712-50 exam dumps

712-50 practice question 241 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 241

Single answerResolve personnel and teamwork issues within time, cost, and quality constraints

A CISO is leading a critical identity and access management (IAM) remediation program after an audit found excessive privileged access across several business units. The board has mandated that the highest-risk findings be closed within 90 days, but the program is behind schedule. Tension has escalated between the security architecture team and the infrastructure team: each claims the other is causing delays, key engineers are skipping joint design meetings, and defect rework is increasing. The budget has little room for adding staff, and the audit deadline cannot move. What should the CISO do FIRST to resolve the personnel and teamwork issues while still protecting time, cost, and quality objectives?

  1. A

    Replace the infrastructure manager immediately and bring in an external consulting team to accelerate delivery

  2. B

    Escalate the conflict to the CEO and request a deadline extension so the teams can work through their disagreements

  3. C

    Establish a joint remediation governance structure with clear accountability, decision rights, and measurable deliverables, then facilitate a focused root-cause session to remove collaboration blockers

  4. D

    Split the program into separate workstreams so each team can deliver independently with minimal interaction

Show answer and explanation

Correct answer: C

Explanation

The best first action for a CCISO in this scenario is to restore governance and cross-functional execution discipline rather than immediately restructuring staff, escalating upward, or isolating teams. Senior security leaders are expected to resolve personnel and teamwork issues in a way that balances time, cost, and quality constraints. In practice, that means clarifying ownership, aligning incentives, defining decision-making authority, establishing measurable milestones, and addressing the root causes of conflict.

This approach is consistent with widely accepted leadership and program-management practices. Governance mechanisms such as clear accountability matrices, formal issue escalation, milestone tracking, and risk-based prioritization are standard ways to reduce rework and improve delivery predictability. PMBOK-style project management guidance emphasizes that unresolved stakeholder conflict, role ambiguity, and poor communications are major causes of schedule slippage and quality defects. Similarly, COBIT governance principles stress clear roles, responsibilities, and decision structures to ensure enterprise objectives are met. From an information security leadership perspective, NIST CSF 2.0's Govern function also reinforces the importance of defined organizational roles, responsibilities, and oversight for cybersecurity outcomes.

In a CCISO context, the leader should first stabilize execution with a structured intervention: convene the accountable leaders, define what must be delivered by the audit deadline, assign owners for each high-risk finding, set quality criteria, document dependencies, and create a rapid escalation path for blockers. This is more cost-effective than immediate staff replacement, more responsible than premature executive escalation, and safer than separating interdependent teams. The goal is not just to reduce conflict, but to convert conflict into coordinated delivery that meets the remediation deadline without compromising control quality.

  • A. Incorrect.

    This is not the best first action. Replacing a manager immediately is a drastic personnel intervention without first validating whether the root cause is leadership failure, unclear roles, poor process design, conflicting priorities, or unresolved technical dependencies. Bringing in consultants also increases cost and may not address the underlying teamwork issue quickly enough. A CCISO is expected to manage within cost constraints and first apply governance, accountability, and conflict-resolution mechanisms before resorting to high-cost structural changes.

  • B. Incorrect.

    This is a weak first response because it externalizes the problem before the CISO has exercised leadership to resolve it. Escalation to the CEO and asking for a deadline extension may be necessary only if risk, resourcing, or enterprise constraints truly make delivery infeasible after corrective action. On a certification-level leadership question, prematurely escalating signals poor ownership and can undermine confidence. The board has already set a fixed deadline, so the better first move is to restore execution discipline and cross-functional alignment.

  • C. Correct.

    This is the best answer. The scenario shows classic delivery breakdowns caused by poor coordination, unclear ownership, and unresolved inter-team conflict. A joint governance structure with defined accountability (for example, using a RACI-style approach), explicit decision rights, issue escalation paths, milestone-based deliverables, and shared success criteria directly addresses teamwork failure while preserving schedule, budget, and quality. Facilitating a root-cause session helps uncover whether the delays stem from unclear requirements, architecture disagreements, resource contention, or communication gaps. This is the most balanced leadership response because it targets the cause of rework and missed meetings rather than just the symptoms.

  • D. Incorrect.

    This is plausible but incorrect because it reduces communication at the exact point where integration and shared decision-making are most needed. IAM remediation often depends on coordinated work across architecture, infrastructure, operations, and business stakeholders. Splitting the effort into isolated workstreams can worsen quality problems, create inconsistent technical decisions, and increase rework when outputs must eventually be integrated. It may appear to improve speed, but it typically sacrifices quality and increases downstream delay.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam