712-50 exam dumps

712-50 practice question 191 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 191

Single answerBehavioral decision making

A newly appointed CISO is preparing to present a major security investment proposal to the executive committee. In prior meetings, business leaders repeatedly deferred funding because no major breach had occurred at the company, and they focused instead on short-term revenue targets. The CISO wants to improve the quality of the committee's decision making by addressing the behavioral biases influencing the discussion. Which approach is MOST effective?

  1. A

    Frame the proposal using quantified business impact scenarios, including probable loss exposure, operational disruption, and regulatory consequences, and compare those against the cost of the proposed controls

  2. B

    Emphasize that peer organizations have recently increased security spending and recommend matching their budgets to avoid appearing less mature than competitors

  3. C

    Present a highly technical threat briefing to demonstrate the sophistication of current attacks and allow executives to infer the need for investment

  4. D

    Ask the committee to approve the full budget immediately because delaying the decision increases the chance that a future breach will be attributed to executive negligence

Show answer and explanation

Correct answer: A

Explanation

In CCISO practice, behavioral decision making requires the security leader to recognize how cognitive biases affect executive risk decisions and to structure communication to improve judgment. In this scenario, the committee is displaying signs of normalcy bias ('nothing bad has happened yet'), optimism bias, and possibly present bias by prioritizing short-term revenue over less visible future losses. The most effective response is to reframe the decision in terms executives routinely use: probable financial loss, business interruption, legal and regulatory impact, and risk reduction relative to cost.

This is consistent with established risk management and governance practices found in frameworks such as NIST SP 800-30 for risk assessment, FAIR for financial risk analysis, and board-level cyber governance guidance from organizations such as NIST and ISACA. These sources emphasize translating technical risk into business impact to support informed decision making. Benchmarking peers can be supplementary, but it should not replace organization-specific risk analysis. Likewise, technical detail alone rarely changes board decisions unless it is tied directly to enterprise objectives and risk appetite.

  • A. Correct.

    Correct. This approach directly addresses common behavioral decision-making problems such as normalcy bias, optimism bias, and availability bias by making risk concrete, relevant, and tied to business outcomes. Executives make better decisions when cyber risk is translated into financial exposure, operational impact, and compliance consequences rather than abstract technical threats. Using quantified scenarios and a cost-versus-risk-reduction comparison also supports rational governance and aligns with enterprise risk management practices.

  • B. Incorrect.

    Incorrect. While peer benchmarking can be useful as supporting context, this option primarily appeals to social proof and herd behavior rather than improving decision quality. Matching competitor spending does not necessarily reflect the organization's own risk appetite, threat exposure, control maturity, or business objectives. It may reinforce bias instead of mitigating it.

  • C. Incorrect.

    Incorrect. A technical threat briefing may increase awareness, but it does not effectively counter the executives' tendency to discount low-salience or non-immediate risks. Senior leaders generally need decisions framed in business terms. Relying on executives to infer the investment case from technical detail often leads to misunderstanding, disengagement, or continued deferral.

  • D. Incorrect.

    Incorrect. This option uses fear and pressure rather than sound decision support. Although delay can increase exposure, forcing immediate approval by implying future blame is not an effective or mature way to improve behavioral decision making. It may trigger defensiveness, reduce trust, and weaken governance discipline.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam