712-50 exam dumps

712-50 practice question 84 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 84

Single answerLeadership with Power, Persuasion, and Influence

A newly appointed CISO has identified that the product engineering division is routinely bypassing secure development requirements to meet aggressive release deadlines. Previous attempts by the security team to enforce compliance through policy reminders and audit findings have created resentment, and the head of engineering has significant influence with the CEO because revenue depends on rapid feature delivery. The CISO must gain executive support and change engineering behavior without damaging critical business relationships. What is the BEST course of action?

  1. A

    Escalate the issue immediately to the board's audit committee and request a directive requiring engineering to follow all security controls before any release

  2. B

    Meet with the head of engineering and key executives to reframe the issue in business terms, present risk scenarios tied to revenue and customer trust, and jointly agree on risk-based secure development milestones and accountability

  3. C

    Issue a formal exception process that allows engineering to bypass secure development controls as long as the business accepts the risk in writing

  4. D

    Direct the security team to increase technical gatekeeping by blocking all production releases that do not meet every security requirement, regardless of business impact

Show answer and explanation

Correct answer: B

Explanation

The scenario tests the CISO's ability to use power, persuasion, and influence at the executive level. In CCISO practice, senior security leaders are expected to achieve outcomes through business alignment, stakeholder engagement, and risk communication rather than relying only on policy, audit pressure, or technical enforcement. The strongest response is to engage the engineering leader and executives, translate the issue into enterprise risk language, and negotiate a risk-based path that preserves delivery goals while improving security accountability. This approach reflects established best practices in security leadership and governance, including aligning security with business objectives, using risk management to drive decisions, and building cross-functional support. It is also consistent with guidance from common governance and risk frameworks such as NIST CSF and ISO/IEC 27001, which emphasize risk-based decision-making, leadership involvement, and integration of security into organizational processes rather than isolated enforcement.

  • A. Incorrect.

    This is not the best first action. While board escalation may sometimes be necessary, going directly to the audit committee before attempting executive alignment can damage relationships, reduce the CISO's credibility as a collaborative business leader, and appear overly reliant on formal authority. In a leadership, persuasion, and influence context, the CISO should first seek to build consensus and align stakeholders around shared business outcomes unless the risk is immediate and intolerable.

  • B. Correct.

    This is the best answer because it reflects executive-level influence rather than dependence on positional power alone. By translating security concerns into business impact such as customer trust, contractual exposure, operational disruption, and revenue risk, the CISO increases the likelihood of buy-in from engineering and senior leadership. Jointly defining risk-based milestones demonstrates negotiation, coalition building, and pragmatic leadership, which are core expectations of a chief information security officer.

  • C. Incorrect.

    This is plausible because exception processes are legitimate governance tools, but it is not the best answer here. If used too early, it can normalize bypassing security rather than changing behavior. A written risk acceptance may document accountability, but it does not itself create influence, executive alignment, or sustainable improvement. It can also become a mechanism for routine noncompliance if not governed carefully.

  • D. Incorrect.

    This option relies primarily on coercive power and is likely to intensify conflict. Although release gates can be appropriate in mature governance models, imposing absolute technical blocking without executive agreement and business context may be seen as obstructing the enterprise mission. Effective CISOs balance security with organizational objectives and use influence to create durable support rather than forcing compliance in a way that undermines trust.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam