New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Implementer Exam - Topic 5 Question 40 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 40
Topic #: 5
[All ISO-IEC-27001-Lead-Implementer Questions]

Scenario 2:

Beauty is a well-established cosmetics company in the beauty industry. The company was founded several decades ago with a passion for creating high-quality skincare, makeup, and personal care products that enhance natural beauty. Over the years, Beauty has built a strong reputation for its innovative product offerings, commitment to customer satisfaction, and dedication to ethical and sustainable business practices.

In response to the rapidly evolving landscape of consumer shopping habits, Beauty transitioned from traditional retail to an e-commerce model. To initiate this strategy, Beauty conducted a comprehensive information security risk assessment, analyzing potential threats and vulnerabilities associated with its new e-commerce venture, aligned with its business strategy and objectives.

Concerning the identified risks, the company implemented several information security controls. All employees were required to sign confidentiality agreements to emphasize the importance of protecting sensitive customer dat

a. The company thoroughly reviewed user access rights, ensuring only authorized personnel could access sensitive information. In addition, since the company stores valuable products and unique formulas in the warehouse, it installed alarm systems and surveillance cameras with real-time alerts to prevent any potential act of vandalism.

After a while, the information security team analyzed the audit logs to monitor and track activities across the newly implemented security controls. Upon investigating and analyzing the audit logs, it was discovered that an attacker had accessed the system due to out-of-date anti-malware software, exposing customers' sensitive information, including names and home addresses. Following this, the IT team replaced the anti-malware software with a new one capable of automatically removing malicious code in case of similar incidents. The new software was installed on all workstations and regularly updated with the latest malware definitions, with an automatic update feature enabled. An authentication process requiring user identification and a password was also implemented to access sensitive information.

During the investigation, Maya, the information security manager of Beauty, found that information security responsibilities in job descriptions were not clearly defined, for which the company took immediate action. Recognizing that their e-commerce operations would have a global reach, Beauty diligently researched and complied with the industry's legal, statutory, regulatory, and contractual requirements. It considered international and local regulations, including data privacy laws, consumer protection acts, and global trade agreements.

To meet these requirements, Beauty invested in legal counsel and compliance experts who continuously monitored and ensured the company's compliance with legal standards in every market they operated in. Additionally, Beauty conducted multiple information security awareness sessions for the IT team and other employees with access to confidential information, emphasizing the importance of system and network security.

Under which category does the vulnerability identified by Maya during the incident fall into?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Anika
3 months ago
Definitely a network issue with that breach.
upvoted 0 times
...
Clay
3 months ago
I think this falls under Organization. Clear roles are key!
upvoted 0 times
...
Stevie
3 months ago
Wait, how did they not notice the outdated software sooner?
upvoted 0 times
...
Pamela
4 months ago
Totally agree, they should have kept their anti-malware updated!
upvoted 0 times
...
Bambi
4 months ago
Sounds like a classic case of poor software management!
upvoted 0 times
...
Pete
4 months ago
I’m leaning towards "Site" because the incident involved the software and system access, but I could see it being "Organization" too.
upvoted 0 times
...
Barrett
4 months ago
I practiced a similar question where a lack of clarity in roles led to security breaches. It feels like this situation is also about organizational structure.
upvoted 0 times
...
Vincenza
4 months ago
I'm not entirely sure, but I remember something about network vulnerabilities being linked to software issues. Could this be a network problem?
upvoted 0 times
...
Lindsey
5 months ago
I think the vulnerability might fall under the "Organization" category since it relates to the unclear job descriptions and responsibilities.
upvoted 0 times
...
Nikita
5 months ago
This question requires a good understanding of information security concepts. I'll carefully consider the different categories and how they relate to the vulnerability described in the scenario. Paying close attention to the details will be crucial to selecting the right answer.
upvoted 0 times
...
Elfrieda
5 months ago
I'm a bit confused here. The scenario mentions issues with job descriptions and compliance, so I'm not sure if the vulnerability is strictly a network-level problem. I'll need to re-read the details to make sure I understand the context.
upvoted 0 times
...
Xuan
5 months ago
Okay, the key seems to be that the vulnerability was related to out-of-date anti-malware software. Based on that, I think the answer is Network, since the vulnerability was in the company's network security controls.
upvoted 0 times
...
Miesha
5 months ago
Hmm, the question is a bit tricky. The scenario covers a lot of information security aspects, so I'll need to analyze it closely to pinpoint the specific vulnerability mentioned.
upvoted 0 times
...
Dottie
5 months ago
This seems like a straightforward question about the vulnerability identified during the incident. I'll carefully review the details in the scenario to determine which category it falls under.
upvoted 0 times
...
Rikki
5 months ago
This seems pretty straightforward. I think the answer is A - just need a browser and the NSP IP address to get started.
upvoted 0 times
...
Julio
5 months ago
I think HTTPS and TCP listeners are the ones that support the active/standby setup. It was in one of the practice tests.
upvoted 0 times
...
Arlette
5 months ago
I'm a bit confused by the options here. I know IBM Cloud Pak for Data System has some alert capabilities, but I'm not sure which specific methods are used. I'll have to guess on this one.
upvoted 0 times
...
Lawrence
10 months ago
The 'Organization' option is the way to go here. Apparently, Beauty's security was as flawless as their products. Guess they need to work on their organizational security game as much as their skincare line.
upvoted 0 times
Germaine
9 months ago
Beauty should definitely focus on strengthening their organizational security to prevent incidents like this in the future.
upvoted 0 times
...
Germaine
9 months ago
It's crucial for companies to have clear information security responsibilities defined in job descriptions.
upvoted 0 times
...
Germaine
9 months ago
I agree, organizational security seems to be the weak point in this scenario.
upvoted 0 times
...
...
Chau
10 months ago
Haha, I bet the attacker was like, 'Wow, these guys need to update their anti-malware software more often!' But seriously, the 'Organization' answer is spot on. Beauty should have had its ducks in a row before going digital.
upvoted 0 times
...
Lucy
10 months ago
I think the correct answer is 'C) Organization'. The vulnerability was not a network or site-specific issue, but rather a organizational-level problem where the roles and responsibilities were not clearly defined. This allowed the security breach to occur.
upvoted 0 times
Joesph
9 months ago
Organizational vulnerabilities can be quite risky if not addressed properly. It's crucial for companies to have clear policies and procedures in place.
upvoted 0 times
...
Adelle
9 months ago
I agree. It's important for companies to clearly define information security responsibilities to prevent such incidents.
upvoted 0 times
...
Royal
9 months ago
Yes, you are right. It was definitely an organizational issue that led to the security breach.
upvoted 0 times
...
Ora
10 months ago
I think the correct answer is 'C) Organization'. The vulnerability was not a network or site-specific issue, but rather a organizational-level problem where the roles and responsibilities were not clearly defined. This allowed the security breach to occur.
upvoted 0 times
...
...
Aleta
10 months ago
The vulnerability identified by Maya falls under the 'Organization' category. Clearly, the job descriptions did not clearly define information security responsibilities, which led to the security breach. The company should have had better organizational policies and structures in place to prevent such incidents.
upvoted 0 times
Mona
10 months ago
User 2
upvoted 0 times
...
Milly
10 months ago
User 1
upvoted 0 times
...
...
Kallie
11 months ago
I also believe it is an organizational vulnerability. Beauty should have clearly defined roles and responsibilities to prevent such incidents.
upvoted 0 times
...
Romana
11 months ago
I agree with Salina. Maya found that information security responsibilities were not clearly defined, which is an organizational issue.
upvoted 0 times
...
Salina
11 months ago
I think the vulnerability falls under the category of Organization.
upvoted 0 times
...

Save Cancel