ExamRange

CCISO (712-50) Executive Decision Simulation

Master executive risk prioritization and strategic alignment. This simulation trains you to analyze risk metrics and make governance decisions that justify budget allocations to the board.

Executive Briefing

You are the Chief Information Security Officer (CISO) for a rapidly scaling financial technology (FinTech) enterprise. The Board of Directors has requested a prioritized risk register to finalize the Q3 security budget.

Due to recent market volatility, the CFO has mandated a 15% reduction in discretionary spending. You cannot fund mitigation efforts for every identified vulnerability in the enterprise infrastructure. You must strategically prioritize which risks receive immediate funding based on robust risk management principles.

Business Context

  • Risk Appetite: The organization has a very low tolerance for risks impacting primary transaction processing systems.
  • Financial Constraints: Mitigation capital is strictly limited. Investments must yield the highest possible risk reduction ROI.
  • Compliance: The enterprise is subject to PCI-DSS and SOC 2 Type II regulatory frameworks, requiring documented justification for risk acceptance or mitigation.

Decision Scenario

Your risk management team presents two critical vulnerabilities existing on the core payment processing gateway. Upon performing a quantitative analysis, it is determined that both risks—if realized—would result in an identical Single Loss Expectancy (SLE) of $2.5 Million.

Because the potential financial impact is identical, you instruct your Risk Analysts to focus on the frequency of occurrence. The data proves that Risk A is attacked with much greater frequency than Risk B across the industry.

You must now report this finding to the Risk Committee to justify directing all Q3 funding to mitigate Risk A first.

Question

You have a system with 2 identified risks. You determine the probability of one risk occurring is higher than the

A. Relative likelihood of event
B. Controlled mitigation effort
C. Risk impact comparison
D. Comparative threat analysis