712-50 exam dumps

712-50 practice question 85 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 85

Single answerLeadership with Power, Persuasion, and Influence

A newly appointed CISO has identified that the sales division is bypassing the formal third-party risk review process to onboard cloud-based marketing tools more quickly. The head of sales argues that the security process is slowing revenue growth and has strong influence with the CEO. Previous CISOs responded by escalating incidents of noncompliance to the board, which damaged relationships and resulted in only temporary improvement. The CISO needs to change this behavior and gain durable executive support without weakening risk governance. What is the BEST course of action?

  1. A

    Present the CEO and sales leadership with business-focused metrics showing the revenue, regulatory, and operational impact of unmanaged third-party risk, then propose a jointly owned fast-track review process with defined risk thresholds and accountability.

  2. B

    Require all cloud purchases by sales to be preapproved by the security team and inform procurement to block any exceptions until the sales division demonstrates full compliance for two consecutive quarters.

  3. C

    Send a formal memo to the board audit committee documenting repeated policy violations by the sales division and request that the committee direct the CEO to enforce security policy immediately.

  4. D

    Allow the sales division to continue using its preferred tools temporarily, provided the head of sales signs a risk acceptance statement on behalf of the business.

Show answer and explanation

Correct answer: A

Explanation

This question tests leadership with power, persuasion, and influence at the executive level. In CCISO practice, the most effective security leaders do not depend exclusively on positional authority, policy citation, or escalation. They translate cyber risk into business language, understand stakeholder incentives, and shape decisions through credibility, data, coalition-building, and governance design. In this scenario, the best answer balances influence and control: the CISO uses persuasive, business-relevant evidence to gain support from the CEO and sales leadership, while also redesigning the process so that secure behavior becomes easier and faster. That is more likely to create durable change than punitive enforcement alone.

This aligns with widely accepted best practices in executive security leadership and governance, including risk-based decision-making, stakeholder engagement, and security-business alignment. It is also consistent with principles reflected in frameworks and guidance such as NIST Cybersecurity Framework governance concepts, NIST SP 800-37 risk management principles, and ISO/IEC 27001 governance and risk treatment expectations, all of which emphasize integrating security into business processes and assigning accountability through formal governance rather than ad hoc exceptions.

  • A. Correct.

    Correct. This response demonstrates executive leadership through persuasion and influence rather than relying solely on positional authority. It reframes security in terms meaningful to business leaders: revenue protection, regulatory exposure, operational resilience, and decision accountability. By proposing a jointly owned fast-track process, the CISO preserves governance while addressing the business concern about speed. This approach is consistent with effective security leadership practices: aligning security objectives to business outcomes, building coalitions, using data-driven communication, and designing risk-based controls that enable the business instead of appearing purely obstructive.

  • B. Incorrect.

    Incorrect. Although tighter control may appear decisive, this approach relies primarily on coercive power and is likely to deepen resistance from a powerful business stakeholder. Blocking all exceptions until prolonged compliance is demonstrated does not address the underlying conflict between speed and governance. It may also encourage further shadow IT behavior. A CCISO-level leader should seek sustainable behavioral change by influencing stakeholders, aligning incentives, and improving process design rather than defaulting to hard enforcement as the first response.

  • C. Incorrect.

    Incorrect. Escalation to the board may be appropriate if significant risk persists after reasonable executive-level efforts fail, but the scenario specifically notes that prior board escalation damaged relationships and produced only temporary improvement. Using the board as an initial lever here reflects overreliance on formal authority rather than executive influence. A mature CISO should first attempt to build executive alignment with the CEO and business leadership using risk-informed persuasion and a practical operating model.

  • D. Incorrect.

    Incorrect. This option appears collaborative, but it weakens governance inappropriately. Risk acceptance for third-party risk should follow the organization's defined risk management and approval framework, not be informally delegated to a business executive for convenience. In many organizations, material vendor, regulatory, privacy, or security risks require formal review and approval at the proper authority level. Simply allowing continued usage in exchange for a signature does not solve the process problem and can create unmanaged enterprise exposure.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam