10 free PECB ISO/IEC 27005 Risk Manager practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 60 questions. Work through them, then open each answer to check your reasoning.
Get all 60 questions (US$39) · Download these 10 as a PDF
Question 1
Can organizations obtain certification against ISO 31000?
Show answer and explanation
Correct answer: C. No, organizations cannot obtain certification against ISO 31000, as the standard provides only guidelines
ISO 31000, as the standard provides only guidelines ISO 31000 is a standard that provides guidelines and principles for risk management across organizations, but it is not designed as a certification standard. Organizations cannot be certified against ISO 31000 in the way they can be certified against ISO 31001 or ISO 27001. The standard serves as a framework and guideline document rather than a specification that enables third-party certification.
Why the other options are wrong
- A. ISO 31000 does not enable formal certification of organizations despite being applicable to any organization type.
- B. ISO 31000 is not limited to product manufacturing organizations and still does not provide for certification.
Question 2
Which of the following statements best defines information security risk?
Show answer and explanation
Correct answer: A. The potential that threats will exploit vulnerabilities of an information asset and cause harm to an organization
Information security risk is defined as the potential that threats will exploit vulnerabilities and cause harm to an organization's assets. This definition correctly combines the three essential elements: threats (potential causes), vulnerabilities (exploitable weaknesses), and impact (harm to the organization). It encompasses the complete risk scenario.
Why the other options are wrong
- B. This describes a vulnerability, not a risk. A vulnerability alone is not a complete risk definition without threats and potential impact.
- C. While this mentions potential harm, it does not specifically articulate the threa-ulnerability-impact relationship that defines information security risk.
Question 3
Scenario 1 -The risk assessment process was led by Henry, Bontton’s risk manager. The first step that Henry took was identifying the company’s assets.
Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers’ personal data.
Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.
Based on the scenario above, answer the following question:
Bontton established a risk management process based on ISO/IEC 27005, to systematically manage information security threats. Is this a good practice?
Show answer and explanation
Correct answer: A. Yes, ISO/IEC 27005 provides guidelines for information security risk management that enable organizations to systematically manage information security threats
ISO/IEC 27005 provides comprehensive guidelines for information security risk management. It enables organizations to systematically identify, analyze, evaluate, and treat information security risks. The scenario described in the question demonstrates a proper application of the ISO/IEC 27005 risk management process, making this the appropriate standard for managing information security threats.
Why the other options are wrong
- B. ISO/IEC 27005 is specifically designed for information security risk management, not all types of organizational threats.
- C. ISO/IEC 27005 is a generic framework applicable across all sectors, including the food sector, and can effectively manage information security threats regardless of industry.
Question 4
Scenario 1 -The risk assessment process was led by Henry, Bontton’s risk manager. The first step that Henry took was identifying the company’s assets.
Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers’ personal data.
Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.
Based on scenario 1, Bontton used ISO/IEC 27005 to ensure effective implementation of all ISO/IEC 27001 requirements. Is this appropriate?
Show answer and explanation
Correct answer: C. No, ISO/IEC 27005 does not contain direct guidance on the implementation of all requirements given in ISO/IEC 27001
ISO/IEC 27005 provides guidance on conducting risk assessments within the context of an information security management system based on ISO/IEC 27001. However, it does not provide direct implementation guidance for all ISO/IEC 27001 requirements. ISO/IEC 27005 is specifically focused on the risk management process, not the complete set of controls and requirements specified in ISO/IEC 27001.
Why the other options are wrong
- A. ISO/IEC 27005 provides guidance on risk management methodology but not direct implementation guidance for all ISO/IEC 27001 requirements.
- B. While ISO/IEC 27005 offers methodologies for risk management, it does not comprehensively cover the implementation of all ISO/IEC 27001 requirements.
Question 5
Scenario 1 -The risk assessment process was led by Henry, Bontton’s risk manager. The first step that Henry took was identifying the company’s assets.
Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers’ personal data.
Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.
According to scenario 1, what type of controls did Henry suggest?
Show answer and explanation
Correct answer: C. Administrative
Administrative controls, also known as managerial or procedural controls, involve policies, procedures, guidelines, training, and awareness programs designed to influence human behavior and ensure proper handling of information assets. In this scenario, Henry recommended providing training to personnel on the use of the application and conducting awareness sessions on protecting customers' personal data. These are classic examples of administrative controls because they focus on educating and guiding employees rather than implementing physical barriers or technological solutions, making them the appropriate classification for the measures suggested.
Why the other options are wrong
- A. Technical controls involve technology-based solutions like firewalls, encryption, or access control systems, not training and awareness sessions.
- B. Managerial controls typically refer to broader risk management and oversight decisions made by leadership, whereas training and awareness sessions are operational, people-focused measures classified as administrative controls.
Question 6
Scenario 1 -The risk assessment process was led by Henry, Bontton’s risk manager. The first step that Henry took was identifying the company’s assets.
Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers’ personal data.
Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.
Henry concluded that one of the main concerns regarding the use of the application for online ordering was cyberattacks.
What did Henry identify in this case? Refer to scenario 1.
Show answer and explanation
Correct answer: A. A threat
Cyberattacks represent a threat, a potential cause of harm that could target the organization's assets. A threat is defined as any potential cause of an unwanted incident. In the context of the scenario, Henry identified cyberattacks as a realistic threat to the application, based on the widespread nature of such attacks at the time.
Why the other options are wrong
- B. Vulnerabilities are weaknesses in assets or controls that threats could exploit; the cyberattack itself is the threat, not a vulnerability.
- C. Consequences are the results or impacts of an incident; cyberattacks are the potential cause, making them threats rather than consequences.
Question 7
Scenario 1 -The risk assessment process was led by Henry, Bontton’s risk manager. The first step that Henry took was identifying the company’s assets.
Afterward, Henry created various potential incident scenarios. One of the main concerns regarding the use of the application was the possibility of being targeted by cyber attackers, as a great number of organizations were experiencing cyberattacks during that time. After analyzing the identified risks, Henry evaluated them and concluded that new controls must be implemented if the company wants to use the application. Among others, he stated that training should be provided to personnel regarding the use of the application and that awareness sessions should be conducted regarding the importance of protecting customers’ personal data.
Lastly, Henry communicated the risk assessment results to the top management. They decided that the application will be used only after treating the identified risks.
According to scenario 1, Bontton wanted to use an application that ensures only authorized users have access to customers’ personal data.
Which information security principle does Bontton want to ensure in this case?
Show answer and explanation
Correct answer: C. Confidentiality
Confidentiality is the information security principle that ensures only authorized users can access information. The scenario specifically mentions restricting access to customers' personal data to authorized users only, which is the core definition of confidentiality: preventing unauthorized disclosure of sensitive information.
Why the other options are wrong
- A. Integrity ensures that information has not been altered or modified by unauthorized parties; it does not address access control.
- B. Availability ensures that authorized users can access information when needed; it does not specifically address restricting access to authorized users only.
Question 8
According to ISO/IEC 27000, what is the definition of information security?
Show answer and explanation
Correct answer: A. Preservation of confidentiality, integrity, and availability of information
According to ISO/IEC 27000, information security is defined as the preservation of confidentiality, integrity, and availability of information. These three principles form the foundational triad of information security and are universally recognized across all ISO/IEC 27000 series standards.
Why the other options are wrong
- B. This describes privacy and personally identifiable information protection, which is related to but distinct from the broader definition of information security.
- C. Authenticity, accountability, and reliability are important security concepts but are not the ISO/IEC 27000 definition of information security; the standard focuses on the CIA triad.
Question 9
Which statement regarding risks and opportunities is correct?
Show answer and explanation
Correct answer: B. Opportunities might have a positive impact, whereas risks might have a negative impact
Risks and opportunities are distinct concepts in risk management. Risks have the potential for negative impact on objectives, while opportunities have the potential for positive impact. Option A incorrectly states risks always have positive outcomes. Option C is incorrect because these terms have fundamentally different meanings and implications for organizational objectives.
Why the other options are wrong
- A. Risks inherently have negative potential outcomes, not positive ones.
- C. Risks and opportunities are distinct concepts with opposite directional impacts on objectives.
Question 10
Which of the following risk assessment methods provides an information security risk assessment methodology and involves three phases build asset-based threat profiles, identify infrastructure vulnerabilities, and develop security strategy and plans?
Show answer and explanation
Correct answer: A. OCTAVE-S
OCTAVE-S is a risk assessment methodology designed for information security that operates through three distinct phases: building asset-based threat profiles, identifying infrastructure vulnerabilities, and developing security strategy and plans. MEHARI and TRA use different methodological approaches that do not align with this three-phase structure.
Why the other options are wrong
- B. MEHARI follows a different risk assessment methodology not aligned with the three specified phases.
- C. TRA (Threat and Risk Assessment) uses a different approach than the asset-based threat profile methodology described.
That was 10 of 60.
The full PECB ISO/IEC 27005 Risk Manager pack has all 60 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.
