PECB · ISO/IEC 27005 Risk Manager

PECB ISO/IEC 27005 Risk Manager Exam Practice Questions

60 questionsInstant PDF downloadUpdated September 2026

US$39

Try 10 questions free

Card, Apple Pay or Google Pay. Your PDF is sent by email as soon as you check out.

Pass or your money backFail the exam after using this pack and we refund it. How the guarantee works
Category:
TRY BEFORE YOU BUY

Three of the 60 questions in this pack

Question 1

Can organizations obtain certification against ISO 31000?

  1. Yes, organizations of any type or size can obtain certification against ISO 31000
  2. Yes, but only organizations that manufacture products can obtain an ISO 31000 certification
  3. No, organizations cannot obtain certification against ISO 31000, as the standard provides only guidelines
Show answer and explanation

Correct answer: C. No, organizations cannot obtain certification against ISO 31000, as the standard provides only guidelines

ISO 31000, as the standard provides only guidelines ISO 31000 is a standard that provides guidelines and principles for risk management across organizations, but it is not designed as a certification standard. Organizations cannot be certified against ISO 31000 in the way they can be certified against ISO 31001 or ISO 27001. The standard serves as a framework and guideline document rather than a specification that enables third-party certification.

Why the other options are wrong

  • A. ISO 31000 does not enable formal certification of organizations despite being applicable to any organization type.
  • B. ISO 31000 is not limited to product manufacturing organizations and still does not provide for certification.

Question 2

Which of the following statements best defines information security risk?

  1. The potential that threats will exploit vulnerabilities of an information asset and cause harm to an organization
  2. Weakness of an asset or control that can be exploited by one or a group of threats
  3. Potential cause of an unwanted incident related to information security that can cause harm to an organization
Show answer and explanation

Correct answer: A. The potential that threats will exploit vulnerabilities of an information asset and cause harm to an organization

an information asset and cause harm to an organization Information security risk is defined as the potential that threats will exploit vulnerabilities and cause harm to an organization's assets. This definition correctly combines the three essential elements: threats (potential causes), vulnerabilities (exploitable weaknesses), and impact (harm to the organization). It encompasses the complete risk scenario.

Why the other options are wrong

  • B. This describes a vulnerability, not a risk. A vulnerability alone is not a complete risk definition without threats and potential impact.
  • C. While this mentions potential harm, it does not specifically articulate the threat- vulnerability-impact relationship that defines information security risk.

Question 3

Scenario 1 -The risk assessment process was led by Henry, Bontton’s risk manager. The first step that Henry took was identifying the company’s assets.

Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers’ personal data.

Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.

Based on the scenario above, answer the following question:

Bontton established a risk management process based on ISO/IEC 27005, to systematically manage information security threats. Is this a good practice?

  1. Yes, ISO/IEC 27005 provides guidelines for information security risk management that enable organizations to systematically manage information security threats
  2. Yes, ISO/IEC 27005 provides guidelines to systematically manage all types of threats that organizations may face
  3. No, ISO/IEC 27005 cannot be used to manage information security threats in the food sector
Show answer and explanation

Correct answer: A. Yes, ISO/IEC 27005 provides guidelines for information security risk management that enable organizations to systematically manage information security threats

information security risk management that enable organizations to systematically manage information security threats ISO/IEC 27005 provides comprehensive guidelines for information security risk management. It enables organizations to systematically identify, analyze, evaluate, and treat information security risks. The scenario described in the question demonstrates a proper application of the ISO/IEC 27005 risk management process, making this the appropriate standard for managing information security threats.

Why the other options are wrong

  • B. ISO/IEC 27005 is specifically designed for information security risk management, not all types of organizational threats.
  • C. ISO/IEC 27005 is a generic framework applicable across all sectors, including the food sector, and can effectively manage information security threats regardless of industry.

See all 10 free questions Get the full pack, US$39

60 practice questions for PECB ISO/IEC 27005 Risk Manager, with full explanations.

Every question comes with the correct answer, the reasoning behind it, and a short note on why each distractor is wrong. The set is mapped to the published exam objectives across all four competency domains.

  • 60 questions across all four ISO/IEC 27005 Risk Manager domains
  • Answers and explanations for every question, including the wrong options
  • A questions-only PDF for timed practice runs
  • Instant delivery by email the moment you check out
  • Free monthly updates for as long as the exam is live
  • Pass or your money back

PECB does not publish a standalone exam price: the exam is bundled into the accredited training course, which each PECB partner prices itself, so a failed attempt means a retake fee on top. This pack is US$39, paid once, and refunded if you fail.

Try 10 questions free before you buy.

Last updated September 2026 · 60 questions

What makes the ISO/IEC 27005 Risk Manager hard

Almost half the marks come from the domain people skim. Domain 1, the fundamental principles and concepts of information security risk management, carries 44% of the points. The ISO/IEC 27005 framework and process itself is 30%, implementing a risk management programme 16%, and alternative assessment methods 10%.

Candidates who jump straight to memorising the process steps lose marks on the vocabulary underneath. The traps are terms that sound interchangeable but are not: risk identification and risk analysis, likelihood and consequence, risk criteria and acceptance criteria, residual risk and accepted risk.

ISO/IEC 27005:2022 also moved to event-based and asset-based approaches to identifying risk, so older study material describes a process that no longer matches the standard. The exam is open book, with three options per question: one right answer and two distractors.

About the exam

The ISO/IEC 27005 Risk Manager is PECB’s certification for professionals who establish and run an information security risk management process based on ISO/IEC 27005. It is the natural companion to ISO/IEC 27001, which requires a risk assessment and risk treatment process but does not say how to build one.

Exam domains

  • Domain 1: Fundamental principles and concepts of information security risk management: 44%
  • Domain 2: Implementation of an information security risk management program: 16%
  • Domain 3: Information security risk management framework and process based on ISO/IEC 27005: 30%
  • Domain 4: Other information security risk assessment methods: 10%

Multiple choice with three options per question, open book, pass mark 70%. There is no standalone exam price: the exam, the certification application and the first year of the annual maintenance fee are bundled into the three-day accredited training course, which carries 21 CPD credits and is priced by each PECB partner.

Reviews

There are no reviews yet.

Only logged in customers who have purchased this product may leave a review.

Questions before you buy

What do I get when I buy the PECB ISO/IEC 27005 Risk Manager pack?

60 practice questions as a PDF, each with the correct answer, a full explanation and a note on why the other options are wrong, plus a separate questions-only PDF for timed practice.

How quickly do I receive it?

Straight away. The full PDF and a questions-only copy are emailed to you the moment your payment goes through, and the same links are on your order page.

Is there a free sample?

Yes. Ten questions from this pack, with answers and explanations, are free on this page and as a PDF, so you can judge the quality before you pay.

Are updates included?

Yes. The pack is updated every month for as long as the exam is live, and updates are free for everyone who has bought it.

What if I fail the exam?

We refund the pack. Sit the exam 7 to 30 days after buying, then send your official score report within 7 days of the exam date, as set out in the refund policy.

Can I share it with colleagues?

Each purchase is licensed to one person. For a team, school or training organisation, email support@certstash.com for a licence that fits.