712-50 exam dumps

712-50 practice question 90 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 90

Single answerLeading Organization (6 questions)

A newly appointed CISO at a global manufacturing company has inherited a security program that is viewed by business unit leaders as slow, overly technical, and disconnected from revenue goals. The CEO has asked the CISO to improve executive support for security initiatives before the next budgeting cycle. The company is expanding into new digital services, and several product leaders are bypassing security review because they believe it delays time-to-market. Which action should the CISO take FIRST to most effectively lead the organization and gain sustained executive buy-in?

  1. A

    Develop and present a business-aligned security strategy that maps cyber risks, regulatory obligations, and investment requests to specific enterprise objectives, growth plans, and operational priorities

  2. B

    Implement stricter mandatory security approval gates for all new products and require business leaders to sign exception forms before release

  3. C

    Launch a companywide phishing awareness campaign to quickly demonstrate visible security improvement and reduce user-related risk

  4. D

    Request additional funding for new security tools by benchmarking the organization against industry peers and highlighting recent public breaches in the sector

Show answer and explanation

Correct answer: A

Explanation

In CCISO-level leadership, the CISO is expected to lead through influence, business alignment, and governance rather than through technical authority alone. When security is perceived as obstructive or detached from organizational priorities, the first leadership task is to build a strategy that links security outcomes to enterprise goals, business processes, risk management, and growth initiatives. This is consistent with widely accepted practices in executive security leadership and governance, including principles reflected in NIST Cybersecurity Framework governance outcomes, COBIT's alignment of IT and enterprise goals, and ISO/IEC 27001's emphasis on leadership, organizational context, and risk-based planning. Once strategic alignment is established, the CISO can define appropriate governance processes, justify investments, and improve collaboration with product and business leaders in a way that supports both risk reduction and business performance.

  • A. Correct.

    This is the best first action because leading at the executive level requires translating security from a technical function into a business enabler. By aligning the security strategy to enterprise objectives such as digital expansion, operational resilience, compliance obligations, and revenue protection, the CISO addresses the core leadership issue: lack of executive relevance and support. This approach helps the CEO and business unit leaders understand why security matters in terms of business outcomes, not just controls. It also creates a foundation for governance, prioritization, and future budget requests.

  • B. Incorrect.

    This option is plausible because product teams are bypassing security, and stronger governance may seem necessary. However, imposing tighter gates first is likely to reinforce the perception that security is a blocker rather than a partner. Without first establishing executive alignment, shared risk appetite, and a business-supported operating model, stricter controls may generate more resistance and shadow processes. Governance mechanisms are important, but they should follow strategic alignment and stakeholder engagement.

  • C. Incorrect.

    Security awareness can be valuable, and phishing reduction is a legitimate objective. However, this does not address the stated executive leadership problem: the security program is seen as disconnected from business goals, and product leaders are bypassing security because of perceived friction. A phishing campaign may produce a visible activity metric, but it is not the most effective first step for gaining sustained executive buy-in or repositioning security as a strategic function.

  • D. Incorrect.

    Benchmarking and external breach examples can support a funding case, but requesting more money before demonstrating business alignment is unlikely to succeed. Executives generally fund capabilities that clearly support organizational objectives, risk tolerance, and strategic initiatives. Peer comparisons alone can lead to spending based on fear or imitation rather than enterprise-specific priorities. The misconception here is that budget approval comes primarily from tool gaps rather than from a credible, business-driven security strategy.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam