712-50 exam dumps

712-50 practice question 390 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 390

Single answerDomain 5: Strategic Planning, Finance, Procurement, and Third-Party Management (11%)

A global manufacturing company is accelerating its cloud-first strategy and plans to outsource its security monitoring to a managed detection and response (MDR) provider. The CFO has asked the CISO to justify the investment and ensure the procurement decision supports business objectives, regulatory obligations, and long-term cost control. The current procurement team wants to select the lowest-cost bidder that meets the basic technical requirements. As the CISO, which action is MOST appropriate to take FIRST to support a sound third-party security procurement decision?

  1. A

    Require the procurement team to select the bidder with the lowest total contract value, then add security requirements during contract renewal if issues arise

  2. B

    Develop a risk-based evaluation model that weights security controls, service levels, regulatory obligations, financial viability, and exit strategy before vendor selection

  3. C

    Ask each bidder to provide a marketing presentation on threat detection capabilities and choose the provider with the most mature-looking dashboard

  4. D

    Delay the procurement until the internal security team can build an equivalent monitoring capability to compare exact costs and features

Show answer and explanation

Correct answer: B

Explanation

In CCISO Domain 5, senior security leaders are expected to ensure procurement and third-party decisions are aligned with strategy, risk appetite, regulatory obligations, and financial stewardship. The best first step in this scenario is to create a risk-based vendor evaluation framework before selection. This helps the CISO move the discussion from simple price comparison to value, resilience, and risk-adjusted cost. In practice, this framework should assess total cost of ownership, contractual security requirements, SLA performance, incident response responsibilities, data protection terms, financial health, concentration risk, subcontractor dependencies, and termination or transition support. This approach is consistent with widely accepted third-party risk management practices reflected in sources such as NIST SP 800-161 on supply chain risk management, NIST SP 800-53 controls related to external service providers, ISO/IEC 27036 for supplier relationships, and ISO/IEC 27001 Annex A controls for supplier and information security management. From a governance perspective, the CISO should help procurement and finance understand that the cheapest bidder may create higher long-term costs through breaches, compliance failures, poor service quality, or expensive vendor lock-in. Therefore, a structured, risk-informed procurement model is the most appropriate initial action.

  • A. Incorrect.

    This is incorrect because selecting solely on the lowest contract value is a common procurement mistake in security outsourcing. It ignores total cost of ownership, residual risk, contractual enforceability, data handling obligations, incident response commitments, and vendor resilience. Deferring security requirements until renewal is especially risky because key protections such as audit rights, breach notification timelines, logging ownership, data residency, and service levels must be defined before contract execution.

  • B. Correct.

    This is correct because a risk-based evaluation model aligns procurement with enterprise security strategy, fiduciary oversight, and third-party risk management. For an MDR engagement, the CISO should ensure the selection criteria include not only technical capability, but also measurable security controls, SLA commitments, regulatory and privacy obligations, financial stability of the provider, right-to-audit provisions, subcontractor use, reporting metrics, and a clear exit or transition plan. This approach allows the organization to justify the investment to the CFO in business terms while reducing the chance of selecting a vendor that is inexpensive but operationally or legally unsuitable.

  • C. Incorrect.

    This is incorrect because marketing demonstrations are not reliable evidence of operational effectiveness or control maturity. A polished dashboard may create false confidence and can distract decision-makers from validating detection coverage, integration capability, staffing model, incident escalation procedures, contractual commitments, and independent assurance such as SOC reports or comparable assessments. This option reflects a superficial procurement approach rather than a governance-driven one.

  • D. Incorrect.

    This is incorrect because delaying the decision to build an internal equivalent first is not the best initial step when the business is already pursuing an outsourcing strategy. While a make-versus-buy analysis can be useful in strategic planning, the question asks for the most appropriate first action to support procurement. Building an internal capability for comparison would likely be time-consuming and unnecessary. The more effective first step is to establish evaluation criteria tied to risk, cost, compliance, and business outcomes.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam