Exam ISO-IEC-27005-Risk-Manager Topic 1 Question 30 Discussion

Actual exam question for PECB's ISO-IEC-27005-Risk-Manager exam
Question #: 30
Topic #: 1
Which activity below is NOT included in the information security risk assessment process?

Suggested Answer: C Vote an answer

The information security risk assessment process, as outlined in ISO/IEC 27005, typically includes identifying risks, assessing their potential impact, and prioritizing them. However, selecting risk treatment options is not part of the risk assessment process itself; it is part of the subsequent risk treatment phase. Therefore, option C is the correct answer as it is not included in the risk assessment process.

by Gwendolyn at Jun 07, 2025, 03:03 AM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

0
0
0
10