712-50 exam dumps

712-50 practice question 75 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 75

Single answerDomain 2: Organizational Executive Leadership (16%)

A newly appointed CISO at a global manufacturing company is preparing for the annual board strategy meeting. The board has historically viewed cybersecurity as a technical cost center, but recent supply-chain incidents in the industry have increased concern about operational disruption, regulatory exposure, and reputational damage. The CEO asks the CISO to present a cybersecurity program update that will secure increased funding and stronger executive sponsorship. Which approach should the CISO take FIRST to align cybersecurity with organizational executive leadership expectations and improve the likelihood of board support?

  1. A

    Present a detailed list of unresolved vulnerabilities, malware detections, and patching statistics from the last 12 months to demonstrate the scale of technical risk

  2. B

    Frame the discussion around business objectives, quantify cyber risk in terms of operational, financial, regulatory, and reputational impact, and propose prioritized initiatives tied to enterprise strategy

  3. C

    Request immediate approval for additional security tools because peer organizations in the industry have recently expanded their cybersecurity spending after supply-chain attacks

  4. D

    Focus the presentation on the security team’s staffing shortages and explain that the organization cannot be held accountable for future incidents without more personnel

Show answer and explanation

Correct answer: B

Explanation

The correct answer is Option 2 because a CCISO-level leader must communicate cybersecurity as an enterprise risk and business enabler, not merely as a technical function. Within Organizational Executive Leadership, the CISO is expected to influence senior stakeholders, align security initiatives with business strategy, and articulate how cyber risk affects revenue, operations, compliance obligations, resilience, and reputation. Boards generally respond best to concise, decision-oriented communication that explains risk exposure, business impact, treatment options, priorities, and resource implications. This aligns with broadly accepted governance and risk management practices reflected in frameworks and guidance such as NIST Cybersecurity Framework governance outcomes, NIST SP 800-39 on managing information security risk at the organizational level, ISO/IEC 27014 on governance of information security, and principles from enterprise governance models like COBIT. Technical metrics, staffing concerns, and peer comparisons can support the message, but they should not be the primary framing when seeking executive sponsorship and strategic investment.

  • A. Incorrect.

    This is not the best first approach for executive leadership engagement. While vulnerability, malware, and patching data may be useful supporting information, boards and senior executives typically need a business-oriented view of risk, impact, and strategic priorities rather than operational metrics alone. A common mistake is assuming that more technical detail automatically leads to better executive decisions.

  • B. Correct.

    This is the best answer. In Domain 2, executive leadership expects the CISO to translate cybersecurity into business terms and align the security program with enterprise objectives. By framing cyber risk in terms of business impact and linking requested initiatives to strategic goals, resilience, and governance needs, the CISO is more likely to gain funding and sponsorship. This approach demonstrates leadership, business acumen, and an understanding of how to influence executive stakeholders.

  • C. Incorrect.

    This is plausible but insufficient and weak from an executive leadership perspective. Benchmarking against peers can support a business case, but asking for tools primarily because other companies are spending more does not establish the organization's own risk exposure, strategic priorities, or expected business outcomes. Executive leaders expect justification rooted in enterprise context, not industry imitation.

  • D. Incorrect.

    This reflects a common but ineffective leadership approach. Staffing constraints may be real, but leading with resource complaints and liability distancing is unlikely to build confidence with the board. Executive audiences expect solution-oriented recommendations, prioritized risk treatment, and accountability for building an effective program within the enterprise governance structure.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam