JPNTestでは、ISO-IEC-27005-Risk-Manager試験対策としてPDF版、デスクトップテストエンジン、オンラインテストエンジンの3つの形式をご用意しています。印刷して持ち歩きたい方も、PECB Certified ISO/IEC 27005 Risk Managerの本番環境を再現して練習したい方も、自分に合ったスタイルで62の問題に取り組めます。
PECB ISO-IEC-27005-Risk-Manager 試験概要:
| 認定ベンダー: | PECB |
|---|---|
| 試験名: | PECB Certified ISO/IEC 27005 Risk Manager |
| 試験番号: | ISO-IEC-27005-Risk-Manager |
| 受験料: | $700 USD |
| 対応言語: | フランス語, 英語 |
| 合格点: | 70% |
| 出題数: | 40-80 |
| 試験時間: | 120 分 |
| 関連資格: | PECB Certified ISO/IEC 27005 Senior Risk Manager PECB Certified ISO/IEC 27005 Risk Manager PECB Certified ISO/IEC 27005 Provisional Risk Manager |
| 認定の有効期間: | 認定資格に有効期限はありません。資格の維持は PECB の方針に従います。 |
| 試験形式: | 多肢選択式, 持ち込み可 |
| サンプル問題: | PECB ISO-IEC-27005-Risk-Manager サンプル問題 |
| 受験方法: | オンラインまたは認定試験センターで受験可能な PECB 認定試験。 |
| 前提条件: | ISO/IEC 27005 の基礎的な理解と、情報セキュリティリスクアセスメントおよびリスクマネジメントに関する包括的な知識。 |
| 公式シラバスのURL: | https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27005/iso-iec-27005-risk-manager |
PECB ISO-IEC-27005-Risk-Manager 試験シラバストピック:
| セクション | 目標 |
|---|---|
| トピック 1: 情報セキュリティリスクマネジメントの基本原則と概念 | - 情報セキュリティリスクマネジメントの概念
|
| トピック 2: その他の情報セキュリティリスクアセスメント手法 | - 代替的なリスクアセスメント方法論
|
| トピック 3: 情報セキュリティリスクマネジメントプログラムの実施 | - リスクマネジメントのフレームワーク
|
| トピック 4: ISO/IEC 27005 に基づく情報セキュリティリスクマネジメントプロセス | - リスクコミュニケーションと協議
|
ISO-IEC-27005-Risk-Manager試験についてよくあるご質問
「ISO-IEC-27005-Risk-Manager」は、PECBが実施する「PECB Certified ISO/IEC 27005 Risk Manager」の試験コードです。この試験に合格すると、「ISO/IEC 27005」の認定を取得できます。認定レベルはプロフェッショナルに位置づけられています。関連する認定としては、PECB Certified ISO/IEC 27005 Provisional Risk Manager・PECB Certified ISO/IEC 27005 Risk Manager・PECB Certified ISO/IEC 27005 Senior Risk Managerなどが挙げられます。JPNTestでは、ISO-IEC-27005-Risk-Manager試験対策として62の練習問題をご用意しています。
ISO-IEC-27005-Risk-Manager試験の出題数は40-80、制限時間は120 分です。限られた時間内で全問に取り組む必要があるため、1問にかけられる時間を常に意識し、難しい問題に長く留まりすぎないペース配分が求められます。本番で時間不足に慌てないよう、JPNTestのテストエンジンで制限時間つきの模擬試験に挑戦し、時間配分の感覚を体に覚えさせておくことをおすすめします。
ISO-IEC-27005-Risk-Manager試験の合格ラインは70%、受験料は$700 USDです。万が一不合格だった場合、再受験には改めて全額の受験料が必要になるため、費用面の負担も無視できません。受験前にJPNTestの62の練習問題で模擬試験に取り組み、安定して合格ラインを超えられることを確認してから本番に臨むと安心です。
ISO/IEC 27005 の基礎的な理解と、情報セキュリティリスクアセスメントおよびリスクマネジメントに関する包括的な知識。
受験条件は変更される場合があります。最新かつ正確な情報は、PECBの公式ページで必ずご確認ください。
はい、ご購入前にJPNTestのISO-IEC-27005-Risk-Manager問題集の無料サンプル(PDFデモ)をダウンロードして、問題の品質や形式をご確認いただけます。ご購入後は365日間の無料更新が付帯し、更新期間の終了後も50%割引で継続更新をご利用いただけるため、常に最新の出題傾向に沿った内容で学習を続けられます。
JPNTestでは「返金保証」制度をご用意しています。ご購入後60日以内にISO-IEC-27005-Risk-Manager試験を受験して不合格となった場合、全額返金をご申請いただけます。なお、ご購入後3日以内の受験や、ダウンロード後に実際の受験をしていない場合、無料資料や期限切れのご注文は対象外となり、受験者氏名とお支払い者氏名が一致している必要があります。ご申請の際は、受験票(enrollment slip)の写しと公式スコアレポート(Score Report)のPDFを試験後2日以内にご提出いただき、受理後7日以内に手続きが完了します。返金をご希望でない場合は、同等価値の試験資料2点を無料でお受け取りいただき、元の製品の更新サービスを継続する選択肢もございます。
また、ご購入いただいた製品はお支払い完了後すぐにダウンロードでき、メールでも1分以内にお届けします。2時間以内に届かない場合はカスタマーサポートまでご連絡ください。インストール可能なパソコンの台数に制限はありません。
ISO-IEC-27005-Risk-Manager試験の出題範囲は、全部で4分野で構成されています。主な分野としては、「情報セキュリティリスクマネジメントの基本原則と概念」、「ISO/IEC 27005 に基づく情報セキュリティリスクマネジメントプロセス」、「その他の情報セキュリティリスクアセスメント手法」などが挙げられます。各分野の詳細なトピックと配点は、上記の試験大綱をご確認ください。JPNTestのISO-IEC-27005-Risk-Manager練習問題は、これらの出題分野を幅広くカバーしています。
PECB Certified ISO/IEC 27005 Risk Manager 認定 ISO-IEC-27005-Risk-Manager 試験問題:
問題 #1
Scenario 4: In 2017, seeing that millions of people turned to online shopping, Ed and James Cordon founded the online marketplace for footwear called Poshoe. In the past, purchasing pre-owned designer shoes online was not a pleasant experience because of unattractive pictures and an inability to ascertain the products' authenticity. However, after Poshoe's establishment, each product was well advertised and certified as authentic before being offered to clients. This increased the customers' confidence and trust in Poshoe's products and services. Poshoe has approximately four million users and its mission is to dominate the second-hand sneaker market and become a multi-billion dollar company.
Due to the significant increase of daily online buyers, Poshoe's top management decided to adopt a big data analytics tool that could help the company effectively handle, store, and analyze dat a. Before initiating the implementation process, they decided to conduct a risk assessment. Initially, the company identified its assets, threats, and vulnerabilities associated with its information systems. In terms of assets, the company identified the information that was vital to the achievement of the organization's mission and objectives. During this phase, the company also detected a rootkit in their software, through which an attacker could remotely access Poshoe's systems and acquire sensitive data.
The company discovered that the rootkit had been installed by an attacker who had gained administrator access. As a result, the attacker was able to obtain the customers' personal data after they purchased a product from Poshoe. Luckily, the company was able to execute some scans from the target device and gain greater visibility into their software's settings in order to identify the vulnerability of the system.
The company initially used the qualitative risk analysis technique to assess the consequences and the likelihood and to determine the level of risk. The company defined the likelihood of risk as "a few times in two years with the probability of 1 to 3 times per year." Later, it was decided that they would use a quantitative risk analysis methodology since it would provide additional information on this major risk. Lastly, the top management decided to treat the risk immediately as it could expose the company to other issues. In addition, it was communicated to their employees that they should update, secure, and back up Poshoe's software in order to protect customers' personal information and prevent unauthorized access from attackers.
Based on scenario 4, which scanning tool did Poshoe use to detect the vulnerability in their software?
A. Penetration testing tool
B. Host-based scanning tool
C. Network-based scanning tool
問題 #2
Scenario 7: Adstry is a business growth agency that specializes in digital marketing strategies. Adstry helps organizations redefine the relationships with their customers through innovative solutions. Adstry is headquartered in San Francisco and recently opened two new offices in New York. The structure of the company is organized into teams which are led by project managers. The project manager has the full power in any decision related to projects. The team members, on the other hand, report the project's progress to project managers.
Considering that data breaches and ad fraud are common threats in the current business environment, managing risks is essential for Adstry. When planning new projects, each project manager is responsible for ensuring that risks related to a particular project have been identified, assessed, and mitigated. This means that project managers have also the role of the risk manager in Adstry. Taking into account that Adstry heavily relies on technology to complete their projects, their risk assessment certainly involves identification of risks associated with the use of information technology. At the earliest stages of each project, the project manager communicates the risk assessment results to its team members.
Adstry uses a risk management software which helps the project team to detect new potential risks during each phase of the project. This way, team members are informed in a timely manner for the new potential risks and are able to respond to them accordingly. The project managers are responsible for ensuring that the information provided to the team members is communicated using an appropriate language so it can be understood by all of them.
In addition, the project manager may include external interested parties affected by the project in the risk communication. If the project manager decides to include interested parties, the risk communication is thoroughly prepared. The project manager firstly identifies the interested parties that should be informed and takes into account their concerns and possible conflicts that may arise due to risk communication. The risks are communicated to the identified interested parties while taking into consideration the confidentiality of Adstry's information and determining the level of detail that should be included in the risk communication. The project managers use the same risk management software for risk communication with external interested parties since it provides a consistent view of risks. For each project, the project manager arranges regular meetings with relevant interested parties of the project, they discuss the detected risks, their prioritization, and determine appropriate treatment solutions. The information taken from the risk management software and the results of these meetings are documented and are used for decision-making processes. In addition, the company uses a computerized documented information management system for the acquisition, classification, storage, and archiving of its documents.
Based on scenario 7, Adstry's project managers hold regular meetings with interested parties to discuss risks and risk treatment solutions. According to the guidelines of ISO/IEC 27005, is this in compliance with best practices?
A. Yes, the coordination between project managers and relevant interested parties can be achieved by discussions upon risks and appropriate treatment solutions
B. Yes, risks can be communicated to and discussed with relevant interested parties only if the project manager decides that it is appropriate to do so
C. No, risk owners should not communicate or discuss risk treatment options with external interested parties
問題 #3
Scenario 4: In 2017, seeing that millions of people turned to online shopping, Ed and James Cordon founded the online marketplace for footwear called Poshoe. In the past, purchasing pre-owned designer shoes online was not a pleasant experience because of unattractive pictures and an inability to ascertain the products' authenticity. However, after Poshoe's establishment, each product was well advertised and certified as authentic before being offered to clients. This increased the customers' confidence and trust in Poshoe's products and services. Poshoe has approximately four million users and its mission is to dominate the second-hand sneaker market and become a multi-billion dollar company.
Due to the significant increase of daily online buyers, Poshoe's top management decided to adopt a big data analytics tool that could help the company effectively handle, store, and analyze dat a. Before initiating the implementation process, they decided to conduct a risk assessment. Initially, the company identified its assets, threats, and vulnerabilities associated with its information systems. In terms of assets, the company identified the information that was vital to the achievement of the organization's mission and objectives. During this phase, the company also detected a rootkit in their software, through which an attacker could remotely access Poshoe's systems and acquire sensitive data.
The company discovered that the rootkit had been installed by an attacker who had gained administrator access. As a result, the attacker was able to obtain the customers' personal data after they purchased a product from Poshoe. Luckily, the company was able to execute some scans from the target device and gain greater visibility into their software's settings in order to identify the vulnerability of the system.
The company initially used the qualitative risk analysis technique to assess the consequences and the likelihood and to determine the level of risk. The company defined the likelihood of risk as "a few times in two years with the probability of 1 to 3 times per year." Later, it was decided that they would use a quantitative risk analysis methodology since it would provide additional information on this major risk. Lastly, the top management decided to treat the risk immediately as it could expose the company to other issues. In addition, it was communicated to their employees that they should update, secure, and back up Poshoe's software in order to protect customers' personal information and prevent unauthorized access from attackers.
According to scenario 4, the top management of Poshoe decided to treat the risk immediately after conducting the risk analysis. Is this in compliance with risk management best practices?
A. No, the risk should be communicated to all the interested parties before making any decision regarding risk treatment
B. Yes. risk treatment options should be implemented immediately after analyzing the risk, as the risk could expose the company to other security threats
C. No, risk evaluation should be performed before making any decision regarding risk treatment
問題 #4
Scenario 2: Travivve is a travel agency that operates in more than 100 countries. Headquartered in San Francisco, the US, the agency is known for its personalized vacation packages and travel services. Travivve aims to deliver reliable services that meet its clients' needs. Considering the impact of information security in its reputation, Travivve decided to implement an information security management system (ISMS) based on ISO/IEC 27001. In addition, they decided to establish and implement an information security risk management program. Based on the priority of specific departments in Travivve, the top management decided to initially apply the risk management process only in the Sales Management Department. The process would be applicable for other departments only when introducing new technology.
Travivve's top management wanted to make sure that the risk management program is established based on the industry best practices. Therefore, they created a team of three members that would be responsible for establishing and implementing it. One of the team members was Travivve's risk manager who was responsible for supervising the team and planning all risk management activities. In addition, the risk manager was responsible for monitoring the program and reporting the monitoring results to the top management.
Initially, the team decided to analyze the internal and external context of Travivve. As part of the process of understanding the organization and its context, the team identified key processes and activities. Then, the team identified the interested parties and their basic requirements and determined the status of compliance with these requirements. In addition, the team identified all the reference documents that applied to the defined scope of the risk management process, which mainly included the Annex A of ISO/IEC 27001 and the internal security rules established by Travivve. Lastly, the team analyzed both reference documents and justified a few noncompliances with those requirements.
The risk manager selected the information security risk management method which was aligned with other approaches used by the company to manage other risks. The team also communicated the risk management process to all interested parties through previously established communication mechanisms. In addition, they made sure to inform all interested parties about their roles and responsibilities regarding risk management. Travivve also decided to involve interested parties in its risk management activities since, according to the top management, this process required their active participation.
Lastly, Travivve's risk management team decided to conduct the initial information security risk assessment process. As such, the team established the criteria for performing the information security risk assessment which included the consequence criteria and likelihood criteria.
Based on scenario 2, the team decided to involve interested parties in risk management activities. Is this a good practice?
A. No. only internal interested parties should be involved in risk management activities
B. Yes, relevant interested parties should be involved in risk management activities to ensure the successful completion of the risk assessment
C. No, only the risk management team should be involved in risk management activities
問題 #5
Scenario 5: Detika is a private cardiology clinic in Pennsylvania, the US. Detika has one of the most advanced healthcare systems for treating heart diseases. The clinic uses sophisticated apparatus that detects heart diseases in early stages. Since 2010, medical information of Detika's patients is stored on the organization's digital systems. Electronic health records (EHR), among others, include patients' diagnosis, treatment plan, and laboratory results.
Storing and accessing patient and other medical data digitally was a huge and a risky step for Detik a. Considering the sensitivity of information stored in their systems, Detika conducts regular risk assessments to ensure that all information security risks are identified and managed. Last month, Detika conducted a risk assessment which was focused on the EHR system. During risk identification, the IT team found out that some employees were not updating the operating systems regularly. This could cause major problems such as a data breach or loss of software compatibility. In addition, the IT team tested the software and detected a flaw in one of the software modules used. Both issues were reported to the top management and they decided to implement appropriate controls for treating the identified risks. They decided to organize training sessions for all employees in order to make them aware of the importance of the system updates. In addition, the manager of the IT Department was appointed as the person responsible for ensuring that the software is regularly tested.
Another risk identified during the risk assessment was the risk of a potential ransomware attack. This risk was defined as low because all their data was backed up daily. The IT team decided to accept the actual risk of ransomware attacks and concluded that additional measures were not required. This decision was documented in the risk treatment plan and communicated to the risk owner. The risk owner approved the risk treatment plan and documented the risk assessment results.
Following that, Detika initiated the implementation of new controls. In addition, one of the employees of the IT Department was assigned the responsibility for monitoring the implementation process and ensure the effectiveness of the security controls. The IT team, on the other hand, was responsible for allocating the resources needed to effectively implement the new controls.
Based on scenario 5, the decision to accept the risk of a potential ransomware attack was approved by the risk owner. Is this acceptable?
A. No, all interested parties should approve the risk treatment plan
B. No, the risk treatment plan should be approved by the top management and implemented by risk owners
C. Yes, the risk treatment plan should be approved by the risk owners
解説:
| 問題 #1 正解: B | 問題 #2 正解: A | 問題 #3 正解: C | 問題 #4 正解: B | 問題 #5 正解: C |
263 お客様のコメント



