712-50 exam dumps

712-50 practice question 78 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 78

Single answerWhy Leadership Matters

A newly appointed CISO inherits a security program with strong technical controls but weak executive support. Recent phishing-related incidents have increased, yet business unit leaders continue to delay security initiatives because they view them as obstacles to revenue goals. The CEO asks the CISO to improve the organization's security posture without creating unnecessary friction. Which action should the CISO take FIRST to demonstrate effective leadership and increase the likelihood of sustained organizational support?

  1. A

    Immediately deploy stricter technical controls across all business units to reduce phishing risk, even if some processes are disrupted

  2. B

    Present a business-aligned risk narrative to executive leadership that links phishing risk to financial, operational, and strategic impacts, and seek sponsorship for prioritized enterprise actions

  3. C

    Escalate the lack of cooperation from business unit leaders to the board audit committee and request formal enforcement authority

  4. D

    Launch mandatory phishing awareness training for all employees and measure completion rates before engaging senior leadership

Show answer and explanation

Correct answer: B

Explanation

This question tests a central CCISO principle: leadership matters because information security is fundamentally an enterprise risk management and business enablement function, not just a technical discipline. A senior security leader must influence stakeholders, align security priorities with organizational objectives, and obtain executive sponsorship to drive change across the enterprise. In this scenario, the CISO's first priority is to establish a business case that resonates with leadership, not simply impose controls or escalate authority. This approach is consistent with widely accepted practices in security governance and leadership, including the emphasis in NIST Cybersecurity Framework governance outcomes, NIST SP 800-39 on managing information security risk at the organizational level, and ISO/IEC 27001's requirement for leadership commitment and integration of information security into organizational processes. Strong leadership turns security from a perceived barrier into a business-supported program with shared accountability.

  • A. Incorrect.

    This is not the best first action. While stronger controls may reduce immediate exposure, imposing them without leadership alignment can increase resistance, undermine trust, and create business disruption. In a CCISO context, leadership matters because lasting security improvement depends on influence, sponsorship, and alignment with business priorities rather than purely technical mandates.

  • B. Correct.

    This is the best answer. An effective CISO leads by translating cyber risk into business terms that executives can act on. By framing phishing risk in terms of potential financial loss, operational disruption, regulatory exposure, reputational damage, and strategic impact, the CISO builds shared understanding and secures executive sponsorship. This demonstrates leadership through communication, influence, prioritization, and governance alignment, which are essential for sustainable support across business units.

  • C. Incorrect.

    This is premature as a first step. Board escalation may be appropriate if management support cannot be obtained through normal governance channels, but going directly to the board too early can damage relationships and signal that the CISO is relying on authority instead of leadership. Effective security leadership usually starts with engaging executive management, building consensus, and using established governance processes before escalating.

  • D. Incorrect.

    Training is useful, but this option focuses on a tactical control rather than the leadership challenge in the scenario. Without executive support and business alignment, training may be treated as a compliance exercise and fail to produce meaningful change. The core issue is not lack of training alone; it is lack of leadership engagement and organizational commitment.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam