Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 3 Question 18 Discussion

What is the greatest risk for an organization if no information security policy has been defined?
D) It is not possible for an organization to implement information security in a consistent manner.
A) If everyone works with the same account, it is impossible to find out who worked on what.
B) Information security activities are carried out by only a few people.
C) Too many measures are implemented.

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 3 Question 18 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 18
Topic #: 3
[All ISO-IEC-27001-Lead-Implementer Questions]

What is the greatest risk for an organization if no information security policy has been defined?

Show Suggested Answer Hide Answer
Suggested Answer: D

Contribute your Thoughts:

0/2000 characters
Fidelia
8 months ago
Totally agree with D, without a policy, chaos reigns!
upvoted 0 times
...
Georgeanna
8 months ago
Surprised that people think too many measures (C) is a risk, isn't that better?
upvoted 0 times
...
Jina
9 months ago
B is a big issue, security shouldn't be a solo job!
upvoted 0 times
...
Thomasena
9 months ago
I think D is more accurate, consistency is key for security.
upvoted 0 times
...
Glenn
9 months ago
Definitely A, can't track who did what without individual accounts.
upvoted 0 times
...
Patria
9 months ago
I vaguely recall that without a defined policy, it could lead to chaos in security measures, which might relate to option D.
upvoted 0 times
...
Soledad
9 months ago
I feel like this question is similar to one we practiced about accountability in security roles. I think option A might be a concern too.
upvoted 0 times
...
James
9 months ago
I’m not entirely sure, but I think option D sounds right because without a policy, it’s hard to have a unified approach to security.
upvoted 0 times
...
Benton
9 months ago
I remember discussing how a lack of policy could lead to inconsistent security practices across the organization.
upvoted 0 times
...
Desire
9 months ago
This seems like a straightforward question on consumer behavior. I'll focus on the key terms in the question and think through the options carefully.
upvoted 0 times
...
Valda
9 months ago
Hmm, the first option about the distorted unit cost seems like it could be a pretty big issue, but I'm not sure if that's the least motivating one. I'll have to weigh the pros and cons of each choice.
upvoted 0 times
...
Marti
10 months ago
Easy peasy! A UPS is designed to provide backup power for a limited time, usually around 10-15 minutes, to allow you to save your work and shut down your systems properly. So the answer is D. 10 minutes.
upvoted 0 times
...

Save Cancel