712-50 exam dumps

712-50 practice question 409 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 409

Single answerFinance (5 questions)

A newly appointed CISO is preparing the cybersecurity budget for the next fiscal year after the board questioned why security spending increased while measurable business value remained unclear. The organization is considering three competing initiatives: expanding endpoint detection coverage, implementing a third-party risk management platform, and increasing secure coding training for developers. The CFO has asked for a funding recommendation that aligns security spending with business priorities and financial discipline. Which approach should the CISO use FIRST to justify the budget request?

  1. A

    Recommend the initiative with the lowest upfront cost to demonstrate fiscal restraint and improve the chance of approval

  2. B

    Prioritize the initiative that addresses the highest quantified business risk reduction relative to cost, using a documented risk-based analysis tied to strategic objectives

  3. C

    Request equal funding for all three initiatives so each major security domain receives balanced investment

  4. D

    Select the initiative most strongly favored by the security operations team because they will be responsible for execution

Show answer and explanation

Correct answer: B

Explanation

At the CCISO level, finance decisions should be made using a business-aligned, risk-based framework rather than intuition, equal allocation, or purely technical priorities. The CISO should first quantify and compare the expected reduction in business risk for each initiative relative to its cost, then present the recommendation in terms the CFO and board understand: financial exposure, regulatory implications, resilience, and support for strategic objectives. This approach is consistent with broadly accepted practices from governance and risk frameworks such as NIST Cybersecurity Framework, NIST SP 800-30 for risk assessment, ISO/IEC 27005 for information security risk management, and FAIR-style financial risk analysis where used. These approaches support decisions based on likely loss exposure, treatment options, and business impact, which is the most defensible way to justify security investment.

  • A. Incorrect.

    This is incorrect because choosing solely on lowest upfront cost reflects a cost-minimization mindset rather than financial governance. In CCISO-level finance decisions, the objective is not simply to spend less, but to allocate limited resources where they produce the greatest reduction in enterprise risk and best support business priorities. A low-cost initiative may deliver limited value or leave material risk untreated.

  • B. Correct.

    This is correct because a senior security executive should justify budget requests through a risk-based business case that compares expected risk reduction, impact on business objectives, and total cost. This aligns with common governance and finance practices such as evaluating return on security investment, cost-benefit considerations, risk treatment priorities, and alignment with enterprise strategy. Boards and CFOs typically expect funding recommendations to be traceable to measurable business risk and strategic outcomes rather than technical preference.

  • C. Incorrect.

    This is incorrect because equal distribution of funding across initiatives assumes all risks are equally important, which is rarely true. Security budgeting should be driven by risk prioritization, control maturity gaps, regulatory exposure, and business impact. Spreading funds evenly may underfund the most critical initiative and reduce overall effectiveness of the security program.

  • D. Incorrect.

    This is incorrect because operational preference is useful input but should not be the primary basis for enterprise funding decisions. Security leaders must balance operational feasibility with business risk, financial constraints, and strategic priorities. Allowing the implementing team to drive the decision without a broader business case can result in technically attractive but financially weak recommendations.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam