712-50 exam dumps

712-50 practice question 231 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 231

Single answer

A global manufacturer is midway through a 12-month identity and access management (IAM) modernization project intended to satisfy three business requirements: reduce help-desk password reset costs by 30%, enable faster onboarding for acquisitions, and meet regulatory expectations for privileged access control. At the month-6 steering committee review, the CISO learns that the project is 20% over budget, the project manager reports the timeline is still achievable, and the security architect proposes adding several advanced analytics features that were not in the original business case. The business sponsor is concerned that the project may deliver a technically impressive solution without achieving the cost-reduction target. As the executive responsible for evaluating project management practices and controls, what is the MOST appropriate action for the CISO to take FIRST?

  1. A

    Require the team to perform a formal benefits-realization and scope review against the approved business case, including validation of cost, risk reduction, and required deliverables before approving any additional features

  2. B

    Approve the advanced analytics features because they improve security maturity and can be justified as strategic enhancements even if they increase project cost

  3. C

    Direct the project manager to keep the original scope and timeline unchanged and recover the budget overrun during operational handoff after implementation

  4. D

    Escalate immediately to the board audit committee and recommend pausing the project until a full independent technical penetration test is completed

Show answer and explanation

Correct answer: A

Explanation

This scenario tests executive-level oversight of security program delivery, not technical implementation detail. In CCISO practice, the CISO must ensure project management practices include clear business cases, defined success metrics, stage-gate reviews, change control, risk management, and benefits realization tracking. When a project is over budget and new features are being proposed, the first priority is to determine whether the project still supports the approved business requirements and whether scope changes are justified. This aligns with common governance principles found in PMI project governance, COBIT performance and conformance monitoring, and benefits realization practices used in portfolio management. A mature approach would review the original business case, verify KPIs such as help-desk cost reduction and onboarding efficiency, assess whether regulatory privileged-access requirements remain covered, and require formal approval for any scope expansion. The goal is to ensure the project delivers required risk reduction and business value without uncontrolled cost growth or gold-plating.

  • A. Correct.

    Correct. The primary issue is whether the project is still aligned to the approved business case and whether project controls are effectively ensuring that business requirements are achieved in a cost-effective manner while managing risk. A formal benefits-realization and scope review is the best first step because it evaluates whether the project remains justified, whether scope creep is occurring, and whether proposed enhancements support measurable business outcomes. This is consistent with established governance and portfolio management practices that require periodic revalidation of expected benefits, costs, risks, and success criteria at major stage gates.

  • B. Incorrect.

    Incorrect. Although improved security capabilities may be desirable, approving features outside the original business case without reassessing cost-benefit and risk is poor governance. This reflects a common misconception that more security functionality is automatically better. In executive project oversight, added controls must be justified by business need, risk treatment objectives, and affordability. Otherwise, the organization may fund complexity that undermines the original value proposition.

  • C. Incorrect.

    Incorrect. Preserving schedule optics while ignoring budget variance and emerging misalignment to business objectives is not sound project governance. Recovering overruns later through operations is also problematic because it shifts project costs without validating whether the delivered solution will meet the approved business outcomes. This option reflects the misconception that delivery against schedule alone proves project success.

  • D. Incorrect.

    Incorrect. Immediate escalation to the board and a project pause for a penetration test is disproportionate based on the facts presented. The key concern is benefits realization, cost control, and scope management, not evidence of a specific technical vulnerability requiring urgent assurance testing. A penetration test may be appropriate later in the lifecycle, but it does not address whether the project is delivering the right outcomes in a cost-effective manner.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam