712-50 exam dumps

712-50 practice question 200 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 200

Single answerIdentify the organization's operational process and objectives

A newly hired CISO at a global manufacturing company has been asked to build a three-year security strategy. The board is concerned about ransomware, but the CEO emphasizes that the company’s competitive advantage depends on maintaining uninterrupted production, meeting customer delivery commitments, and protecting proprietary design data shared with contract manufacturers. The security team proposes several initiatives, but the CISO first wants to ensure the strategy is aligned to the organization’s operational processes and business objectives. Which action should the CISO take FIRST?

  1. A

    Map critical business services and operational workflows to supporting assets, dependencies, and business outcomes before prioritizing security investments

  2. B

    Deploy additional endpoint detection and response tools across all corporate and plant environments to reduce ransomware risk immediately

  3. C

    Adopt a zero trust architecture roadmap based on industry trends and require all business units to conform to it

  4. D

    Benchmark the security program against peer manufacturers and prioritize any controls that competitors have already implemented

Show answer and explanation

Correct answer: A

Explanation

This question tests whether the candidate understands that a CISO must begin with the business, not the technology. In CCISO practice, security strategy should be built from an understanding of mission-critical operations, value streams, supporting assets, third-party dependencies, and executive objectives. Only then can the CISO determine which risks matter most and which controls best support resilience, confidentiality, and operational continuity.

The best answer is to map critical business services and operational workflows to assets, dependencies, and business outcomes. This aligns with established security and risk management practices. NIST Cybersecurity Framework (CSF) 2.0 emphasizes understanding organizational context, mission objectives, stakeholders, and critical services before selecting and prioritizing cybersecurity outcomes. Similarly, NIST SP 800-39 and common enterprise risk management approaches stress framing risk in business terms, including mission, functions, and dependencies. ISO/IEC 27001 and ISO 22301 also support understanding the organization, its interested parties, and business continuity priorities before implementing controls.

In practical terms, for a manufacturing company, this means identifying which production lines, ERP processes, engineering systems, supplier connections, and design collaboration platforms are essential to revenue, delivery commitments, safety, and intellectual property protection. Once these are known, the CISO can prioritize investments such as segmentation, backup resilience, OT monitoring, supplier risk management, or data protection based on business impact rather than fear, trends, or peer pressure.

  • A. Correct.

    Correct. Before selecting or prioritizing security initiatives, the CISO should identify how the organization actually operates: which business services are most critical, how production and supply-chain workflows function, what assets and third parties support them, and which outcomes matter most to leadership. This creates the necessary business context for risk-based prioritization. In this scenario, uninterrupted production, delivery performance, and protection of design data are explicit business objectives, so mapping operational processes to these objectives is the right first step.

  • B. Incorrect.

    Incorrect. Expanding endpoint detection and response may be valuable, especially given the board’s ransomware concern, but doing so first risks optimizing for a single threat without understanding which operational processes are most critical and where control gaps create the greatest business impact. This is a common mistake: leading with technology deployment before establishing business context and criticality.

  • C. Incorrect.

    Incorrect. Zero trust can be an appropriate strategic direction, but adopting it first because it is an industry trend is not the same as aligning security to the company’s operational objectives. A CISO should derive architecture decisions from business requirements, operational realities, and risk tolerance rather than imposing a model before understanding the organization’s key processes and constraints, especially in mixed corporate and operational technology environments.

  • D. Incorrect.

    Incorrect. Peer benchmarking can help validate maturity and support board discussions, but it should not be the starting point for strategy. Competitor controls do not necessarily reflect this organization’s unique production dependencies, intellectual property exposure, customer obligations, or risk appetite. Choosing controls because peers use them is a maturity comparison exercise, not an objective-driven method for identifying the organization’s operational process and objectives.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam