712-50 exam dumps

712-50 practice question 93 of 455

Certified Chief Information Security Officer (CCISO). Associate level, EC-Council. Free question with the correct answer and a full explanation.

712-50 Question 93

Single answerBoard Briefing

A newly appointed CISO is preparing for her first quarterly board briefing after a ransomware incident that caused limited operational disruption but no confirmed exfiltration of regulated data. In prior meetings, the board complained that security updates were too technical and did not help them make governance decisions. The CEO asks the CISO to present in a way that will support the board's oversight responsibilities and future investment decisions. Which approach should the CISO take?

  1. A

    Present a detailed review of malware indicators, forensic tool output, and firewall rule changes so the board can understand exactly how the attack occurred

  2. B

    Structure the briefing around business impact, current enterprise risk exposure, management's response effectiveness, legal and regulatory implications, and specific decisions or resources needed from the board

  3. C

    Limit the presentation to a high-level statement that the incident was contained and avoid discussing control weaknesses until the technical investigation is fully complete

  4. D

    Focus primarily on benchmarking the security team against peer organizations and defer discussion of the incident because the board should avoid involvement in operational matters

Show answer and explanation

Correct answer: B

Explanation

For a board briefing, the CISO should communicate in business and governance terms, not technical operations language. Widely accepted governance and security frameworks support this approach. NIST Cybersecurity Framework emphasizes communicating cybersecurity risk in terms that support organizational objectives and risk management. NIST SP 800-61 on incident response highlights the importance of reporting incidents to the appropriate stakeholders, including leadership, with actionable information. ISO/IEC 27014 also reinforces that governance bodies need information relevant to evaluation, direction, and monitoring of information security. In practice, boards should receive a concise briefing covering material facts, business impact, current risk posture, response status, potential legal or regulatory consequences, lessons learned, and explicit asks such as investment approval, policy direction, or risk acceptance decisions. The best answer is the one that enables the board to fulfill its oversight role and make informed governance decisions.

  • A. Incorrect.

    This is incorrect because it overemphasizes technical detail instead of governance-relevant insight. Boards are responsible for oversight, risk appetite, resilience, and strategic decision-making, not operational incident handling. While technical depth may be appropriate for management or technical committees, a full board briefing should translate the incident into business risk, impact, and required governance actions.

  • B. Correct.

    This is correct because it aligns the briefing to what the board needs: business impact, enterprise risk implications, adequacy of management response, regulatory exposure, and decisions requiring board awareness or approval. Effective board communication should be concise, strategic, and framed in business terms, including what happened, what it means to the organization, how management is responding, whether residual risk remains within tolerance, and what support or direction is needed.

  • C. Incorrect.

    This is incorrect because it withholds information the board needs to exercise oversight. Even if some technical facts are still being validated, the board should be informed of known impact, preliminary risk assessment, response status, and any material uncertainties. Avoiding discussion of control weaknesses can prevent timely decisions about communications, remediation funding, insurance, legal strategy, or risk acceptance.

  • D. Incorrect.

    This is incorrect because although peer benchmarking can provide useful context, it should not replace discussion of a material incident. The misconception is that board involvement in cyber matters is inappropriate because incidents are operational. In reality, cyber incidents often have strategic, legal, financial, and reputational consequences, making them directly relevant to board oversight.

Timed practice exam

Take a 712-50 practice test under exam conditions

150 questions in 150 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam