Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 1 Question 33 Discussion

Does information security reduce the impact of risks?
A) Yes, information security reduces risks and their impact by protecting the organization against threats and vulnerabilities
B) No, information security does not have an impact on risks as information security and risk management are separate processes
C) Yes, information security reduces the impact of risks by eliminating the likelihood of exploitation of vulnerabilities by threats

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 1 Question 33 Discussion

Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 33
Topic #: 1
[All ISO-IEC-27005-Risk-Manager Questions]

Does information security reduce the impact of risks?

Show Suggested Answer Hide Answer
Suggested Answer: A

Information security aims to protect information assets against threats and vulnerabilities that could lead to unauthorized access, disclosure, alteration, or destruction. By implementing effective security measures (such as access controls, encryption, and monitoring), an organization reduces the likelihood of vulnerabilities being exploited and mitigates the potential impact of risks. According to ISO/IEC 27005, risk management in information security includes identifying, assessing, and applying controls to reduce both the likelihood and impact of potential risks. Thus, option A is correct because it acknowledges the role of information security in reducing the impact of risks. Option B is incorrect because information security is a key component of risk management, and option C is incorrect because information security does not eliminate risks entirely; it mitigates their impact.


Contribute your Thoughts:

0/2000 characters
I practiced a question similar to this, and I remember that information security does play a role in mitigating risks, so I lean towards A or C.
upvoted 0 times
...
Denna
5 days ago
I feel like option C is also valid since reducing the likelihood of exploitation seems like a key part of risk management, but I can't recall the exact details.
upvoted 0 times
...
Jesusita
10 days ago
I'm not so sure about option B; I remember studying that information security and risk management are closely linked, but maybe they aren't the same thing?
upvoted 0 times
...
Val
15 days ago
I think option A makes sense because information security measures definitely help protect against various threats.
upvoted 0 times
...

Save Cancel