Exam Mode

EBIOS Risk Manager

French risk analysis method

The six exams, one by one

ExamFormatQuestions
1Domain training50
2Domain training50
3Domain training50
4Domain training50
5Timed simulation80
6Timed simulation80

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
Domain 3 - Risk Assessment78%
Domain 2 - Risk Management Framework64%
Domain 1 - Fundamental Principles and Concepts55%

The domains assessed

Actual distribution of this product questions.

Domain 3 - Risk Assessment138
Domain 2 - Risk Management Framework134
Domain 1 - Fundamental Principles and Concepts88

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. Domain 2 - Risk Management Framework

    An auditor disputes the moment of the initial risk calculation: they place it at Workshop 2 (after the ROs/TOs), the consultant places it later. Who is right, and which workshops provide the two components of the calculation?

    1. It results from the impacts of the RO/TO pairs of Workshop 2 combined with the operational scenarios of Workshop 4
    2. It is calculated by the formula: number of strategic scenarios x number of operational scenarios x threat level of the ecosystem
    3. It results from the crossing between the severity of the feared events rated by the business (Workshop 1) and the likelihood assessed in cybersecurity (Workshop 4)
    4. It comes from the strategic scenario with the highest severity, combined with the technical vulnerabilities with the highest likelihood of success
  2. Domain 3 - Risk Assessment

    The CISO of a hospital wonders to which workshop to attach a biomedical maintenance provider (physical and logical access, without certification) and by which criteria to judge the critical nature of a stakeholder. What is the answer?

    1. Workshop 1 (scope and baseline): the identification of the ecosystem is part of the perimeter set during the initial scoping
    2. Workshop 4 (operational scenarios): the analysis of the ecosystem requires a technical evaluation of the vulnerabilities of each stakeholder
    3. Workshop 2 (risk origins): the analysis of the ecosystem is linked to the identification of attacker profiles and their motivations
    4. Workshop 3 (strategic scenarios): the threat level evaluation opens this workshop and closes the review of the context
  3. Domain 1 - Fundamental Principles and Concepts

    What is an elementary action in the context of Workshop 4 of the EBIOS Risk Manager method, and what role does it play in the development of the operational scenarios?

    1. A unitary security measure applied to a specific supporting asset to reduce the likelihood of an operational scenario identified during the technical analysis
    2. A mandatory step of the EBIOS RM methodology to which each stakeholder of the ecosystem must contribute in order to validate the completeness of the risk analysis
    3. An elementary compliance check carried out by the audit team on each component of the information system to verify the effective application of the security measures of the baseline
    4. A unitary act that a risk origin performs on a supporting asset during an operational scenario, for example the exploitation of a vulnerability
  4. Domain 2 - Risk Management Framework

    Scenario - COSMELUX: a high-end cosmetics house operating in a highly competitive market, whose patents and manufacturing formulas form its strategic assets. The company has a head office in France, two research centres (France, Ireland), four factories (France, Bulgaria, Tunisia, Mexico) and four distribution platforms. The IT of the research centres is managed in-house, that of the factories and distribution by a single outsourced provider. A maintenance operator, also a single one, intervenes in the event of an incident, without any test having been conducted. The researchers are selected with rigour, unlike the other roles, which are subject to lower confidentiality requirements. Within Workshop 1, how many interviews would be needed at a minimum to identify all the feared events of this house?

    1. About 9 interviews: the head office directors and one manager per type of activity, since identical activities across sites give the same results, making it pointless to visit each site.
    2. 10 interviews: one manager per site, since it is their feared events that will be handled
    3. At least 16 interviews: the main head office directors and all the directors or activity managers of each site, for a complete inventory
    4. A single collective interview bringing together all the managers, since the method favours collaborative workshops
  5. Domain 3 - Risk Assessment

    An expert evaluates an operational scenario of 4 elementary actions with success likelihood values of 4, 3, 1 and 4. The technical director is surprised by a low overall result when 3 actions out of 4 are easy. How is this justified according to the standard method of Workshop 4?

    1. The overall score takes the highest success likelihood, because the attacker will exploit the most accessible flaw to advance
    2. The overall score is the average of the success likelihood values, weighted by the technical difficulty of each action
    3. The overall score corresponds to the lowest success likelihood of the chain: the weak link, because the attacker must succeed in all the actions
    4. The overall score is assessed by expert judgement over the whole path, without individual rating of the actions
  6. Domain 1 - Fundamental Principles and Concepts

    Management asks the CISO whether the "Security Continuous Improvement Plan" it approved 2 years ago still bears that name in the current version of the method. What do you answer, and what is the exact term used today?

    1. Risk treatment plan, a document gathering all the security actions to be implemented to treat the risks identified during Workshops 1 to 4
    2. Security Continuous Improvement Plan (SCIP), covering all the corrective and preventive actions identified during the 5 workshops of the method
    3. Cyber Remediation and Resilience Plan (CRRP), a strategic document validated by senior management defining the security investments for the next 3 years
    4. Residual risk register, a document listing all the risks that remain after the application of all the security measures provided for in the method
  7. Domain 2 - Risk Management Framework

    Scenario - COSMELUX: a high-end cosmetics house operating in a highly competitive market, whose patents and manufacturing formulas form its strategic assets. The company has a head office in France, two research centres (France, Ireland), four factories (France, Bulgaria, Tunisia, Mexico) and four distribution platforms. The IT of the research centres is managed in-house, that of the factories and distribution by a single outsourced provider. A maintenance operator, also a single one, intervenes in the event of an incident, without any test having been conducted. The researchers are selected with rigour, unlike the other roles, which are subject to lower confidentiality requirements. Which Risk Origin / Target Objective pairs would be the most likely for this cosmetics house?

    1. A competitor capturing the research results; organized crime setting up a parallel resale market; anti-luxury hacktivists sabotaging a production line
    2. A disgruntled employee disclosing formulas; the regulator imposing sanctions; a raw-materials supplier out of stock
    3. A former service provider slowing production to win a contract; organized crime corrupting components; a cyberterrorist disclosing R&D data, the most likely trio.
    4. A hacker seeking a claim to fame by destabilizing the business; a fraudster aiming for extortion; an agency harming the reputation
  8. Domain 3 - Risk Assessment

    The operational scenarios of a single strategic path can be numerous. Should all the possibilities that an attacker could exploit be described?

    1. Yes, provided that the project budget and the experts' time allow each scenario to be analysed in detail
    2. Yes: all attack possibilities must be described exhaustively in order to have a complete and detailed view
    3. No: the most realistic operating modes are retained, those that the attacker would use given its profile, resources and motivations
    4. No: it is limited to two operational scenarios per strategic path to ease the workload and target the main entry points
  9. Domain 1 - Fundamental Principles and Concepts

    What are the four classic risk treatment options applicable in Workshop 5 of the EBIOS Risk Manager method?

    1. Permanently eliminate the risk, minimize the risk to the lowest possible level, insure the risk with a third party and monitor the risk continuously
    2. Ignore the risk, document the risk, escalate the risk to management and remediate the risk through technical measures targeting the most vulnerable supporting assets of the information system
    3. Prevent the risk, detect the risk, correct the effects of the risk and recover the systems after the risk materializes
    4. Reduce the risk through security measures, accept the risk if it is tolerable, transfer or share the risk, and avoid or refuse the risk by modifying the activity
  10. Domain 2 - Risk Management Framework

    Scenario - COSMELUX: a high-end cosmetics house operating in a highly competitive market, whose patents and manufacturing formulas form its strategic assets. The company has a head office in France, two research centres (France, Ireland), four factories (France, Bulgaria, Tunisia, Mexico) and four distribution platforms. The IT of the research centres is managed in-house, that of the factories and distribution by a single outsourced provider. A maintenance operator, also a single one, intervenes in the event of an incident, without any test having been conducted. The researchers are selected with rigour, unlike the other roles, which are subject to lower confidentiality requirements. To better protect the R&D secrets within the security baseline, what would be the main actions to carry out?

    1. Encrypt all research data in a general way, keep only the final results and delete the intermediate data after each step, which is enough to rule out any risk of leakage.
    2. Deploy a DLP on all the workstations of the research centres and close the USB ports and Internet access of the researchers
    3. Fully internalize the research work, raise researchers' awareness of leaks and close access to external students and experts
    4. Segregate the research data on separate servers with strong authentication, train staff on social engineering and automate the backups of the work

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the EBIOS Risk Manager training.

See the training

All exams