Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27005-Risk-Manager Exam - Topic 2 Question 27 Discussion

Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 27
Topic #: 2
[All ISO-IEC-27005-Risk-Manager Questions]

Does information security reduce the impact of risks?

Show Suggested Answer Hide Answer
Suggested Answer: A

Information security aims to protect information assets against threats and vulnerabilities that could lead to unauthorized access, disclosure, alteration, or destruction. By implementing effective security measures (such as access controls, encryption, and monitoring), an organization reduces the likelihood of vulnerabilities being exploited and mitigates the potential impact of risks. According to ISO/IEC 27005, risk management in information security includes identifying, assessing, and applying controls to reduce both the likelihood and impact of potential risks. Thus, option A is correct because it acknowledges the role of information security in reducing the impact of risks. Option B is incorrect because information security is a key component of risk management, and option C is incorrect because information security does not eliminate risks entirely; it mitigates their impact.


Contribute your Thoughts:

0/2000 characters
Daniel
4 days ago
Option C sounds right to me, but I wonder if it's really possible to eliminate all vulnerabilities completely.
upvoted 0 times
...
Belen
9 days ago
I'm not so sure about option B; I remember studying that risk management and information security often overlap in practice.
upvoted 0 times
...
Chaya
14 days ago
I think option A makes sense because information security measures like firewalls and encryption do help protect against threats.
upvoted 0 times
...

Save Cancel