712-50 exam dumps

712-50 practice question 222 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 222

Single answer

A newly appointed CISO is leading the design and implementation of an enterprise information security program after the company acquired three regional businesses. Security responsibilities are fragmented, duplicate tools exist across business units, and the board has approved only a modest first-year budget increase. The CIO wants rapid standardization, while business unit leaders insist that local operational needs must be preserved. To secure the resources needed for a successful program, the CISO must propose a staffing and technology plan for executive approval. Which action should the CISO take FIRST to most effectively negotiate and acquire the right mix of people, infrastructure, and architectural support?

  1. A

    Develop a risk-based target operating model that maps required security capabilities to business priorities, identifies resource gaps across people, processes, and technology, and uses that analysis to justify phased funding and staffing

  2. B

    Standardize immediately on the most feature-rich security platform across all acquired entities so the organization can reduce tool sprawl before assessing staffing implications

  3. C

    Request that each business unit fund its own security resources independently so implementation can proceed in parallel without waiting for enterprise agreement

  4. D

    Hire additional security engineers first, because resource shortages are usually caused by insufficient technical staff rather than architectural inconsistency

Show answer and explanation

Correct answer: A

Explanation

The best answer is to start with a risk-based target operating model and gap analysis. At the CCISO level, resource negotiation is not primarily about asking for more tools or staff in isolation; it is about translating business strategy, acquisition realities, and risk appetite into a defensible security operating model. In this scenario, the CISO must reconcile competing stakeholder interests, limited budget, duplicated infrastructure, and varied local requirements. A target operating model helps determine which capabilities should be centralized, federated, or retained locally, and what resources are required across people, infrastructure, and architecture.

This approach aligns with widely accepted security and governance practices. NIST Cybersecurity Framework 2.0 emphasizes governance, organizational context, prioritization, and improvement planning based on business needs and risk. COBIT supports aligning enterprise goals, governance objectives, and resource optimization. SABSA and other enterprise security architecture approaches similarly stress deriving security architecture and capability requirements from business drivers before selecting technologies. In practice, executive approval is more likely when the CISO presents phased investments tied to measurable risk reduction, integration milestones, and operating efficiency rather than isolated requests for headcount or tools.

  • A. Correct.

    Correct. A risk-based target operating model is the strongest first step because it links resource acquisition directly to business objectives, integration priorities, and measurable capability gaps. This allows the CISO to negotiate credibly with executives by showing what skills, platforms, and architectural decisions are required, what can be centralized, and what should remain locally tailored. It also supports phased implementation when budget is constrained, which is common in post-acquisition environments.

  • B. Incorrect.

    Incorrect. Tool rationalization may eventually be appropriate, but choosing a platform first is premature. Without understanding business requirements, control gaps, integration constraints, operating model implications, and staffing needs, the organization risks buying expensive technology that does not align to enterprise architecture or actual risk priorities. This reflects the common misconception that technology standardization alone solves security program fragmentation.

  • C. Incorrect.

    Incorrect. Decentralized funding may appear to accelerate implementation, but it usually reinforces inconsistency, duplicates spend, and weakens enterprise governance. In a newly consolidated organization, the CISO should first establish enterprise security capability requirements and governance principles before allowing business-unit-specific exceptions. This option fails to create a coherent resource strategy.

  • D. Incorrect.

    Incorrect. Additional engineers may be needed, but hiring before assessing capability gaps and future-state architecture can lead to misaligned roles, overstaffing in some areas, and underinvestment in governance, architecture, or program management. The misconception here is that people shortages are the primary problem when, in reality, effective resource management requires balancing personnel, infrastructure, and architectural design.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam