PECB EBIOS Risk Manager EBIOS Risk Manager Dumps in PDF

Free PECB EBIOS Risk Manager Real Questions (page: 3)

What does the strategic scenario represent?

  1. All the paths of attack that a risk origin is likely to take to achieve its intended objective
  2. All risk origins that can be brought to reach their target objective on an organization business asset
  3. All the target objectives that a risk origin may search for within the same business asset ecosystem

Answer(s): A

Explanation:

A strategic scenario represents the set of plausible attack paths that a risk origin could use to achieve its objective against a business asset. It captures the attacker's overall strategy and possible approaches at a high level, without detailing the technical execution steps.



SCENARIO - ManageSys

ManageSys is an outsourcing company that carries out systems administration and maintenance on behalf of its customers. ManageSys' commercial outsourcing offering includes a range of services such as installation, administration, supervision and maintenance of systems and application services. ManageSys does not have its own hosting infrastructure and has a hosting contract with HostServ.

ManageSys customers include a number of major international accounts and small and medium-sized enterprises in all sectors of activity in several European countries. ManageSys is ITIL-certified (Information Technology Infrastructure Library) and has technical staff certified by solution providers and security product suppliers.

Its main partner, HostServ, is a systems hosting company with a presence at 2 sites (one in France and another one in Germany), providing its infrastructure with a standard level of security. HostServ also uses subcontractors to ensure the smooth running of the various sites, in accordance with established specifications and regular monitoring of services. A security policy is in place and serves as an operating framework for all stakeholders

HostServ is organized as follows:

General services are provided directly by the host for the air conditioning, electricity, fire extinguishing and smoke detection systems, etc., as well as for the management of electrical power and back-up power (battery, generator).
The management of security services (access control, intrusion, video surveillance, human security) is also handled by HostServ, even though the hardware (cameras and access control equipment) is maintained by suppliers.
Guarding (physical security) is provided for each site. These are different guarding companies for each site, subcontracted by the hosting provider.

Relations between ManageSys staff and HostServ staff are rather difficult: HostServ's general services management staff refuse to receive orders from customers like ManageSys.

Access conditions to HostServ's hosting sites change regularly, often depending on who is on duty on site, making it difficult for ManageSys staff to access the sites.

The working conditions of ManageSys staff are sometimes difficult to ensure a good quality of service to its own customers, particularly when maintenance operations are carried out by HostServ staff without notifying ManageSys (which regularly causes power cuts or other malfunctions affecting the servers).

Recently, a ManageSys customer wanted to audit all its suppliers, including ManageSys. During this audit, the customer's auditors wanted to check the equipment on HostServ's premises. HostServ refused to carry out this part of the audit, arguing that the audit clause did not apply to it.

Under which category of the risk treatment plan does HostServ or ManageSys train staff on the procedures to be applied?

  1. Protection
  2. Governance
  3. Defense

Answer(s): B

Explanation:

Training staff on procedures is part of governance because it concerns defining, communicating, and ensuring the proper application of organizational rules, responsibilities, and processes. In EBIOS Risk Manager, governance measures aim to structure how people act and coordinate, particularly across organizational boundaries such as those between ManageSys and HostServ.



Does an organizations security baseline depend on the level of compliance?

  1. The security baseline depends on the activity of the CISO, whereas the level of compliance is linked to legal obligations, which are managed by the Legal Director in the contracts, with little adherence
  2. The security baseline depends on the level of compliance, but also on the means, resources and budget allocated to information systems security
  3. The security baseline is the result of the level of compliance, as it depends on the effectiveness of the security measures implemented

Answer(s): B

Explanation:

In EBIOS Risk Manager, the security baseline is influenced by the level of compliance with legal, regulatory, and contractual obligations, but it is not determined by compliance alone. It also depends on the organization's available means, resources, and budget, which condition the realistic implementation and maintenance of security measures.



What is the purpose of having business managers define the level of severity for each feared event?

  1. It enables each business manager to obtain quantified results concerning the impact of feared events. In this way, prioritization can be carried out more easily
  2. It provides the list of impacts and the list of feared events to define the scope to be analyzed
  3. It ensures that business managers apply the EBIOS Risk Manager method to their scope of activity

Answer(s): A

Explanation:

Having business managers define the severity of feared events ensures that impacts are assessed from a business perspective using quantified criteria. This makes the consequences of feared events comparable and allows risks to be prioritized objectively according to their potential impact on the organization's activities.



Does the identification of the threat level only concern external stakeholders?

  1. Yes, because stakeholders are mainly those representing a potential danger to the organization
  2. No, all internal and external stakeholders must be identified and assessed to define their respective threat level
  3. No, external stakeholders must first have a defined threat level before carrying out the same analysis and assessment of the internal stakeholders

Answer(s): B

Explanation:

In EBIOS Risk Manager, the identification of threat levels applies to all stakeholders, whether internal or external. Both categories can represent potential risk origins depending on their position, access, capabilities, and intent within the ecosystem, and must therefore be assessed consistently.



At the end of Workshop 2, what type of mapping is carried out based on the results of the feared events obtained by business managers?

  1. A map of dangerous situations concerning business assets
  2. A mapping of the operational threats on the ecosystem
  3. A mapping of risk origins and associated target objectives

Answer(s): C

Explanation:

At the end of Workshop 2, the method establishes a mapping of risk origins and their associated target objectives. Based on the feared events identified by business managers, this mapping links potential attackers or threat sources to the business assets they may target, preparing the development of strategic scenarios.



With regard to the results of Workshop 4, what factors should be taken into account to protect business assets?

  1. Vulnerabilities with the highest probability of success and technical difficulty scores should be investigated as a priority
  2. Vulnerabilities with the highest probability of success scores or the lowest technical difficulty scores should be investigated as a priority
  3. All the vulnerabilities are worth remembering. All the basic actions indicated in the methods of attack are vulnerabilities

Answer(s): B

Explanation:

Following Workshop 4, protection priorities focus on vulnerabilities that are most exploitable by an attacker.
Those with a high probability of success or low technical difficulty represent the easiest and most realistic attack opportunities, so addressing them first most effectively reduces the risk to business assets.



What is the best practice recommended by the EBIOS Risk Manager method for analyzing the results of feared events?

  1. The results of the analyses should be prioritized according to the highest level of severity first, ending with the lowest level of severity of the feared events
  2. The results of the analyses must be prioritized according to the criticality level of the activity only, without taking into account the level of severity. Business asset concerns have priority
  3. The results of the analyses must be prioritized from the lowest to the highest level of severity. The resolution work will be applied progressively to all levels of severity and will automatically reduce them

Answer(s): A

Explanation:

EBIOS Risk Manager recommends prioritizing the analysis of feared events by starting with those that have the highest severity. Addressing the most severe impacts first ensures that the most critical business consequences are treated as a priority, enabling efficient allocation of resources to what threatens the organization the most.



Share your comments for PECB EBIOS Risk Manager exam with other users:

R
rsmyth
5/18/2023 12:44:00 PM

q40 the answer is not d, why are you giving incorrect answers? snapshot consolidation is used to merge the snapshot delta disk files to the vm base disk

K
Keny
6/23/2023 9:00:00 PM

thanks, very relevant

M
Muhammad Rawish Siddiqui
11/29/2023 12:14:00 PM

wrong answer. it is true not false.

J
Josh
7/10/2023 1:54:00 PM

please i need the mo-100 questions

V
VINNY
6/2/2023 11:59:00 AM

very good use full

A
Andy
12/6/2023 5:56:00 AM

very valid questions

M
Mamo
8/12/2023 7:46:00 AM

will these question help me to clear pl-300 exam?

M
Marial Manyang
7/26/2023 10:13:00 AM

please provide me with these dumps questions. thanks

A
Amel Mhamdi
12/16/2022 10:10:00 AM

in the pdf downloaded is write google cloud database engineer i think that it isnt the correct exam

A
Angel
8/30/2023 10:58:00 PM

i think you have the answers wrong regarding question: "what are three core principles of web content accessibility guidelines (wcag)? answer: robust, operable, understandable

S
SH
5/16/2023 1:43:00 PM

these questions are not valid , they dont come for the exam now

S
sudhagar
9/6/2023 3:02:00 PM

question looks valid

V
Van
11/24/2023 4:02:00 AM

good for practice

D
Divya
8/2/2023 6:54:00 AM

need more q&a to go ahead

R
Rakesh
10/6/2023 3:06:00 AM

question 59 - a newly-created role is not assigned to any user, nor granted to any other role. answer is b https://docs.snowflake.com/en/user-guide/security-access-control-overview

N
Nik
11/10/2023 4:57:00 AM

just passed my exam today. i saw all of these questions in my text today. so i can confirm this is a valid dump.

D
Deep
6/12/2023 7:22:00 AM

needed dumps

T
tumz
1/16/2024 10:30:00 AM

very helpful

N
NRI
8/27/2023 10:05:00 AM

will post once the exam is finished

K
kent
11/3/2023 10:45:00 AM

relevant questions

Q
Qasim
6/11/2022 9:43:00 AM

just clear exam on 10/06/2202 dumps is valid all questions are came same in dumps only 2 new questions total 46 questions 1 case study with 5 question no lab/simulation in my exam please check the answers best of luck

C
Cath
10/10/2023 10:09:00 AM

q.112 - correct answer is c - the event registry is a module that provides event definitions. answer a - not correct as it is the definition of event log

S
Shiji
10/15/2023 1:31:00 PM

good and useful.

A
Ade
6/25/2023 1:14:00 PM

good questions

P
Praveen P
11/8/2023 5:18:00 AM

good content

A
Anastasiia
12/28/2023 9:06:00 AM

totally not correct answers. 21. you have one gcp account running in your default region and zone and another account running in a non-default region and zone. you want to start a new compute engine instance in these two google cloud platform accounts using the command line interface. what should you do? correct: create two configurations using gcloud config configurations create [name]. run gcloud config configurations activate [name] to switch between accounts when running the commands to start the compute engine instances.

P
Priyanka
7/24/2023 2:26:00 AM

kindly upload the dumps

N
Nabeel
7/25/2023 4:11:00 PM

still learning

G
gure
7/26/2023 5:10:00 PM

excellent way to learn

C
ciken
8/24/2023 2:55:00 PM

help so much

B
Biswa
11/20/2023 9:28:00 AM

understand sql col.

S
Saint Pierre
10/24/2023 6:21:00 AM

i would give 5 stars to this website as i studied for az-800 exam from here. it has all the relevant material available for preparation. i got 890/1000 on the test.

R
Rose
7/24/2023 2:16:00 PM

this is nice.

A
anon
10/15/2023 12:21:00 PM

q55- the ridac workflow can be modified using flow designer, correct answer is d not a

AI Tutor 👋 I’m here to help!