New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 1 Question 11 Discussion

Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 11
Topic #: 1
[All ISO-IEC-27005-Risk-Manager Questions]

What type of process is risk management?

Show Suggested Answer Hide Answer
Suggested Answer: A

According to the CRAMM (CCTA Risk Analysis and Management Method) methodology, risk assessment begins by collecting detailed information on the system and identifying all assets that fall within the defined scope. This foundational step ensures that the assessment is comprehensive and includes all relevant assets, which could be potential targets for risk. This makes option A the correct answer.


Contribute your Thoughts:

0/2000 characters
Aimee
3 months ago
I thought it was just a one-time thing, but ongoing makes sense!
upvoted 0 times
...
Leandro
3 months ago
Wait, it has to be annual? That seems too rigid.
upvoted 0 times
...
Dylan
3 months ago
I agree, it should be ongoing to stay effective.
upvoted 0 times
...
Jamie
4 months ago
I think it's more iterative, especially with audits involved.
upvoted 0 times
...
Armando
4 months ago
Definitely ongoing! You can't just set it and forget it.
upvoted 0 times
...
Yolando
4 months ago
I’m a bit confused; I thought risk management was more about regular assessments rather than just being ongoing. Maybe I should go with option A?
upvoted 0 times
...
Davida
4 months ago
I feel like option A makes the most sense since it talks about monitoring risk continuously, which aligns with what we learned.
upvoted 0 times
...
Tarra
4 months ago
I remember practicing a question that emphasized the iterative nature of risk management, so I might lean towards option B.
upvoted 0 times
...
Shala
5 months ago
I think risk management is ongoing, but I'm not sure if it needs to be conducted annually like option C suggests.
upvoted 0 times
...
Franchesca
5 months ago
I think the key here is that risk management is an ongoing, continuous process, not something that's done in isolation or on a fixed schedule. Option A seems to capture that best, so I'm leaning towards selecting that one.
upvoted 0 times
...
Glenna
5 months ago
Wait, is risk management really just an ongoing process? I thought there were more specific requirements around how it's conducted. I'm a bit confused by the wording of these options - I'll need to re-read them carefully to make sure I understand the nuances.
upvoted 0 times
...
Jackie
5 months ago
Okay, I've got this. Risk management is an ongoing process that allows organizations to continuously monitor and manage risks. It's not something that's just done once a year or in parallel with other activities. I'm confident option A is the correct answer.
upvoted 0 times
...
Joaquin
5 months ago
Hmm, I'm a little unsure about this one. Risk management could be ongoing, but it might also be iterative or have some other specific requirements. I'll need to think through the differences between the answer choices to make sure I select the right one.
upvoted 0 times
...
Hubert
5 months ago
This seems like a straightforward question about the nature of risk management. I'll read through the options carefully and try to identify the key characteristics of each type of process.
upvoted 0 times
...
Vonda
5 months ago
Hmm, this seems like a tricky one. I'll need to think through the different options carefully.
upvoted 0 times
...
Vivan
10 months ago
Risk management is like a game of whack-a-mole, but with higher stakes. Gotta stay on top of it, that's for sure.
upvoted 0 times
Noelia
9 months ago
C) Ongoing, which must be conducted annually and be consistent with the selection of security controls
upvoted 0 times
...
Paulene
9 months ago
Risk management is definitely a continuous process.
upvoted 0 times
...
Rosio
9 months ago
A) Ongoing, which allows organizations to monitor risk and keep it at an acceptable level
upvoted 0 times
...
...
Georgeanna
10 months ago
Annual risk management? No thank you, I want to be on top of it all year round. A is the clear winner here.
upvoted 0 times
Elza
9 months ago
User 3: I think A is the way to go, keeping risk at an acceptable level is key.
upvoted 0 times
...
Jacklyn
9 months ago
User 2: Definitely, option A seems like the best choice for ongoing monitoring.
upvoted 0 times
...
Vilma
10 months ago
User 1: I agree, staying on top of risk management all year round is crucial.
upvoted 0 times
...
...
Casandra
10 months ago
Hold up, is this a trick question? Iterative risk management? I think I'll stick with the classic ongoing approach.
upvoted 0 times
...
Marget
10 months ago
Hmm, I'd say option A is the way to go. Monitoring risk is key to keeping it under control.
upvoted 0 times
Meaghan
9 months ago
Option A seems like the most effective approach for risk management.
upvoted 0 times
...
Dustin
9 months ago
It's an ongoing process that needs to be consistently monitored.
upvoted 0 times
...
Cheryll
9 months ago
Definitely, keeping risk at an acceptable level is important for organizations.
upvoted 0 times
...
Rikki
10 months ago
I agree, monitoring risk is crucial to maintaining control.
upvoted 0 times
...
...
Kayleigh
11 months ago
But isn't it also iterative, conducted simultaneously with internal audits?
upvoted 0 times
...
Evangelina
11 months ago
Risk management is definitely an ongoing process. Gotta keep a close eye on those risks, am I right?
upvoted 0 times
Jolanda
9 months ago
Absolutely, staying proactive is key in risk management.
upvoted 0 times
...
Jennie
9 months ago
C) Ongoing, which must be conducted annually and be consistent with the selection of security controls
upvoted 0 times
...
German
9 months ago
Yes, it's important to continuously assess and manage risks.
upvoted 0 times
...
Stephaine
10 months ago
A) Ongoing, which allows organizations to monitor risk and keep it at an acceptable level
upvoted 0 times
...
...
Laurene
11 months ago
I agree with Ronald, it allows organizations to monitor risk continuously.
upvoted 0 times
...
Ronald
11 months ago
I think risk management is an ongoing process.
upvoted 0 times
...

Save Cancel