nerdexam
EC-Council

712-50 · Question #189

As the CISO for your company you are accountable for the protection of information resources commensurate with:

The correct answer is D. Risk of exposure. Protection of information resources must be proportional to the risk of exposure (D) - this is the foundational principle of risk-based security. A CISO's job is to identify threats, assess likelihood and impact, and allocate controls accordingly. Resources that carry higher…

Governance (Policy, Legal & Compliance)

Question

As the CISO for your company you are accountable for the protection of information resources commensurate with:

Options

  • ACustomer demand
  • BCost and time to replace
  • CInsurability tables
  • DRisk of exposure

How the community answered

(57 responses)
  • A
    2% (1)
  • B
    5% (3)
  • C
    9% (5)
  • D
    84% (48)

Explanation

Protection of information resources must be proportional to the risk of exposure (D) - this is the foundational principle of risk-based security. A CISO's job is to identify threats, assess likelihood and impact, and allocate controls accordingly. Resources that carry higher risk of exposure warrant stronger, more costly protection; low-risk assets require proportionally less.

Why the distractors fail:

  • A (Customer demand) - Security decisions driven by customer preferences rather than actual risk lead to inconsistent, reactive protection that may miss critical exposures.
  • B (Cost and time to replace) - Asset replacement cost relates to availability and business continuity, not to how sensitive or exposed the information itself is; a cheap asset can still carry massive breach risk.
  • C (Insurability tables) - Insurance helps transfer risk financially but is not the standard by which you determine the level of protection to apply.

Memory tip: Think of the CISO's job as a risk-proportional shield - the bigger the target on an asset (its exposure risk), the thicker the shield. Risk always drives the protection decision, not cost, customer wishes, or insurance tables.

Topics

#CISO Accountability#Risk Management#Information Protection#Governance

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice