nerdexam
EC-Council

212-82 · Question #165

GlobalTech, a multinational tech conglomerate, has been operating across 50 countries for the past two decades. Recently, it faced a significant data breach that affected Its reputation and bottom…

The correct answer is C. Establish a governance framework that integrates security considerations into all business. Explanation Establishing a governance framework that integrates security into all business decisions (Option C) is correct because GlobalTech's challenge is fundamentally a governance problem, not just a technical one - the board explicitly wants security aligned with long-term…

Submitted by chiamaka_o· Mar 6, 2026Cloud Security Risks & Threat Mitigation

Question

GlobalTech, a multinational tech conglomerate, has been operating across 50 countries for the past two decades. Recently, it faced a significant data breach that affected Its reputation and bottom line. As a result, the board of directors decided to overhaul its existing corporate strategy, with a pronounced focus on enhancing its Information Security Governance. The company believes that a robust governance structure would not only prevent future breaches but would also align with its long-term business objectives of expansion and dominance in the tech market. It has called upon several third-party consultants to pitch an optimal strategy for the conglomerate's unique position. Which strategy best aligns with GlobalTech's requirement?

Options

  • AImplement a robust intrusion detection system.
  • BPrioritize security audits for quarterly review.
  • CEstablish a governance framework that integrates security considerations into all business
  • DFormulate an isolated team for cybersecurity tasks.

How the community answered

(25 responses)
  • A
    4% (1)
  • B
    8% (2)
  • C
    68% (17)
  • D
    20% (5)

Explanation

Explanation

Establishing a governance framework that integrates security into all business decisions (Option C) is correct because GlobalTech's challenge is fundamentally a governance problem, not just a technical one - the board explicitly wants security aligned with long-term expansion objectives across 50 countries, which requires an enterprise-wide, strategic approach rather than isolated fixes.

Why the distractors fail:

  • Option A (intrusion detection system) is purely a technical/tactical control that addresses symptoms, not the root governance gap - it cannot align security with business strategy
  • Option B (quarterly audits) is a useful component of governance but is too narrow and periodic to constitute a comprehensive governance overhaul
  • Option D (isolated cybersecurity team) directly contradicts good governance principles - siloing security creates blind spots and prevents the cross-functional integration the board is seeking

Memory Tip: Think of governance as the "umbrella" - it covers everything beneath it. Whenever an exam question involves a board-level decision, strategic alignment, or organization-wide change, the answer almost always points to a governance framework rather than a specific tool, schedule, or isolated team. If the question mentions strategy + business objectives, think governance integration.

Topics

#Information Security Governance#Corporate Strategy#Risk Management#Business Alignment

Community Discussion

No community discussion yet for this question.

Full 212-82 Practice