712-50 exam dumps

712-50 practice question 206 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 206

Single answer

A global manufacturing company recently implemented several security controls after a ransomware incident, including endpoint detection and response (EDR), privileged access management (PAM), network segmentation, and an enhanced vulnerability management process. Six months later, the board asks the CISO to demonstrate whether these controls are effectively reducing business risk and supporting operational objectives such as production uptime and regulatory compliance. The security team currently reports the number of alerts generated, total vulnerabilities identified, and total security spending. Which metric should the CISO prioritize to best measure control performance against organizational objectives?

  1. A

    The total number of security alerts generated by monitoring tools each month

  2. B

    The percentage of critical vulnerabilities remediated within the organization's approved SLA for production systems

  3. C

    The total annual budget spent on security technologies compared with the prior year

  4. D

    The number of security policies reviewed and updated during the last quarter

Show answer and explanation

Correct answer: B

Explanation

The best answer is the metric that demonstrates whether a control is reducing risk in a way that matters to the business. In this scenario, the board wants evidence that implemented controls are improving resilience, production uptime, and compliance. Effective CCISO-level metrics should be outcome-oriented, aligned to business objectives, measurable over time, and tied to risk treatment. The percentage of critical vulnerabilities remediated within SLA for production systems satisfies those criteria because it reflects exposure reduction in high-value assets and supports both operational continuity and compliance expectations.

By contrast, counts such as alerts generated, dollars spent, or policies reviewed are often useful supporting metrics but are not strong KPIs for executive decision-making because they measure activity or input rather than effectiveness. This aligns with widely accepted practices from sources such as NIST SP 800-55 on performance measurement, which emphasizes metrics that support decision-making and assess effectiveness and efficiency, and NIST Cybersecurity Framework guidance, which encourages measurement tied to organizational outcomes. From an ISACA and governance perspective, metrics should also support risk oversight, demonstrate whether controls operate within tolerance, and enable corrective action when targets are missed.

  • A. Incorrect.

    Incorrect. Alert volume is primarily an operational activity metric, not a strong indicator of whether controls are reducing business risk or supporting objectives. A higher or lower number of alerts may reflect tuning changes, logging scope, or threat activity rather than actual control effectiveness. Executives can be misled by this metric because it measures system output, not risk reduction or performance against defined business outcomes.

  • B. Correct.

    Correct. The percentage of critical vulnerabilities remediated within the approved SLA for production systems is a strong KPI because it links control performance to risk treatment, timeliness, and business impact. It measures whether the vulnerability management control is operating effectively in the systems most important to production uptime and compliance. This metric is actionable, aligned to risk appetite and service expectations, and can be trended over time to demonstrate whether the organization is reducing exposure in a meaningful way.

  • C. Incorrect.

    Incorrect. Security spend is a financial input metric, not a measure of control effectiveness. Increased spending does not necessarily result in improved risk posture, and decreased spending does not automatically indicate weaker controls. This is a common executive reporting mistake: tracking investment levels rather than measurable outcomes tied to risk reduction and business objectives.

  • D. Incorrect.

    Incorrect. Policy review activity can support governance and compliance, but the number of policies updated does not show whether technical or administrative controls are performing effectively. It is an example of a completion metric rather than a performance KPI. Someone might choose it because governance documentation is important, but by itself it does not indicate whether ransomware-related risk is being reduced.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam