712-50 exam dumps

712-50 practice question 353 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 353

Single answerThreat Management (5 questions)

A global manufacturing company has expanded rapidly through acquisitions and now operates several security tools across business units, including separate SIEMs, endpoint platforms, and network monitoring solutions. The board has asked the CISO to reduce the likelihood of a business-disrupting ransomware incident without significantly increasing next year's budget. Recent internal reviews found that threat intelligence feeds are being purchased by multiple teams, but incident response teams rarely use the intelligence in a timely way, and many alerts are not prioritized by business criticality. Which action should the CISO take FIRST to improve threat management effectiveness at the enterprise level?

  1. A

    Consolidate threat intelligence acquisition and establish a formal process to operationalize intelligence into prioritized detection and response use cases aligned to critical assets

  2. B

    Purchase an additional commercial threat intelligence feed focused on ransomware indicators to improve visibility across newly acquired subsidiaries

  3. C

    Require each business unit to keep its current tools but submit a monthly report of all high-severity alerts to the central security office

  4. D

    Conduct an enterprise-wide ransomware tabletop exercise before making changes to tooling or threat intelligence processes

Show answer and explanation

Correct answer: A

Explanation

This question tests executive-level threat management judgment: the CISO must identify the highest-leverage action that improves enterprise resilience within budget constraints. In this scenario, the organization has tool sprawl, duplicated intelligence purchases, and weak operationalization of threat intelligence. Best practice is to align threat management to business risk by identifying critical assets and business services, then using curated threat intelligence to drive use cases, detection engineering, prioritization, and response. This aligns with widely accepted practices from NIST guidance on cyber threat information sharing and use, NIST Cybersecurity Framework concepts such as Detect and Respond, and risk-based security operating models emphasized in executive security governance. The key leadership decision is to improve process integration and governance first, rather than simply adding tools, data sources, or administrative reporting.

  • A. Correct.

    Correct. The core issue is not lack of raw intelligence, but lack of integration, prioritization, and operational use. At the CCISO level, the most effective first step is to rationalize duplicated intelligence spending and create governance and processes that turn intelligence into actionable detection logic, response playbooks, and prioritization based on business-critical assets. This improves threat management maturity while controlling cost, which directly addresses the board's concern.

  • B. Incorrect.

    Incorrect. Buying another feed is a common but flawed response when the existing problem is failure to operationalize current intelligence. More data will likely increase noise and cost without improving detection or response unless there is a process to curate, map, and apply intelligence to the organization's threat landscape and critical business services.

  • C. Incorrect.

    Incorrect. Monthly reporting is too delayed and administrative to materially reduce ransomware risk. It may improve oversight, but it does not solve fragmented detection, duplicate spending, or the lack of business-context-driven prioritization. Threat management requires timely, actionable coordination rather than retrospective reporting alone.

  • D. Incorrect.

    Incorrect. A tabletop exercise can be valuable for validating preparedness and coordination, but it should not be the first enterprise-level action in this scenario. The review already identified operational gaps in intelligence usage and alert prioritization. Exercising an immature process may reveal issues, but it will not itself remediate the underlying threat management deficiencies.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam