Jede Wiederholung der ISO-IEC-27005-Risk-Manager Prüfung bedeutet nicht nur verlorene Zeit, sondern auch erneute Kosten für die Anmeldung. ZertFragen unterstützt Sie mit 62 sorgfältig erarbeiteten Übungsfragen zur PECB Certified ISO/IEC 27005 Risk Manager, damit Sie gut vorbereitet in den Prüfungsraum gehen.
PECB ISO-IEC-27005-Risk-Manager Prüfungsübersicht:
| Zertifizierungsanbieter: | PECB () |
|---|---|
| Prüfungsname: | Prüfung zum PECB-zertifizierten ISO/IEC 27005 Risikomanager |
| Prüfungsnummer: | ISO-IEC-27005-Risk-Manager |
| Mindestpunktzahl: | 70% |
| Verwandte Zertifizierungen: | ISO/IEC 27005 Risikomanager ISO/IEC 27001 Leitender Implementierer ISO/IEC 27001 Leitender Auditor |
| Anzahl der Fragen: | 80 |
| Gültigkeitsdauer des Zertifikats: | 3 Jahre |
| Prüfungsformat: | Prüfung ohne Hilfsmittel, Multiple-Choice-Fragen |
| Prüfungsgebühr: | Unterscheidet sich je nach Region (üblicherweise im Bereich von 500–1000 USD, keine offizielle Festlegung) |
| Prüfungsdauer: | 120-180 |
| Verfügbare Sprachen: | Englisch, Arabisch, Französisch, Spanisch, Portugiesisch |
| Empfohlenes Training: | PECB-Schulung zum ISO/IEC 27005 Risikomanager |
| Prüfungsanmeldung: | Offizielles PECB-Portal für Zertifizierungen |
| Beispielfragen: | ![]() |
| Prüfungsmethode: | Online-Prüfung oder Vor-Ort-Prüfung mit Aufsicht |
| Voraussetzungen: | Keine zwingenden Teilnahmevoraussetzungen, jedoch werden Kenntnisse zu ISO/IEC 27001 und dem Informationssicherheitsmanagement dringend empfohlen |
| Offizielle Syllabus-URL: | https://pecb.com |
PECB ISO-IEC-27005-Risk-Manager Prüfungsthemen:
| Abschnitt | Ziele |
|---|---|
| Thema 1: Grundsätze des Informationssicherheits-Risikomanagements | - Grundlagen des Risikomanagements - Risikobegriffe und Fachterminologie |
| Thema 2: Methoden der Risikobewertung | - Qualitative Risikoanalyse - Quantitative Risikoanalyse |
| Thema 3: Risikobehandlung und Auswahl von Kontrollmaßnahmen | - Strategien zur Risikominderung - Auswahl und Umsetzung von Kontrollmaßnahmen |
| Thema 4: Rahmenwerk ISO/IEC 27005 | - Prozess der Risikobewertung - Maßnahmen zur Risikobehandlung - Festlegung des Kontexts |
| Thema 5: Risikokommunikation und Überwachung | - Risikoberichterstattung und Kommunikation - Fortlaufende Überwachung und Überprüfung |
Alles Wissenswerte zur ISO-IEC-27005-Risk-Manager Prüfung im Überblick
Die ISO-IEC-27005-Risk-Manager Prüfung (PECB Certified ISO/IEC 27005 Risk Manager) ist eine offizielle Zertifizierungsprüfung von PECB. Wer sie besteht, erwirbt die Zertifizierung PECB-zertifizierter ISO/IEC 27005 Risikomanager. Sie ist dem Niveau Fachkraft zugeordnet. Zudem steht sie im Zusammenhang mit folgenden Zertifizierungen: ISO/IEC 27001 Leitender Implementierer, ISO/IEC 27001 Leitender Auditor, ISO/IEC 27005 Risikomanager. Mit den 62 Übungsfragen von ZertFragen bereiten Sie sich gezielt auf alle Anforderungen dieser Prüfung vor.
Die ISO-IEC-27005-Risk-Manager Prüfung umfasst 80 Fragen, für die Ihnen 120-180 zur Verfügung stehen. Entwickeln Sie schon in der Vorbereitung ein Gefühl für Ihr persönliches Antworttempo, damit am Ende noch ein Puffer für markierte oder knifflige Fragen bleibt. Lassen Sie sich von schwierigen Aufgaben nicht aufhalten: Markieren Sie sie, arbeiten Sie zunächst die sicheren Fragen ab und kehren Sie dann zurück. Absolvieren Sie vor dem Termin mehrere komplette Probeklausuren unter Zeitdruck – etwa mit den Testengines von ZertFragen –, damit Sie die Zeitbegrenzung im realen Ablauf nicht als Belastung empfinden.
Zum Bestehen der ISO-IEC-27005-Risk-Manager Prüfung benötigen Sie 70%. Die offizielle Prüfungsgebühr von PECB beträgt Unterscheidet sich je nach Region (üblicherweise im Bereich von 500–1000 USD, keine offizielle Festlegung); bei einem Nichtbestehen ist für jeden Wiederholungsversuch die volle Gebühr erneut zu entrichten. Um dieses Risiko so klein wie möglich zu halten, testen Sie Ihren Wissensstand vor der Anmeldung mit den 62 Übungsfragen von ZertFragen und melden Sie sich erst an, wenn Sie in den Probeklausuren konstant sichere Ergebnisse erzielen.
PECB gibt für die ISO-IEC-27005-Risk-Manager Prüfung folgende Zulassungsvoraussetzungen bzw. Empfehlungen an: Keine zwingenden Teilnahmevoraussetzungen, jedoch werden Kenntnisse zu ISO/IEC 27001 und dem Informationssicherheitsmanagement dringend empfohlen Da sich die Anforderungen gelegentlich ändern, vergewissern Sie sich bitte vor der Anmeldung auf der offiziellen Seite von PECB über den aktuellen Stand.
Die Anmeldung zur PECB Certified ISO/IEC 27005 Risk Manager erfolgt über die offiziellen Kanäle von PECB:
Zur Prüfungsform selbst: Online-Prüfung oder Vor-Ort-Prüfung mit Aufsicht
PECB empfiehlt zur Vorbereitung auf die PECB Certified ISO/IEC 27005 Risk Manager unter anderem folgende Trainings:
Ergänzend dazu finden Sie bei ZertFragen 62 Übungsfragen zur ISO-IEC-27005-Risk-Manager Prüfung, mit denen Sie das in den Kursen erworbene Wissen unmittelbar anwenden und Ihren Lernfortschritt überprüfen können.
Ja. Bei ZertFragen laden Sie vor dem Kauf eine kostenlose Demo der ISO-IEC-27005-Risk-Manager Lernmaterialien herunter und überzeugen sich in Ruhe von Aufbau und Qualität der Fragen. Nach dem Kauf profitieren Sie zudem 365 Tage lang von kostenlosen Updates: Sobald sich die Prüfungsinhalte der PECB Certified ISO/IEC 27005 Risk Manager ändern, erhalten Sie die aktualisierte Version automatisch per E-Mail. Möchten Sie den Update-Service nach Ablauf des Jahres fortsetzen, gewähren wir Ihnen auf die Verlängerung 50 % Rabatt.
Sollten Sie die ISO-IEC-27005-Risk-Manager Prüfung trotz Vorbereitung mit unseren Materialien nicht bestehen, können Sie innerhalb von 60 Tagen nach dem Kauf eine vollständige Rückerstattung beantragen. Voraussetzung ist, dass Sie die entsprechende Prüfung tatsächlich abgelegt haben; ein Nichtbestehen innerhalb von drei Tagen nach dem Kauf sowie kostenlose oder bereits abgelaufene Bestellungen sind ausgeschlossen, und der Name des Prüfungsteilnehmers muss mit dem des Zahlenden übereinstimmen. Reichen Sie dafür die Anmeldebestätigung (Enrollment Slip) als Scan und das offizielle Score Report als PDF innerhalb von zwei Tagen nach dem Prüfungstermin ein – die Bearbeitung erfolgt anschließend innerhalb von sieben Tagen. Alternativ zur Erstattung können Sie auf Wunsch kostenlos zwei gleichwertige Prüfungsprodukte erhalten und behalten dabei den Update-Service Ihres ursprünglich gekauften Produkts. Die Lieferung selbst erfolgt sofort nach der Zahlung: Sie laden das Produkt direkt herunter und erhalten es zusätzlich innerhalb einer Minute per E-Mail; sollte nach zwei Stunden nichts eingegangen sein, wenden Sie sich bitte an unseren Kundenservice. Eine Beschränkung der Anzahl der Computer, auf denen Sie die Materialien installieren, gibt es nicht.
Die PECB Certified ISO/IEC 27005 Risk Manager gliedert sich in 5 Themenbereiche. Zu den zentralen Inhalten zählen Risikobehandlung und Auswahl von Kontrollmaßnahmen, Grundsätze des Informationssicherheits-Risikomanagements sowie Rahmenwerk ISO/IEC 27005. Die vollständige Gliederung mit allen Themengebieten und Unterpunkten finden Sie in der Prüfungsübersicht weiter oben auf dieser Seite; die Übungsfragen von ZertFragen decken die genannten Bereiche ab.
PECB Certified ISO/IEC 27005 Risk Manager ISO-IEC-27005-Risk-Manager Prüfungsfragen mit Lösungen
Which statement regarding information gathering techniques is correct?
- A. Interviews should be conducted only with individuals responsible for information security management
- B. Organizations can utilize technical tools to identify technical vulnerabilities and compile a list of assets that influence risk assessment
- C. Sending questionnaires to a group of people who represent the interested parties is NOT preferred
Antwort: B 🗳️
Erklärung: (Nur für ZertFragen-Mitglieder sichtbar)
Scenario 2: Travivve is a travel agency that operates in more than 100 countries. Headquartered in San Francisco, the US, the agency is known for its personalized vacation packages and travel services. Travivve aims to deliver reliable services that meet its clients' needs. Considering the impact of information security in its reputation, Travivve decided to implement an information security management system (ISMS) based on ISO/IEC 27001. In addition, they decided to establish and implement an information security risk management program. Based on the priority of specific departments in Travivve, the top management decided to initially apply the risk management process only in the Sales Management Department. The process would be applicable for other departments only when introducing new technology.
Travivve's top management wanted to make sure that the risk management program is established based on the industry best practices. Therefore, they created a team of three members that would be responsible for establishing and implementing it. One of the team members was Travivve's risk manager who was responsible for supervising the team and planning all risk management activities. In addition, the risk manager was responsible for monitoring the program and reporting the monitoring results to the top management.
Initially, the team decided to analyze the internal and external context of Travivve. As part of the process of understanding the organization and its context, the team identified key processes and activities. Then, the team identified the interested parties and their basic requirements and determined the status of compliance with these requirements. In addition, the team identified all the reference documents that applied to the defined scope of the risk management process, which mainly included the Annex A of ISO/IEC 27001 and the internal security rules established by Travivve. Lastly, the team analyzed both reference documents and justified a few noncompliances with those requirements.
The risk manager selected the information security risk management method which was aligned with other approaches used by the company to manage other risks. The team also communicated the risk management process to all interested parties through previously established communication mechanisms. In addition, they made sure to inform all interested parties about their roles and responsibilities regarding risk management. Travivve also decided to involve interested parties in its risk management activities since, according to the top management, this process required their active participation.
Lastly, Travivve's risk management team decided to conduct the initial information security risk assessment process. As such, the team established the criteria for performing the information security risk assessment which included the consequence criteria and likelihood criteria.
Based on scenario 2, the team decided to involve interested parties in risk management activities. Is this a good practice?
- A. Yes, relevant interested parties should be involved in risk management activities to ensure the successful completion of the risk assessment
- B. No. only internal interested parties should be involved in risk management activities
- C. No, only the risk management team should be involved in risk management activities
Antwort: A 🗳️
Erklärung: (Nur für ZertFragen-Mitglieder sichtbar)
Scenario 2: Travivve is a travel agency that operates in more than 100 countries. Headquartered in San Francisco, the US, the agency is known for its personalized vacation packages and travel services. Travivve aims to deliver reliable services that meet its clients' needs. Considering the impact of information security in its reputation, Travivve decided to implement an information security management system (ISMS) based on ISO/IEC 27001. In addition, they decided to establish and implement an information security risk management program. Based on the priority of specific departments in Travivve, the top management decided to initially apply the risk management process only in the Sales Management Department. The process would be applicable for other departments only when introducing new technology.
Travivve's top management wanted to make sure that the risk management program is established based on the industry best practices. Therefore, they created a team of three members that would be responsible for establishing and implementing it. One of the team members was Travivve's risk manager who was responsible for supervising the team and planning all risk management activities. In addition, the risk manager was responsible for monitoring the program and reporting the monitoring results to the top management.
Initially, the team decided to analyze the internal and external context of Travivve. As part of the process of understanding the organization and its context, the team identified key processes and activities. Then, the team identified the interested parties and their basic requirements and determined the status of compliance with these requirements. In addition, the team identified all the reference documents that applied to the defined scope of the risk management process, which mainly included the Annex A of ISO/IEC 27001 and the internal security rules established by Travivve. Lastly, the team analyzed both reference documents and justified a few noncompliances with those requirements.
The risk manager selected the information security risk management method which was aligned with other approaches used by the company to manage other risks. The team also communicated the risk management process to all interested parties through previously established communication mechanisms. In addition, they made sure to inform all interested parties about their roles and responsibilities regarding risk management. Travivve also decided to involve interested parties in its risk management activities since, according to the top management, this process required their active participation.
Lastly, Travivve's risk management team decided to conduct the initial information security risk assessment process. As such, the team established the criteria for performing the information security risk assessment which included the consequence criteria and likelihood criteria.
Did the risk management team establish all the criteria required to perform the information security risk assessment? Refer to scenario 2.
- A. No, the risk management team should also establish the criteria for treating the identified risks
- B. No, the risk management team should also establish the criteria for determining the level of risk
- C. Yes. the risk management team established all the criteria that are necessary to perform an information security risk assessment
Antwort: B 🗳️
Erklärung: (Nur für ZertFragen-Mitglieder sichtbar)
An organization has installed security cameras and alarm systems. What type of information security control has been implemented in this case?
- A. Legal
- B. Technical
- C. Managerial
Antwort: B 🗳️
Erklärung: (Nur für ZertFragen-Mitglieder sichtbar)
Scenario 3: Printary is an American company that offers digital printing services. Creating cost-effective and creative products, the company has been part of the printing industry for more than 30 years. Three years ago, the company started to operate online, providing greater flexibility for its clients. Through the website, clients could find information about all services offered by Printary and order personalized products. However, operating online increased the risk of cyber threats, consequently, impacting the business functions of the company. Thus, along with the decision of creating an online business, the company focused on managing information security risks. Their risk management program was established based on ISO/IEC 27005 guidelines and industry best practices.
Last year, the company considered the integration of an online payment system on its website in order to provide more flexibility and transparency to customers. Printary analyzed various available solutions and selected Pay0, a payment processing solution that allows any company to easily collect payments on their website. Before making the decision, Printary conducted a risk assessment to identify and analyze information security risks associated with the software. The risk assessment process involved three phases: identification, analysis, and evaluation. During risk identification, the company inspected assets, threats, and vulnerabilities. In addition, to identify the information security risks, Printary used a list of the identified events that could negatively affect the achievement of information security objectives. The risk identification phase highlighted two main threats associated with the online payment system: error in use and data corruption After conducting a gap analysis, the company concluded that the existing security controls were sufficient to mitigate the threat of data corruption. However, the user interface of the payment solution was complicated, which could increase the risk associated with user errors, and, as a result, impact data integrity and confidentiality.
Subsequently, the risk identification results were analyzed. The company conducted risk analysis in order to understand the nature of the identified risks. They decided to use a quantitative risk analysis methodology because it would provide more detailed information. The selected risk analysis methodology was consistent with the risk evaluation criteri a. Firstly, they used a list of potential incident scenarios to assess their potential impact. In addition, the likelihood of incident scenarios was defined and assessed. Finally, the level of risk was defined as low.
In the end, the level of risk was compared to the risk evaluation and acceptance criteria and was prioritized accordingly.
Based on scenario 3, Printary used a list of identified events that could negatively influence the achievement of its information security objectives to identify information security risks. Is this in compliance with the guidelines of ISO/IEC 27005?
- A. Yes, a list of events that can negatively influence the achievement of information security objectives in the company should be used to identity information security risks
- B. No. a list of risk sources, business processes. and business objectives should be used to identify information security risks
- C. No, a list of risk scenarios with their consequences related to assets or events and their likelihood should be used to identity information security risks
Antwort: A 🗳️
Erklärung: (Nur für ZertFragen-Mitglieder sichtbar)

987 Kundenrezensionen 







Seyfer -
Schön, dass ich die ISO-IEC-27005-Risk-Manager Prüfung bestanden habe. Dank für ihre Hilfe.