nerdexam
EC-Council

712-50 · Question #34

What is the MAIN reason for conflicts between Information Technology and Information Security programs?

The correct answer is D. The effective implementation of security controls can be viewed as an inhibitor to rapid. Option D captures the core tension: security controls - like access restrictions, change management gates, and approval workflows - slow down the speed and flexibility that IT teams need to deliver and innovate, making security feel like a blocker rather than an enabler. This…

Governance (Policy, Legal & Compliance)

Question

What is the MAIN reason for conflicts between Information Technology and Information Security programs?

Options

  • ATechnology governance defines technology policies and standards while security governance
  • BSecurity governance defines technology best practices and Information Technology governance
  • CTechnology Governance is focused on process risks whereas Security Governance is focused on
  • DThe effective implementation of security controls can be viewed as an inhibitor to rapid

How the community answered

(18 responses)
  • A
    6% (1)
  • B
    6% (1)
  • C
    11% (2)
  • D
    78% (14)

Explanation

Option D captures the core tension: security controls - like access restrictions, change management gates, and approval workflows - slow down the speed and flexibility that IT teams need to deliver and innovate, making security feel like a blocker rather than an enabler. This friction is the primary and most practical source of organizational conflict between the two functions.

Why the distractors fail:

  • A & B are incomplete answer fragments (the choices appear truncated), but both point at governance definition overlap - while governance misalignment can cause friction, it's a secondary structural issue, not the main day-to-day conflict driver.
  • C hints at a risk focus difference (process risk vs. something else - also truncated), but framing conflict as a matter of risk category misses the operational reality; both teams deal with overlapping risks.

Memory tip: Think "Security = the brake pedal, IT = the gas pedal." The main conflict is that one function exists to move fast (IT) and the other exists to slow things down when necessary (Security) - opposite incentives in the same vehicle.

Topics

#IT/Security governance conflict#Security controls as business inhibitor#Organizational alignment#Security vs operational speed

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice