712-50 exam dumps

712-50 practice question 57 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 57

Single answerFollow organizational ethics

You are the newly appointed CISO of a global manufacturing company. During a quarterly board preparation meeting, the CFO tells you that reporting a recently discovered third-party data exposure to a major customer before contract renewal would likely jeopardize a significant deal. The CFO asks you to omit the incident from the board briefing until the contract is signed, arguing that the issue is still being investigated and may turn out to be immaterial. The company’s code of ethics requires transparency, compliance with legal and contractual obligations, and escalation of material risks. What is the MOST appropriate action for you to take?

  1. A

    Delay disclosure until the investigation is complete so you do not create unnecessary concern for the board or the customer

  2. B

    Remove the incident from the board briefing, but document the CFO’s request in case the decision is later questioned

  3. C

    Include the incident in the board briefing with the known facts, clearly identify uncertainties, and initiate review with legal, compliance, and executive leadership regarding notification obligations

  4. D

    Inform the customer immediately on your own authority before discussing the matter internally, because ethical conduct requires full external transparency as soon as possible

Show answer and explanation

Correct answer: C

Explanation

This question tests whether the candidate can apply organizational ethics in a senior leadership scenario involving pressure from another executive to suppress material security information. In the CCISO context, following organizational ethics means acting in accordance with the enterprise’s code of conduct, governance model, legal obligations, and duty to provide decision-makers with complete and accurate risk information. The CISO is expected to support integrity in reporting, avoid misrepresentation by omission, and escalate issues appropriately.

Best practice is to brief the board on material cyber risks using the facts currently known, explicitly identify uncertainties, and coordinate with legal, compliance, privacy, and executive stakeholders on notification and disclosure obligations. This approach is consistent with widely recognized governance and ethics principles reflected in frameworks and guidance such as ISACA guidance on governance and assurance, the NIST Cybersecurity Framework governance emphasis, and common corporate code-of-ethics expectations around honesty, transparency, and escalation. Concealing or delaying a material incident for business convenience creates ethical, legal, and governance risk, while unilateral disclosure without internal coordination can also be improper. The most appropriate response is transparent internal reporting with structured cross-functional review.

  • A. Incorrect.

    This is incorrect because withholding a potentially material incident from the board conflicts with organizational ethics requirements for transparency and proper escalation of risk. While investigations should establish facts, uncertainty does not justify concealing a potentially significant issue from governance bodies that are responsible for oversight. A common misconception is that incomplete information should not be reported; in practice, leaders should report what is known, what is unknown, and what is being done.

  • B. Incorrect.

    This is incorrect because documenting the CFO’s request does not resolve the ethical failure of intentionally excluding relevant risk information from the board. Although documentation is useful, the CISO’s duty is not merely to preserve evidence of the request but to ensure proper governance, escalation, and adherence to the organization’s code of ethics and risk reporting requirements. This option reflects a common but flawed belief that personal protection through documentation is sufficient.

  • C. Correct.

    This is correct because it aligns with organizational ethics, executive accountability, and sound governance. The CISO should provide accurate, timely reporting to the board, distinguish confirmed facts from open questions, and engage legal and compliance functions to evaluate regulatory, contractual, and customer notification requirements. This approach balances transparency with due process and avoids both concealment and premature unsupported conclusions.

  • D. Incorrect.

    This is incorrect because, although transparency is important, unilateral external notification without coordinating with legal, compliance, incident response, and executive leadership may violate established incident management, contractual, and regulatory processes. Ethical conduct requires responsible, authorized, and fact-based action, not bypassing governance. A common misconception is that ethics requires immediate disclosure by any means, when in reality it requires transparent escalation and proper decision-making.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam