712-50 exam dumps

712-50 practice question 81 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 81

Single answerRole of Leader in Organizational Success

A newly appointed CISO joins a global manufacturing company after a ransomware incident exposed weak coordination between IT, operations, legal, and business leadership. The CEO wants security to become a business enabler rather than a compliance function. In the first 90 days, which action by the CISO would BEST demonstrate effective leadership that contributes to organizational success?

  1. A

    Develop and communicate a risk-based security strategy aligned to business objectives, assign executive ownership for key risks, and establish cross-functional governance with measurable outcomes

  2. B

    Immediately increase spending on endpoint and network security tools to reassure the board that the organization is taking visible action

  3. C

    Centralize all security decisions within the CISO's office so responses are faster and accountability is clearer

  4. D

    Focus first on rewriting all security policies and standards to ensure every control gap is formally documented before engaging business leaders

Show answer and explanation

Correct answer: A

Explanation

The best answer is Option 1 because the scenario is testing the CISO's role as an enterprise leader, not just a technical manager. In CCISO practice, leadership contributes to organizational success by aligning security with business goals, influencing peers, establishing governance, and ensuring accountability for risk across the organization. Following a major incident, the most effective first step is to create a risk-based strategy that supports resilience and business priorities, then use cross-functional governance to drive execution.

This approach is consistent with widely accepted security and governance practices. NIST Cybersecurity Framework 2.0 emphasizes governance, business context, and risk-informed decision-making. ISO/IEC 27014 highlights governance of information security as a leadership responsibility tied to organizational objectives. COBIT also reinforces alignment of enterprise goals, governance structures, and performance measurement. Together, these practices support the principle that a CISO's leadership value comes from enabling the business to make better risk decisions, not merely deploying controls or drafting policies.

  • A. Correct.

    This is correct because it reflects the leadership role of a CISO at the executive level: aligning cybersecurity with business strategy, building shared accountability, and creating governance mechanisms that enable informed decision-making across functions. After an incident, the strongest leadership response is not only technical remediation, but also establishing direction, influence, and coordination. A risk-based strategy tied to business objectives helps prioritize investments, resilience, compliance, and operational continuity. Assigning executive ownership for key risks reinforces that cybersecurity risk is an enterprise issue, not solely an IT problem. Measurable outcomes also support board reporting and demonstrate value creation.

  • B. Incorrect.

    This is incorrect because increasing tool spend may be necessary, but it is not the best leadership action in this scenario. It addresses symptoms more than root causes and can create a false sense of progress. The scenario specifically highlights poor coordination among leadership groups and a CEO mandate to make security a business enabler. Buying more technology without governance, business alignment, or accountability often leads to duplicated controls, misallocated budget, and limited improvement in organizational resilience.

  • C. Incorrect.

    This is incorrect because overly centralizing security decisions undermines the collaborative leadership model needed for enterprise success. Although faster decision-making can seem attractive after an incident, concentrating authority in the CISO's office can reduce business ownership, create bottlenecks, and weaken integration with legal, operations, and business units. Effective executive leadership in cybersecurity typically involves federated accountability with centralized strategy and oversight, not isolated decision-making.

  • D. Incorrect.

    This is incorrect because policy improvement is important, but leading with policy rewrites is too internally focused for the stated business need. Formal documentation alone does not create organizational alignment, improve crisis coordination, or make security a business enabler. A leader should first set strategic direction, engage stakeholders, and define governance and risk priorities. Policies should then support that strategy rather than substitute for leadership.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam