Exam ISO-IEC-27005-Risk-Manager Topic 1 Question 30 Discussion
Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 30
Topic #: 1
Question #: 30
Topic #: 1
Which activity below is NOT included in the information security risk assessment process?
Suggested Answer: C Vote an answer
The information security risk assessment process, as outlined in ISO/IEC 27005, typically includes identifying risks, assessing their potential impact, and prioritizing them. However, selecting risk treatment options is not part of the risk assessment process itself; it is part of the subsequent risk treatment phase. Therefore, option C is the correct answer as it is not included in the risk assessment process.
by Gwendolyn at Jun 07, 2025, 03:03 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).