712-50 exam dumps

712-50 practice question 230 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 230

Single answer

A global manufacturing company launches a 12-month identity and access management (IAM) modernization project to satisfy audit findings, reduce provisioning delays, and support a new acquisition. Six months into the project, the CISO learns that costs are already at 80% of the approved budget, several custom workflow changes have been added at the request of regional managers, and the project team reports progress mainly in terms of completed technical tasks. Meanwhile, internal audit notes that success criteria tied to business outcomes and risk reduction were never formally baselined. As the executive responsible for security governance, which action should the CISO take FIRST to determine whether project management practices and controls are ensuring business requirements are met cost-effectively while managing organizational risk?

  1. A

    Direct the team to continue execution but submit weekly status reports focused on percentage complete, so budget overruns can be monitored more closely

  2. B

    Initiate an independent project review to validate scope, business case alignment, benefit realization measures, risk register quality, and change control effectiveness before approving further major spending

  3. C

    Approve the requested custom workflow changes because they improve regional stakeholder satisfaction and can be justified after go-live if audit issues are reduced

  4. D

    Escalate the budget overrun to the board risk committee immediately and request cancellation of the project until a new funding cycle is approved

Show answer and explanation

Correct answer: B

Explanation

The best first step is to perform a structured project governance review focused on whether the initiative remains aligned with business requirements and is being delivered in a cost-effective, risk-managed manner. At the executive level, the CISO should look beyond technical milestones and examine whether the project has defined success criteria, measurable business outcomes, a maintained business case, effective change control, and a current risk register with assigned owners and treatment plans. This aligns with widely accepted governance and project management practices reflected in COBIT's emphasis on benefits realization, risk optimization, and resource optimization, as well as PMBOK principles covering scope, cost, schedule, risk, and stakeholder management. In security programs, benefit realization should include operational and control outcomes such as reduced provisioning time, audit remediation, segregation-of-duties improvements, and acquisition integration readiness. Without these baselines and controls, task completion reporting can mask significant governance failure.

  • A. Incorrect.

    This is incorrect because tracking percentage complete alone is a weak control if the project is not tied to baselined business outcomes, risk reduction targets, scope discipline, and benefit realization metrics. A project can appear on track operationally while still failing to deliver value or managing risk effectively. This option improves reporting frequency but does not address the underlying governance gaps.

  • B. Correct.

    This is correct because the immediate need is to evaluate whether project management practices and controls are still aligned to the approved business case, risk appetite, and expected benefits. An independent review should assess scope management, benefit realization criteria, risk register completeness, change control, and whether customization requests are eroding cost-effectiveness. This provides a fact-based basis for corrective action before additional funds are committed.

  • C. Incorrect.

    This is incorrect because approving additional customization without validating business value, total cost impact, implementation risk, and control implications is a classic example of scope creep. Stakeholder satisfaction is important, but governance requires formal change evaluation against business requirements, budget, timeline, and risk exposure. Deferring justification until after go-live weakens accountability.

  • D. Incorrect.

    This is incorrect because immediate escalation for cancellation is premature without first establishing whether the issues can be corrected through stronger governance, scope control, and reprioritization. Board-level escalation may become necessary, but the CISO should first obtain an evidence-based assessment of project health and alignment rather than moving directly to termination.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam