New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 2 Question 19 Discussion

Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 19
Topic #: 2
[All ISO-IEC-27005-Risk-Manager Questions]

Scenario 8: Biotide is a pharmaceutical company that produces medication for treating different kinds of diseases. The company was founded in 1997, and since then it has contributed in solving some of the most challenging healthcare issues.

As a pharmaceutical company, Biotide operates in an environment associated with complex risks. As such, the company focuses on risk management strategies that ensure the effective management of risks to develop high-quality medication. With the large amount of sensitive information generated from the company, managing information security risks is certainly an important part of the overall risk management process. Biotide utilizes a publicly available methodology for conducting risk assessment related to information assets. This methodology helps Biotide to perform risk assessment by taking into account its objectives and mission. Following this method, the risk management process is organized into four activity areas, each of them involving a set of activities, as provided below.

1. Activity area 1: The organization determines the criteria against which the effects of a risk occurring can be evaluated. In addition, the impacts of risks are also defined.

2. Activity area 2: The purpose of the second activity area is to create information asset profiles. The organization identifies critical information assets, their owners, as well as the security requirements for those assets. After determining the security requirements, the organization prioritizes them. In addition, the organization identifies the systems that store, transmit, or process information.

3. Activity area 3: The organization identifies the areas of concern which initiates the risk identification process. In addition, the organization analyzes and determines the probability of the occurrence of possible threat scenarios.

4. Activity area 4: The organization identifies and evaluates the risks. In addition, the criteria specified in activity area 1 is reviewed and the consequences of the areas of concerns are evaluated. Lastly, the level of identified risks is determined.

The table below provides an example of how Biotide assesses the risks related to its information assets following this methodology:

According to the risk assessment methodology used by Biotide, what else should be performed during activity area 4? Refer to scenario 8.

Show Suggested Answer Hide Answer
Suggested Answer: B

According to ISO/IEC 27005, the output of the documentation of risk management processes should include detailed information about the results of the risk assessment and the chosen risk treatment options. This ensures transparency and provides a clear record of the decision-making process related to information security risk management. Therefore, option B is the correct answer.


Contribute your Thoughts:

0/2000 characters
Nada
2 months ago
Monitoring security controls is super important too!
upvoted 0 times
...
Jess
2 months ago
Totally agree, risk management is crucial for pharma!
upvoted 0 times
...
Alex
2 months ago
Biotide was founded in 1997.
upvoted 0 times
...
Fausto
3 months ago
Wait, are they really using a public methodology? Sounds risky.
upvoted 0 times
...
Mabelle
3 months ago
I think selecting a mitigation strategy is key here.
upvoted 0 times
...
Sharita
3 months ago
I’m leaning towards selecting a mitigation strategy too, since it seems like the logical next step after identifying and evaluating risks.
upvoted 0 times
...
Roselle
3 months ago
Creating a strategic and operational plan sounds important, but I feel like that might be more relevant to the overall risk management rather than just activity area 4.
upvoted 0 times
...
Sarah
4 months ago
I remember a similar practice question where we had to monitor security controls, but that was more about ongoing processes rather than risk evaluation.
upvoted 0 times
...
Clarinda
4 months ago
I think we might need to select a mitigation strategy for the identified risk profiles in activity area 4, but I'm not entirely sure.
upvoted 0 times
...
An
4 months ago
The key here is to focus on the specific requirements of activity area 4, which is about identifying and evaluating risks. Option B, selecting a mitigation strategy, seems to be the best fit for that step in the process.
upvoted 0 times
...
Frederick
4 months ago
I'm a bit unsure about this one. The question is asking about activity area 4, but the options don't seem to directly match the descriptions given for that area. I'll need to think this through carefully.
upvoted 0 times
...
Franchesca
4 months ago
Based on the information provided, I believe the correct answer is option B. The question specifically asks what should be performed during activity area 4, and selecting a mitigation strategy seems to be the logical next step after identifying and evaluating the risks.
upvoted 0 times
...
Annmarie
5 months ago
Okay, let me re-read the details about the four activity areas. I think I have a good grasp of the overall process now.
upvoted 0 times
...
Herschel
5 months ago
This question seems straightforward, but I want to make sure I understand the risk assessment methodology used by Biotide before answering.
upvoted 0 times
...
Apolonia
10 months ago
I wonder if Biotide has a risk management strategy for dealing with 'Biotide' puns. That could be a real danger zone!
upvoted 0 times
Valda
8 months ago
C) Monitor security controls for ensuring they are appropriate for new threats
upvoted 0 times
...
Elvis
8 months ago
B) Select a mitigation strategy for the identified risk profiles
upvoted 0 times
...
Asuncion
8 months ago
A) Create a strategic and operational plan
upvoted 0 times
...
...
Avery
10 months ago
Hmm, this is a tricky one. I bet the answer involves something about prioritizing the risks based on the criteria established in activity area 1.
upvoted 0 times
...
Jettie
10 months ago
Creating a strategic and operational plan seems like it would come a bit later in the process. Activity area 4 is all about identifying and evaluating the risks, right?
upvoted 0 times
Denise
9 months ago
Monitoring security controls for ensuring they are appropriate for new threats is also important during activity area 4.
upvoted 0 times
...
Yen
9 months ago
I think we should select a mitigation strategy for the identified risk profiles during activity area 4.
upvoted 0 times
...
Loise
9 months ago
Yes, you're correct. Activity area 4 focuses on identifying and evaluating risks.
upvoted 0 times
...
...
Raina
10 months ago
Monitoring security controls is definitely important, but I think evaluating the risks and determining their level is the key focus of activity area 4.
upvoted 0 times
Romana
8 months ago
Monitoring security controls is important, but assessing the risks is the foundation for effective risk management.
upvoted 0 times
...
Lorita
9 months ago
Yes, that's right. It helps in understanding the potential impact of the risks on the organization.
upvoted 0 times
...
Eugene
9 months ago
I agree, evaluating the risks and determining their level is crucial in activity area 4.
upvoted 0 times
...
...
Kirk
10 months ago
This methodology seems quite comprehensive, but I'm curious about the specific steps in activity area 4. Selecting a mitigation strategy seems like a logical next step.
upvoted 0 times
Charisse
9 months ago
C) Monitor security controls for ensuring they are appropriate for new threats
upvoted 0 times
...
Merlyn
9 months ago
B) Select a mitigation strategy for the identified risk profiles
upvoted 0 times
...
Jean
10 months ago
A) Create a strategic and operational plan
upvoted 0 times
...
...
Jovita
10 months ago
I believe monitoring security controls for new threats is also important to ensure ongoing protection.
upvoted 0 times
...
Deane
11 months ago
I agree with Carin, selecting a mitigation strategy is crucial for managing risks effectively.
upvoted 0 times
...
Carin
11 months ago
I think the answer is B) Select a mitigation strategy for the identified risk profiles.
upvoted 0 times
...

Save Cancel