712-50 exam dumps

712-50 practice question 92 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 92

Single answerBoard Briefing

A newly appointed CISO is preparing for her first quarterly board briefing after the company experienced a ransomware incident that disrupted operations for two days. Several board members are not technical, but they are highly focused on business continuity, regulatory exposure, and whether security investments are reducing risk. The CISO has 15 minutes on the agenda. Which approach is the MOST effective for this board briefing?

  1. A

    Present a detailed technical timeline of the attack, including malware indicators, forensic artifacts, and the full list of affected servers, so the board can understand exactly how the compromise occurred.

  2. B

    Structure the briefing around business impact, current enterprise risk exposure, legal and regulatory implications, remediation status, and specific decision points requiring board support, using concise metrics tied to business objectives.

  3. C

    Focus primarily on the security team's operational response metrics, such as number of alerts reviewed, patches deployed, and hours worked, to demonstrate that the incident was handled diligently.

  4. D

    Limit the discussion to high-level assurances that the issue has been contained and avoid discussing residual risk until the investigation is fully complete, so as not to create unnecessary concern.

Show answer and explanation

Correct answer: B

Explanation

For CCISO-level board briefing responsibilities, the CISO should communicate in a governance-focused, business-oriented manner rather than a technical or operational one. Boards are responsible for oversight of strategy, risk, resilience, and compliance, so the briefing should translate a cybersecurity incident into business impact: operational disruption, financial implications, regulatory obligations, customer trust, recovery status, residual risk, and required board decisions. This approach is consistent with widely accepted security governance practices reflected in frameworks and guidance such as NIST Cybersecurity Framework 2.0 governance themes, NIST SP 800-61 for incident handling communication considerations, and board-focused cyber risk guidance from organizations such as NACD and the World Economic Forum. A strong board briefing is concise, decision-oriented, and framed around enterprise risk and resilience rather than technical depth or team activity.

  • A. Incorrect.

    This is incorrect because a board briefing should not be centered on deep technical artifacts unless they are directly relevant to governance decisions. While a technical timeline is important for internal operational review, boards typically need a concise view of business impact, risk, accountability, recovery, and strategic implications. A common misconception is that providing more technical detail demonstrates competence; in reality, it can obscure the decision-relevant message for non-technical directors.

  • B. Correct.

    This is correct because it aligns the security update to the board's oversight responsibilities: enterprise risk, resilience, legal exposure, financial impact, and strategic decisions. Effective board communication translates cyber events into business terms, highlights residual risk, explains remediation progress, and identifies where governance input or funding approval is needed. Concise metrics tied to business objectives help directors assess whether management is reducing risk and improving resilience rather than merely reporting activity.

  • C. Incorrect.

    This is incorrect because operational effort metrics do not necessarily show reduction in enterprise risk or improvement in resilience. Boards are less concerned with how busy the security team was than with whether critical services were restored, whether obligations to regulators and customers were met, and whether the organization's risk posture is improving. This option reflects the common mistake of reporting activity instead of outcomes.

  • D. Incorrect.

    This is incorrect because boards need transparency on residual risk, even when investigations are ongoing. Providing only reassurance without discussing remaining exposure, dependencies, and next steps undermines effective governance and may impair the board's ability to fulfill fiduciary and oversight duties. While uncertainty should be acknowledged, material risks and management's plan to address them should still be presented.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam