Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam Lead Implementer All Questions

View all questions & answers for the Lead Implementer exam

Exam Lead Implementer topic 1 question 13 discussion

Actual exam question from PECB's Lead Implementer
Question #: 13
Topic #: 1
[All Lead Implementer Questions]

Which of the following statements regarding information security risk is NOT correct?

  • A. Information security risk is associated with the potential that the vulnerabilities of an information asset may be exploited by threats
  • B. Information security risk cannot be accepted without being treated or during the process of risk treatment
  • C. Information security risk can be expressed as the effect of uncertainty on information security objectives
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Everfaithful1
1 month, 2 weeks ago
Selected Answer: B
The incorrect statement is: B. Information security risk cannot be accepted without being treated or during the process of risk treatment This statement is NOT correct because according to ISO 27001, risk acceptance is one of the possible risk treatment options. Organizations may accept certain risks if the cost of mitigation is higher than the potential impact of the risk or if the risk is deemed to be at an acceptable level. Therefore, information security risks can be accepted without being treated, as part of the risk treatment process.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...