Exam Mode

ISO/IEC 27005 Risk Manager

Manage information security risk

The six exams, one by one

ExamFormatQuestions
1Domain training60
2Domain training60
3Domain training60
4Domain training60
5Timed simulation60
6Timed simulation60

The report you get at the end

Not a percentage: a diagnosis. We tell you whether it is worth sitting the exam, which domains to reinforce and how many answers you got right while unsure.

Sample reportYou would pass, but with no margin
Domain 3: Risk management framework78%
Domain 1: Fundamental risk management concepts64%
Domain 4: Other risk assessment methods55%
Domain 2: Implementing a risk management programme82%

The domains assessed

Actual distribution of this product questions.

Domain 3: Risk management framework133
Domain 1: Fundamental risk management concepts79
Domain 4: Other risk assessment methods76
Domain 2: Implementing a risk management programme72

Ten sample exam questions

One per competency domain, exactly as they appear in the simulator.

  1. Domain 1: Fundamental risk management concepts

    Scenario - HealthData: HealthData is a certified health-data hosting provider (HDS) operating from Paris. The organization hosts the electronic health records (EHR) of 200 client clinics and processes 2 million requests daily through a cloud infrastructure. The organization is subject to the GDPR, HDS certification, and the recommendations of ANSSI (the French national cybersecurity agency). The security director, Ms. Morel, has launched a risk management program aligned with ISO/IEC 27005. During the identification phase, her team discovered: (1) undocumented APIs in the EHR access layer, (2) the absence of logging on the authentication server, and (3) a subcontracting contract with a cloud provider whose incident-notification clause is missing. The assessment revealed a high level of risk related to the exfiltration of patient data through the undocumented APIs. The risk owner, medical director Dr. Fabre, must make a decision. In this scenario, how are the undocumented APIs, the absence of logging, and the contract without a notification clause classified?

    1. They are three residual risks resulting from insufficient previous treatment.
    2. They are three vulnerabilities of different kinds: technical, technical, and organizational.
    3. The undocumented APIs are a threat, the absence of logging is a vulnerability, and the contract is a risk.
    4. They are three threats bearing on the patient data held by HealthData.
  2. Domain 3: Risk management framework

    Scenario - HealthData: HealthData is a certified health-data hosting provider (HDS) operating from Paris. The organization hosts the electronic health records (EHR) of 200 client clinics and processes 2 million requests daily through a cloud infrastructure. The organization is subject to the GDPR, HDS certification, and the recommendations of ANSSI (the French national cybersecurity agency). The security director, Ms. Morel, has launched a risk management program aligned with ISO/IEC 27005. During the identification phase, her team discovered: (1) undocumented APIs in the EHR access layer, (2) the absence of logging on the authentication server, and (3) a subcontracting contract with a cloud provider whose incident-notification clause is missing. The assessment revealed a high level of risk related to the exfiltration of patient data through the undocumented APIs. The risk owner, medical director Dr. Fabre, must make a decision. Dr. Fabre, the risk owner, decides to implement encryption of the APIs and centralized logging. In parallel, he takes out cyber insurance covering GDPR notification costs. Which combination of treatment options has he chosen?

    1. Risk modification only, since insurance is a financial security control.
    2. Risk avoidance and risk sharing, since encryption completely prevents exploitation.
    3. Risk retention and risk modification, since insurance means accepting the risk.
    4. A modification combined with risk sharing.
  3. Domain 2: Implementing a risk management programme

    Scenario - HealthData: HealthData is a certified health-data hosting provider (HDS) operating from Paris. The organization hosts the electronic health records (EHR) of 200 client clinics and processes 2 million requests daily through a cloud infrastructure. The organization is subject to the GDPR, HDS certification, and the recommendations of ANSSI (the French national cybersecurity agency). The security director, Ms. Morel, has launched a risk management program aligned with ISO/IEC 27005. During the identification phase, her team discovered: (1) undocumented APIs in the EHR access layer, (2) the absence of logging on the authentication server, and (3) a subcontracting contract with a cloud provider whose incident-notification clause is missing. The assessment revealed a high level of risk related to the exfiltration of patient data through the undocumented APIs. The risk owner, medical director Dr. Fabre, must make a decision. Ms. Morel must establish the risk acceptance criteria. The CEO wants only the cost of the security controls to be taken into account. What is Ms. Morel's best response?

    1. The criteria must incorporate business objectives, regulatory requirements, and risk appetite, not cost alone.
    2. Ms. Morel should disregard the CEO's opinion and define her own criteria independently.
    3. The acceptance criteria should consider only the GDPR requirements, with the other factors being secondary.
    4. The CEO is right: cost-benefit is the only relevant criterion recognized by ISO/IEC 27005.
  4. Domain 4: Other risk assessment methods

    Scenario - GovSecure: The government agency GovSecure is responsible for protecting national critical infrastructure. It employs 500 people and manages systems classified as 'Defense Confidential.' The director, Mr. Bertin, wants to modernize the risk management program by adopting a structured methodology. The technical team recommends EBIOS Risk Manager (the ANSSI method), the external consultant proposes OCTAVE Allegro, and the DPO suggests MEHARI for its knowledge base of scenarios. The agency must comply with ANSSI directives and the European NIS2 regulations. Given that GovSecure is subject to ANSSI directives, which methodology is most consistent with its regulatory framework?

