712-50 exam dumps

712-50 practice question 440 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 440

Select 2Understand the cost implications of cloud computing and design controls to monitor spending and maintain budgets

A global company has accelerated migration of development and analytics workloads to multiple public cloud providers. Six months later, the CFO reports monthly cloud spending is 28% above forecast, with the largest increases coming from orphaned storage, oversized compute instances, and uncontrolled use of premium services by business units. The CISO has been asked to recommend governance controls that will reduce the likelihood of budget overruns without slowing approved projects. Which TWO actions should the CISO prioritize?

  1. A

    Implement mandatory resource tagging tied to cost centers and owners, enforce cloud budgets with spend alerts, and review usage reports regularly with business and engineering leaders

  2. B

    Require all cloud services to be purchased only through annual enterprise agreements so that variable consumption charges are eliminated

  3. C

    Establish policy guardrails using cloud-native controls to restrict unapproved regions, instance types, and premium services, with exception handling for justified business needs

  4. D

    Shift cloud cost management entirely to the procurement department because technical teams are not responsible for operational spending after deployment

  5. E

    Increase reserved capacity commitments across all major services immediately to reduce unit pricing, regardless of current utilization patterns

Show answer and explanation

Correct answers: A, C

Explanation

The best answer is to prioritize governance controls that improve visibility and prevent uncontrolled consumption while preserving business agility: mandatory tagging with budgets/alerts and policy guardrails with exceptions. From a CCISO perspective, this reflects executive-level cloud financial governance rather than a purely technical optimization exercise. Effective control design typically includes: resource ownership and cost allocation; budget thresholds and anomaly detection; preventive controls over provisioning choices; periodic review with finance and business stakeholders; and exception management. These principles align with widely accepted cloud financial management and governance practices, including FinOps guidance on allocation, accountability, and continuous optimization, as well as cloud-provider best practices such as AWS cost allocation tags, AWS Budgets, Azure Policy and Cost Management, and Google Cloud billing budgets and labels. The scenario specifically points to the need for both detective controls (visibility, alerts, reporting) and preventive controls (service and configuration guardrails) to maintain budgets without unnecessarily slowing approved projects.

  • A. Correct.

    Correct. Mandatory tagging is a foundational FinOps and governance control because it enables chargeback/showback, accountability, and budget monitoring by owner, environment, and business unit. Pairing tags with budgets and alerts helps identify anomalies before month-end, while regular reviews with finance, engineering, and business leaders supports ongoing cost governance rather than one-time remediation. This approach addresses the scenario directly by improving visibility into orphaned resources, business-unit consumption, and accountability.

  • B. Incorrect.

    Incorrect. Enterprise agreements may provide discounts or negotiated terms, but they do not eliminate variable consumption charges in public cloud. Cloud cost overruns often result from usage behavior, architecture choices, and lack of controls, not simply contract structure. A candidate might choose this because discounts sound financially attractive, but contract centralization alone does not solve oversized instances, orphaned storage, or unapproved premium service usage.

  • C. Correct.

    Correct. Policy guardrails are an effective executive control because they reduce cost and risk at the point of provisioning. Restricting unapproved regions, instance families, or premium services helps prevent teams from consuming unnecessarily expensive options while preserving agility through an exception process. This is consistent with cloud governance best practice: define approved service catalogs, apply preventive controls, and allow documented exceptions for legitimate business needs.

  • D. Incorrect.

    Incorrect. Procurement has an important role in vendor management and commercial negotiation, but cloud spending must be jointly owned by security, finance, engineering, and service owners. Technical teams directly influence cost through architecture, scaling, storage retention, and service selection. Assigning cost management entirely to procurement ignores the operational drivers of cloud expense and weakens accountability.

  • E. Incorrect.

    Incorrect. Reserved capacity or savings commitments can reduce rates when workloads are stable and well understood, but applying them broadly without utilization analysis can lock the organization into unnecessary spend. In this scenario, the company first needs visibility, ownership, and provisioning guardrails. A candidate might select this because committed-use discounts are a known optimization tactic, but using them indiscriminately can worsen budget performance.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam