New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 3 Question 59 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 59
Topic #: 3
[All ISO-IEC-27001-Lead-Implementer Questions]

Scenario 2: Beauty is a cosmetics company that has recently switched to an e-commerce model, leaving the traditional retail. The top management has decided to build their own custom platform in-house and outsource the payment process to an external provider operating online payments systems that support online money transfers.

Due to this transformation of the business model, a number of security controls were implemented based on the identified threats and vulnerabilities associated to critical assets. To protect customers' information. Beauty's employees had to sign a confidentiality agreement. In addition, the company reviewed all user access rights so that only authorized personnel can have access to sensitive files and drafted a new segregation of duties chart.

However, the transition was difficult for the IT team, who had to deal with a security incident not long after transitioning to the e commerce model. After investigating the incident, the team concluded that due to the out-of-date anti-malware software, an attacker gamed access to their files and exposed customers' information, including their names and home addresses.

The IT team decided to stop using the old anti-malware software and install a new one which would automatically remove malicious code in case of similar incidents. The new software was installed in every workstation within the company. After installing the new software, the team updated it with the latest malware definitions and enabled the automatic update feature to keep it up to date at all times. Additionally, they established an authentication process that requires a user identification and password when accessing sensitive information.

In addition, Beauty conducted a number of information security awareness sessions for the IT team and other employees that have access to confidential information in order to raise awareness on the importance of system and network security.

Which statement below suggests that Beauty has implemented a managerial control that helps avoid the occurrence of incidents? Refer to scenario 2.

Show Suggested Answer Hide Answer
Suggested Answer: B

Managerial controls are administrative actions that are designed to prevent or reduce the likelihood of security incidents by influencing human behavior. They include policies, procedures, guidelines, standards, training, and awareness programs. In scenario 2, Beauty has implemented a managerial control by conducting information security awareness sessions for the IT team and other employees that have access to confidential information. These sessions aim to educate the staff on the importance of system and network security, the potential threats and vulnerabilities, and the best practices to follow to avoid the occurrence of incidents. By raising the level of awareness and knowledge of the employees, Beauty can reduce the human errors and negligence that might compromise the security of the information assets.


Contribute your Thoughts:

0/2000 characters
Quentin
2 months ago
Wait, they were using outdated anti-malware? That's shocking!
upvoted 0 times
...
Billye
2 months ago
Definitely B! Security awareness can really make a difference.
upvoted 0 times
...
Olene
2 months ago
Really? I’m not sure just training is enough to prevent incidents.
upvoted 0 times
...
Antonio
3 months ago
A confidentiality agreement is important, but it’s not a managerial control.
upvoted 0 times
...
Marcelle
3 months ago
I think option B is the best choice here. Awareness is key!
upvoted 0 times
...
Launa
3 months ago
I was leaning towards C at first, but now I see how B directly addresses employee behavior, which is key to avoiding future incidents.
upvoted 0 times
...
Elin
3 months ago
I feel like B is definitely the strongest option here. Training employees on security is crucial, especially after a breach.
upvoted 0 times
...
Glendora
4 months ago
I'm not entirely sure, but I remember a similar question where updating policies was considered a managerial control. So maybe A could also be relevant?
upvoted 0 times
...
Chanel
4 months ago
I think the answer might be B because conducting awareness sessions seems like a proactive way to prevent incidents.
upvoted 0 times
...
Vallie
4 months ago
This is a tricky one. I'm torn between the confidentiality agreement and the security awareness sessions. I'll need to re-read the scenario carefully to make sure I don't miss any important details.
upvoted 0 times
...
Margret
4 months ago
I've got a good feeling about this one. The confidentiality agreement and security awareness sessions seem like the most relevant managerial controls mentioned in the scenario.
upvoted 0 times
...
Phuong
4 months ago
Okay, let's think this through step-by-step. The scenario mentions several security measures, but I believe the question is asking specifically about a managerial control. I'll focus on that.
upvoted 0 times
...
Aja
5 months ago
Hmm, I'm a bit unsure about this one. There are a few options that seem relevant, but I'll need to carefully consider each one to determine the best answer.
upvoted 0 times
...
Ula
5 months ago
This question seems straightforward. I think the key is to identify the managerial control that helps avoid the occurrence of incidents.
upvoted 0 times
...
James
8 months ago
I think both options A and B are valid. They both contribute to preventing security incidents in different ways.
upvoted 0 times
...
Scot
8 months ago
I believe option A is also important. Signing a confidentiality agreement shows commitment to protecting sensitive information.
upvoted 0 times
...
Miesha
9 months ago
I agree with you, Nieves. Conducting security awareness sessions is crucial for preventing incidents.
upvoted 0 times
...
William
9 months ago
The information security awareness sessions are definitely the way to go. You can have all the technical controls in the world, but if your employees don't know how to use them properly, you're still vulnerable.
upvoted 0 times
...
Rodolfo
9 months ago
Haha, I bet the IT team was sweating bullets after that security incident. Good thing they got that new anti-malware software in place. That automatic update feature is a lifesaver!
upvoted 0 times
Beula
8 months ago
Definitely, but at least they took action and upgraded their anti-malware software.
upvoted 0 times
...
Dyan
8 months ago
Yeah, that security incident must have been a nightmare for the IT team.
upvoted 0 times
...
...
Aimee
10 months ago
Updating the segregation of duties chart sounds like a smart move to me. Keeping tight control over access to sensitive info is so important these days.
upvoted 0 times
...
Nieves
10 months ago
I think option B is the correct answer.
upvoted 0 times
...
Lenny
10 months ago
The confidentiality agreement is a good step, but I think the security awareness sessions are the real key to preventing incidents. Educating employees is crucial.
upvoted 0 times
Ira
9 months ago
C) Beauty updated the segregation of duties chart
upvoted 0 times
...
Arthur
9 months ago
B) Beauty conducted a number of information security awareness sessions for the IT team and other employees that have access to confidential information
upvoted 0 times
...
Mattie
9 months ago
A) Beauty's employees signed a confidentiality agreement
upvoted 0 times
...
...

Save Cancel