform because a competitor was recently featured in the news after a ransomware incident. Internal assessment data, however, shows the organization's most significant risks stem from poor third-party access governance, weak patching discipline, and inconsistent backup testing. Which action should the CISO take FIRST to improve decision quality and reduce behavioral bias in the investment process?

  1. A

    Approve the threat hunting platform because peer incidents indicate the company is likely to face the same attack next

  2. B

    Reframe the discussion around quantified enterprise risk, using internal loss scenarios, control effectiveness data, and agreed risk appetite to prioritize funding

  3. C

    Split the budget evenly between the advanced platform and the known control gaps to satisfy both executive concerns and security operations

  4. D

    Delay all security spending until the executive team completes additional cyber awareness training on cognitive bias

Show answer and explanation

Correct answer: B

Explanation

This question tests the candidate's ability to recognize how behavioral factors distort executive security decisions and how a CCISO should respond. The strongest first step is to implement a structured, risk-based decision process that uses objective internal data, loss scenarios, control effectiveness, and risk appetite. In this scenario, executives are reacting to a salient external event, a classic example of availability bias and potentially social proof or bandwagon thinking. A mature CISO should redirect the discussion toward enterprise risk management principles, ensuring security investments are prioritized based on the organization's actual exposure and expected risk reduction. This aligns with widely accepted best practices in information security governance and risk management, including the need for security strategy to support business objectives, risk appetite, and measurable control improvement. Frameworks such as NIST CSF, ISO/IEC 27001 and 27005, and general ERM practices all support evidence-based prioritization over reactive spending driven by recent events or competitor behavior.

  • A. Incorrect.

    This is incorrect because it reflects availability bias and herd behavior. A recent incident affecting a competitor may make a threat feel more urgent, but that does not mean it is the most material risk to this organization. Effective security leadership requires grounding investment decisions in the organization's own risk profile, threat exposure, control maturity, and business impact rather than reacting to headlines.

  • B. Correct.

    This is correct because it directly addresses behavioral decision-making weaknesses by shifting the conversation from emotionally salient events to evidence-based prioritization. A CISO should use internal risk assessments, likely loss scenarios, known control deficiencies, and board-approved risk appetite to structure decisions. This reduces the influence of availability bias, recency bias, and social proof while aligning spending to enterprise objectives and actual risk reduction.

  • C. Incorrect.

    This is incorrect because it is a compromise approach that may appear politically balanced but is not necessarily risk-informed. Equal allocation can be a form of anchoring or appeasement rather than sound prioritization. If internal data shows foundational controls represent the largest exposure, diverting material funds to a lower-priority capability may leave the highest risks untreated.

  • D. Incorrect.

    This is incorrect because training executives on cognitive bias may be helpful over time, but it is not the first operational step needed to improve the immediate investment decision. The CISO's primary responsibility is to establish a disciplined decision framework for current resource allocation. Deferring necessary security spending could increase exposure and does not itself correct the underlying governance issue.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam