실제 시험 환경과 유사한 모의고사로 ISO-IEC-27005-Risk-Manager 시험 당일의 긴장감을 미리 경험해 보시기 바랍니다. ExamPassdump의 PECB Certified ISO/IEC 27005 Risk Manager 연습문제 62문항은 시간 관리 연습에도 활용하실 수 있습니다.
PECB ISO-IEC-27005-Risk-Manager 시험 개요:
| 인증 벤더: | PECB |
|---|---|
| 시험명: | PECB 인증 ISO/IEC 27005 위험 관리자 시험 |
| 시험 번호: | ISO-IEC-27005-Risk-Manager |
| 자격증 유효 기간: | 3년 |
| 실제 시험 문항 수: | 60 |
| 시험 시간: | 120분 |
| 합격 점수: | 70% |
| 시험 형식: | 시나리오 기반 문항, 객관식 문항 |
| 관련 자격증: | PECB 인증 ISO/IEC 27005 잠정 위험 관리자 PECB 인증 ISO/IEC 27005 선임 위험 관리자 |
| 지원 언어: | 프랑스어, 스페인어, 독일어, 영어, 이탈리아어, 포르투갈어 |
| 응시료: | 300 ~ 450 미국 달러 |
| 권장 교육: | PECB ISO/IEC 27005 위험 관리자 교육 과정 |
| 시험 등록: | PECB 공식 등록 |
| 샘플 문제: | PECB ISO-IEC-27005-Risk-Manager 샘플 문제 |
| 응시 방법: | 온라인 감독 시험 또는 공인 시험 센터에서의 현장 시험 |
| 전제 조건: | 정보보호 및 ISO/IEC 27001에 대한 기본 지식 보유; 필수 선행 자격증 요건 없음; 정식 자격증 취득 요건: 2년의 실무 경험(그중 위험 관리 분야 1년 포함), 관련 업무 활동 200시간 이수, PECB 윤리 강령 서약 |
| 공식 요강 URL: | https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27005/iso-iec-27005-risk-manager |
PECB ISO-IEC-27005-Risk-Manager 시험 요강 주제:
| 섹션 | 비중 | 목표 |
|---|---|---|
| 기타 정보보호 위험 평가 기법 | 20% | - 일반적인 평가 기법
|
| 정보보호 위험 관리 프로그램의 실행 | 25% | - 프로그램 설계 및 계획 수립
|
| 정보보호 위험 관리의 기본 원칙 및 개념 | 25% | - 위험 관리 개념 및 정의
|
| 정보보호 위험 관리 체계 및 절차 | 30% | - ISO/IEC 27005 기준의 절차
|
PECB ISO-IEC-27005-Risk-Manager 시험에 대한 질문과 답변 모음
ISO-IEC-27005-Risk-Manager 시험은 PECB이 시행하는 공인 인증시험으로, 통과하시면 PECB 인증 ISO/IEC 27005 위험 관리자 인증을 취득하실 수 있습니다. 이 인증은 관리자 등급에 해당합니다. PECB 인증 ISO/IEC 27005 잠정 위험 관리자,PECB 인증 ISO/IEC 27005 선임 위험 관리자 등의 관련 인증과도 연계되어 있어 커리어 확장에 도움이 됩니다. ExamPassdump에서는 해당 시험 대비용 62문항의 연습문제를 제공하고 있습니다.
ISO-IEC-27005-Risk-Manager 시험은 60문항이 출제되며 시험 시간은 120분입니다. 문항당 배정 시간을 미리 계산해 두시면 풀이 속도를 조절하기 쉬우며, 어려운 문제에 시간을 과도하게 쓰지 않고 표시 후 넘어가는 전략이 유효합니다. ExamPassdump의 모의고사로 실제 시험과 동일하게 제한 시간을 설정하고 연습하시면 시간 압박에 대한 대응력을 높이실 수 있습니다.
ISO-IEC-27005-Risk-Manager 시험의 합격 기준 점수는 70%이며 공식 응시료는 300 ~ 450 미국 달러입니다. 불합격하시면 재응시 시 응시료를 다시 전액 납부하셔야 하므로 한 번의 응시로 충분히 대비하시는 것이 경제적입니다. 응시 전에 ExamPassdump의 62문항 모의고사로 실력을 점검하시고, 안정적으로 합격 기준을 넘는 점수가 나올 때 시험에 응시하시기를 권장합니다.
ISO-IEC-27005-Risk-Manager 시험의 응시 조건은 다음과 같습니다. 정보보호 및 ISO/IEC 27001에 대한 기본 지식 보유; 필수 선행 자격증 요건 없음; 정식 자격증 취득 요건: 2년의 실무 경험(그중 위험 관리 분야 1년 포함), 관련 업무 활동 200시간 이수, PECB 윤리 강령 서약 응시 조건은 변경될 수 있으므로 최신 정보는 공식 안내 페이지에서 반드시 확인하시기 바랍니다.
ISO-IEC-27005-Risk-Manager 시험은 아래 공식 접수 채널에서 신청하실 수 있습니다.
시험 방식은 온라인 감독 시험 또는 공인 시험 센터에서의 현장 시험입니다. 접수 전에 시험 방식과 일정을 함께 확인하시기 바랍니다.
PECB에서는 ISO-IEC-27005-Risk-Manager 시험 대비용으로 다음과 같은 공식 교육 과정을 권장하고 있습니다.
공식 교육으로 이론을 학습하신 후 ExamPassdump의 62문항 연습문제로 실전 감각을 보완하시면 학습 효율이 더욱 높아집니다.
가능합니다. ExamPassdump에서는 ISO-IEC-27005-Risk-Manager 무료 샘플 문제를 제공하고 있어 구매 전에 문제 품질과 구성을 직접 확인하실 수 있습니다. 또한 제품 구매 후에는 365일 동안 무료 업데이트가 제공되며, 업데이트 기간이 만료된 이후에는 50% 할인된 가격으로 갱신하실 수 있습니다.
ExamPassdump은 환불 보장 정책을 운영하고 있습니다. 구매 후 60일 이내에 ISO-IEC-27005-Risk-Manager 시험에 응시하여 불합격하신 경우, 응시 등록 확인서 사본과 공식 성적표(Score Report) PDF를 시험일로부터 2일 이내에 제출하시면 전액 환불을 신청하실 수 있으며 접수 후 7일 이내에 처리됩니다. 구매 후 3일 이내 응시, 다운로드 후 미응시, 무료 자료 및 만료된 주문은 적용 대상이 아니며 수험자 명의와 결제자 명의가 일치해야 합니다. 환불 대신 동일한 가치의 다른 시험 자료 2개를 무료로 받고 기존 제품의 업데이트 서비스를 유지하는 방법도 선택하실 수 있습니다. 제품은 결제 즉시 다운로드 가능하며 결제 후 1분 이내에 이메일로도 발송됩니다. 2시간이 지나도 받지 못하신 경우 고객센터로 문의해 주시기 바랍니다. 설치 가능한 컴퓨터 대수에는 제한이 없습니다.
ISO-IEC-27005-Risk-Manager 시험은 총 4개의 출제 영역으로 구성되어 있습니다. 주요 영역으로는 정보보호 위험 관리 체계 및 절차(30%),정보보호 위험 관리 프로그램의 실행(25%),기타 정보보호 위험 평가 기법(20%) 등이 있습니다. 각 영역의 세부 항목과 배점 비율은 위에 정리된 전체 시험 범위에서 확인하시기 바랍니다.
최신 ISO/IEC 27005 ISO-IEC-27005-Risk-Manager 무료샘플문제
What type of process is risk management?
- A. Ongoing, which must be conducted annually and be consistent with the selection of security controls
- B. Iterative, which is conducted simultaneously with internal audits to ensure the effectiveness of an organization's operations
- C. Ongoing, which allows organizations to monitor risk and keep it at an acceptable level
설명: (ExamPassdump 회원만 볼 수 있음)
Scenario 3: Printary is an American company that offers digital printing services. Creating cost-effective and creative products, the company has been part of the printing industry for more than 30 years. Three years ago, the company started to operate online, providing greater flexibility for its clients. Through the website, clients could find information about all services offered by Printary and order personalized products. However, operating online increased the risk of cyber threats, consequently, impacting the business functions of the company. Thus, along with the decision of creating an online business, the company focused on managing information security risks. Their risk management program was established based on ISO/IEC 27005 guidelines and industry best practices.
Last year, the company considered the integration of an online payment system on its website in order to provide more flexibility and transparency to customers. Printary analyzed various available solutions and selected Pay0, a payment processing solution that allows any company to easily collect payments on their website. Before making the decision, Printary conducted a risk assessment to identify and analyze information security risks associated with the software. The risk assessment process involved three phases: identification, analysis, and evaluation. During risk identification, the company inspected assets, threats, and vulnerabilities. In addition, to identify the information security risks, Printary used a list of the identified events that could negatively affect the achievement of information security objectives. The risk identification phase highlighted two main threats associated with the online payment system: error in use and data corruption After conducting a gap analysis, the company concluded that the existing security controls were sufficient to mitigate the threat of data corruption. However, the user interface of the payment solution was complicated, which could increase the risk associated with user errors, and, as a result, impact data integrity and confidentiality.
Subsequently, the risk identification results were analyzed. The company conducted risk analysis in order to understand the nature of the identified risks. They decided to use a quantitative risk analysis methodology because it would provide more detailed information. The selected risk analysis methodology was consistent with the risk evaluation criteri a. Firstly, they used a list of potential incident scenarios to assess their potential impact. In addition, the likelihood of incident scenarios was defined and assessed. Finally, the level of risk was defined as low.
In the end, the level of risk was compared to the risk evaluation and acceptance criteria and was prioritized accordingly.
Based on scenario 3, Printary used a list of identified events that could negatively influence the achievement of its information security objectives to identify information security risks. Is this in compliance with the guidelines of ISO/IEC 27005?
- A. No. a list of risk sources, business processes. and business objectives should be used to identify information security risks
- B. Yes, a list of events that can negatively influence the achievement of information security objectives in the company should be used to identity information security risks
- C. No, a list of risk scenarios with their consequences related to assets or events and their likelihood should be used to identity information security risks
설명: (ExamPassdump 회원만 볼 수 있음)
Scenario 2: Travivve is a travel agency that operates in more than 100 countries. Headquartered in San Francisco, the US, the agency is known for its personalized vacation packages and travel services. Travivve aims to deliver reliable services that meet its clients' needs. Considering the impact of information security in its reputation, Travivve decided to implement an information security management system (ISMS) based on ISO/IEC 27001. In addition, they decided to establish and implement an information security risk management program. Based on the priority of specific departments in Travivve, the top management decided to initially apply the risk management process only in the Sales Management Department. The process would be applicable for other departments only when introducing new technology.
Travivve's top management wanted to make sure that the risk management program is established based on the industry best practices. Therefore, they created a team of three members that would be responsible for establishing and implementing it. One of the team members was Travivve's risk manager who was responsible for supervising the team and planning all risk management activities. In addition, the risk manager was responsible for monitoring the program and reporting the monitoring results to the top management.
Initially, the team decided to analyze the internal and external context of Travivve. As part of the process of understanding the organization and its context, the team identified key processes and activities. Then, the team identified the interested parties and their basic requirements and determined the status of compliance with these requirements. In addition, the team identified all the reference documents that applied to the defined scope of the risk management process, which mainly included the Annex A of ISO/IEC 27001 and the internal security rules established by Travivve. Lastly, the team analyzed both reference documents and justified a few noncompliances with those requirements.
The risk manager selected the information security risk management method which was aligned with other approaches used by the company to manage other risks. The team also communicated the risk management process to all interested parties through previously established communication mechanisms. In addition, they made sure to inform all interested parties about their roles and responsibilities regarding risk management. Travivve also decided to involve interested parties in its risk management activities since, according to the top management, this process required their active participation.
Lastly, Travivve's risk management team decided to conduct the initial information security risk assessment process. As such, the team established the criteria for performing the information security risk assessment which included the consequence criteria and likelihood criteria.
Based on scenario 2, the team decided to involve interested parties in risk management activities. Is this a good practice?
- A. Yes, relevant interested parties should be involved in risk management activities to ensure the successful completion of the risk assessment
- B. No, only the risk management team should be involved in risk management activities
- C. No. only internal interested parties should be involved in risk management activities
설명: (ExamPassdump 회원만 볼 수 있음)
According to CRAMM methodology, how is risk assessment initiated?
- A. By determining methods and procedures for managing risks
- B. By identifying the security risks
- C. By gathering information on the system and identifying assets within the scope
설명: (ExamPassdump 회원만 볼 수 있음)
Scenario 3: Printary is an American company that offers digital printing services. Creating cost-effective and creative products, the company has been part of the printing industry for more than 30 years. Three years ago, the company started to operate online, providing greater flexibility for its clients. Through the website, clients could find information about all services offered by Printary and order personalized products. However, operating online increased the risk of cyber threats, consequently, impacting the business functions of the company. Thus, along with the decision of creating an online business, the company focused on managing information security risks. Their risk management program was established based on ISO/IEC 27005 guidelines and industry best practices.
Last year, the company considered the integration of an online payment system on its website in order to provide more flexibility and transparency to customers. Printary analyzed various available solutions and selected Pay0, a payment processing solution that allows any company to easily collect payments on their website. Before making the decision, Printary conducted a risk assessment to identify and analyze information security risks associated with the software. The risk assessment process involved three phases: identification, analysis, and evaluation. During risk identification, the company inspected assets, threats, and vulnerabilities. In addition, to identify the information security risks, Printary used a list of the identified events that could negatively affect the achievement of information security objectives. The risk identification phase highlighted two main threats associated with the online payment system: error in use and data corruption After conducting a gap analysis, the company concluded that the existing security controls were sufficient to mitigate the threat of data corruption. However, the user interface of the payment solution was complicated, which could increase the risk associated with user errors, and, as a result, impact data integrity and confidentiality.
Subsequently, the risk identification results were analyzed. The company conducted risk analysis in order to understand the nature of the identified risks. They decided to use a quantitative risk analysis methodology because it would provide more detailed information. The selected risk analysis methodology was consistent with the risk evaluation criteri a. Firstly, they used a list of potential incident scenarios to assess their potential impact. In addition, the likelihood of incident scenarios was defined and assessed. Finally, the level of risk was defined as low.
In the end, the level of risk was compared to the risk evaluation and acceptance criteria and was prioritized accordingly.
Which of the following situations indicates that Printary identified consequences of risk scenarios? Refer to scenario 3.
- A. Printary used the list of potential incident scenarios and assessed their impact on company's information security
- B. Printary concluded that the complicated user interface could increase the risk of user error and impact data integrity and confidentiality
- C. Printary identified two main threats associated with the online payment system: error in use and corruption of data
설명: (ExamPassdump 회원만 볼 수 있음)



1182 분의 상품리뷰 


모닝커피 -
ExamPassdump에서 보내준 덤프를 출력하여 공부했는데 덤프만으로 시험봐도 되나싶어 처음엔 엄청 떨렸는데
막상 보니깐 그렇게 어렵진 않더군요.PECB ISO-IEC-27005-Risk-Manager덤프문제 그대로 나왔습니다. 결과는 합격이구요.