nerdexam
EC-Council

712-50 · Question #425

Who should be involved in the development of an internal campaign to address email phishing?

The correct answer is B. Business Unite Leaders, CISO, CIO and CEO. Option B is correct because an effective internal phishing campaign requires cross-functional leadership spanning both technical and organizational authority. The CISO owns the security strategy and technical content, Business Unit Leaders ensure the message reaches employees…

Governance (Policy, Legal & Compliance)

Question

Who should be involved in the development of an internal campaign to address email phishing?

Options

  • ABusiness unit leaders, CIO, CEO
  • BBusiness Unite Leaders, CISO, CIO and CEO
  • CAll employees
  • DCFO, CEO, CIO

How the community answered

(58 responses)
  • A
    3% (2)
  • B
    72% (42)
  • C
    9% (5)
  • D
    16% (9)

Explanation

Option B is correct because an effective internal phishing campaign requires cross-functional leadership spanning both technical and organizational authority. The CISO owns the security strategy and technical content, Business Unit Leaders ensure the message reaches employees in context-relevant ways, and the CIO/CEO provide organizational credibility and enforcement weight - without executive sponsorship, security campaigns are easily ignored.

Why the distractors fail:

  • A omits the CISO, who is the most critical stakeholder for a security-specific initiative - CEO and CIO alone lack the domain expertise to shape the campaign's substance.
  • C (all employees) confuses the audience of the campaign with its developers - employees are the target, not the architects.
  • D replaces the CISO with the CFO, who has no direct role in security operations or policy; the CFO's concern is financial risk, not campaign design.

Memory tip: Think "BCIC" - Business units, CISO, and the C-suite (CIO/CEO). The CISO is the non-negotiable anchor for any security initiative - if you see an option without the CISO for a security campaign question, eliminate it immediately.

Topics

#Security Awareness#Phishing Prevention#Executive Governance#Stakeholder Management

Community Discussion

No community discussion yet for this question.

Full 712-50 Practice