    1. CRAMM, because it is developed by a European government and covers classified systems.
    2. EBIOS Risk Manager.
    3. OCTAVE Allegro, because it is internationally recognized and more recent than EBIOS.
    4. MEHARI, because its knowledge base of scenarios is the most complete on the market.
  5. Domain 1: Fundamental risk management concepts

    A CISO is preparing a presentation for the management committee. He must explain: according to ISO/IEC 27005, information security risk is expressed in terms of:

    1. Risk sources, potential events, consequences, and likelihood.
    2. Probability of occurrence and cost of the financial impact.
    3. Threats, vulnerabilities, and asset value exclusively.
    4. Regulatory non-conformities and applicable penalties.
  6. Domain 3: Risk management framework

    Scenario - HealthData: HealthData is a certified health-data hosting provider (HDS) operating from Paris. The organization hosts the electronic health records (EHR) of 200 client clinics and processes 2 million requests daily through a cloud infrastructure. The organization is subject to the GDPR, HDS certification, and the recommendations of ANSSI (the French national cybersecurity agency). The security director, Ms. Morel, has launched a risk management program aligned with ISO/IEC 27005. During the identification phase, her team discovered: (1) undocumented APIs in the EHR access layer, (2) the absence of logging on the authentication server, and (3) a subcontracting contract with a cloud provider whose incident-notification clause is missing. The assessment revealed a high level of risk related to the exfiltration of patient data through the undocumented APIs. The risk owner, medical director Dr. Fabre, must make a decision. The electronic health records and the remote-consultation process are identified assets. The authentication server is another identified asset. How should they be classified correctly?

    1. All three are primary assets because they are all essential to the operation of HealthData.
    2. All three are supporting assets because they all depend on the cloud infrastructure.
    3. EHRs and remote consultation are primary assets; the authentication server is a supporting asset.
    4. The EHRs are informational supporting assets and the server is a technical primary asset.
  7. Domain 2: Implementing a risk management programme

    An organization has limited resources to start risk management. According to ISO/IEC 27005, what is recommended?

    1. To mandatorily apply the complete process to the entire organization from the first cycle.
    2. To fully outsource risk management to a consultant for the first year.
    3. To postpone risk management until a budget sufficient to cover the entire organization is obtained.
    4. To start with a limited scope and expand it progressively.
  8. Domain 4: Other risk assessment methods

    Scenario - GovSecure: The government agency GovSecure is responsible for protecting national critical infrastructure. It employs 500 people and manages systems classified as 'Defense Confidential.' The director, Mr. Bertin, wants to modernize the risk management program by adopting a structured methodology. The technical team recommends EBIOS Risk Manager (the ANSSI method), the external consultant proposes OCTAVE Allegro, and the DPO suggests MEHARI for its knowledge base of scenarios. The agency must comply with ANSSI directives and the European NIS2 regulations. Mr. Bertin wants to understand the structure of EBIOS RM. Workshop no. 2 aims to identify the 'RO/TO pairs.' What does this term mean?

    1. Systems at risk / due-diligence obligations: the critical systems and the associated regulatory requirements.
    2. Risk scenarios / vulnerability options: the association of a scenario with the corresponding weaknesses.
    3. Risk sources / target objectives: the association of a potential attacker with what it seeks to accomplish.
    4. Reference standards / verification objectives: the applicable standards and the associated audit criteria.
  9. Domain 1: Fundamental risk management concepts

    An incident made an online service inaccessible for 8 hours, without any leak or modification of data. This situation illustrates the importance of protecting the three fundamental pillars of information security. What are these three pillars?

    1. Authentication, authorization, and non-repudiation.
    2. Prevention, detection, and correction.
    3. Confidentiality, integrity, and availability.
    4. Identification, protection, and recovery.
  10. Domain 3: Risk management framework

    Scenario - HealthData: HealthData is a certified health-data hosting provider (HDS) operating from Paris. The organization hosts the electronic health records (EHR) of 200 client clinics and processes 2 million requests daily through a cloud infrastructure. The organization is subject to the GDPR, HDS certification, and the recommendations of ANSSI (the French national cybersecurity agency). The security director, Ms. Morel, has launched a risk management program aligned with ISO/IEC 27005. During the identification phase, her team discovered: (1) undocumented APIs in the EHR access layer, (2) the absence of logging on the authentication server, and (3) a subcontracting contract with a cloud provider whose incident-notification clause is missing. The assessment revealed a high level of risk related to the exfiltration of patient data through the undocumented APIs. The risk owner, medical director Dr. Fabre, must make a decision. After treatment, the exfiltration risk is reduced to moderate. HealthData's criteria define this level as tolerable under monitoring. Who must formally accept this residual risk?

    1. Ms. Morel, as the security director who conducted the risk assessment.
    2. The external ISO/IEC 27001 certification auditor at the next audit.
    3. The cloud provider, because the infrastructure belongs to it and it shares responsibility.
    4. Dr. Fabre, as the designated risk owner.

Answer these same ten questions in the simulator and see the explanation of every option, including the wrong ones. It opens with no sign-up →

About the official exam: its format, duration and number of questions are set by the certification body and may change, so confirm them in its documentation before you sit it. This material trains the standard, not one body's exam, so it is just as useful if you certify elsewhere.

How to use it

  1. Start in guided practice: every answer is marked and explained right away.
  2. Move to timed exam mode once you know the material.
  3. Repeat until you clear 90 %, the threshold we recommend before sitting the real exam.
  4. Work on the domains flagged in red before trying again.

Frequently asked questions

Is this the official exam?

No. It is our own preparation material, with original questions. It is neither affiliated with nor endorsed by any certification body.

How long do I have access?

Twelve months from purchase, the same validity as the official retake.

Can I try it first?

Yes, in three steps. Answer 10 questions from exam 1 with no sign up, with an explanation for every option. Leaving your email opens the whole of exam 1. All six exams are activated with the purchase.

Which languages?

Shown on each product. This one is available in the languages listed above.

The training for this certification

If beyond practising you want the full material, the exam and the certificate, this is the ISO/IEC 27005 Risk Manager training.

See the training

All exams