712-50 exam dumps

712-50 practice question 397 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 397

Single answer

A newly appointed CISO at a regional healthcare provider is asked to revise the information security program to support the organization's three-year strategy: expand telehealth services, enter two new states through acquisition, and improve patient retention in a highly competitive market. External analysis shows increasing ransomware activity against healthcare entities, stricter state privacy requirements, and customer expectations for seamless digital access. Internal analysis shows limited third-party risk management maturity, inconsistent security metrics across acquired business units, and a constrained budget. Which action should the CISO take FIRST to best align the security program with the organization's objectives?

  1. A

    Implement a uniform set of advanced security tools across all business units to quickly raise the overall security baseline before expansion

  2. B

    Develop an enterprise security strategy based on a prioritized risk assessment that maps external market and regulatory drivers, acquisition-related integration risks, and internal capability gaps to business objectives

  3. C

    Benchmark the organization's security spending against competitors and request a budget increase to match the industry average for healthcare providers pursuing digital transformation

  4. D

    Launch an organization-wide security awareness campaign focused on phishing and ransomware because healthcare is a top target sector

Show answer and explanation

Correct answer: B

Explanation

At the executive level, the CISO should begin by translating business strategy into security strategy through structured external and internal analysis. External analysis includes customers, competitors, market conditions, threat trends, and legal/regulatory developments. Internal analysis includes risk posture, security capabilities, governance maturity, integration readiness, third-party oversight, and performance measurement. The best answer is the one that creates a risk-prioritized roadmap tied directly to organizational objectives, rather than jumping immediately to tools, spending comparisons, or isolated controls. This approach is consistent with widely recognized practices in NIST CSF 2.0 Govern and Identify functions, ISO/IEC 27001 and 27014 governance principles, and enterprise risk management concepts that require security investment decisions to be traceable to business goals, risk appetite, and compliance obligations.

  • A. Incorrect.

    This is not the best first step. Standardizing tools may eventually be useful, but selecting and deploying technology before understanding business priorities, external obligations, and internal capability gaps can misallocate limited resources. In a multi-entity healthcare environment, premature tool consolidation can also disrupt acquisitions and overlook regulatory differences between states.

  • B. Correct.

    This is correct. The scenario requires aligning the information security program to strategic objectives using both external and internal analysis. A prioritized, enterprise-level strategy that explicitly links market expansion, telehealth growth, state privacy obligations, ransomware risk, acquisition integration, third-party risk weakness, and measurement gaps to business goals is the most appropriate first action. This enables the CISO to sequence investments based on business impact and risk rather than technology preference or generic security priorities.

  • C. Incorrect.

    This is a plausible but incorrect choice. Competitive benchmarking can inform planning, but matching industry-average spending does not ensure alignment with this organization's specific strategy, threat environment, acquisitions, or maturity constraints. Effective CCISO-level decision-making is risk- and objective-based, not spending-parity-based.

  • D. Incorrect.

    This addresses a real threat, but it is too narrow and tactical as the first action. Awareness training may reduce phishing risk, yet it does not address the broader strategic alignment challenge involving telehealth expansion, acquisitions, state privacy requirements, third-party risk, and inconsistent metrics. It is one possible initiative within a larger strategy, not the starting point.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam