ITPEC FE Morning October 2021 Question 40

Source exam: ITPEC FE Morning October 2021Topic: Security

ITPEC FE Morning October 2021 — Question 40 of 80

Level of Risk (ISO/IEC 27000) — definition from the ISMS vocabulary standard.

Per ISO/IEC 27000:2018, level of risk is the magnitude of a risk expressed as the combination of:
- Consequences — impact if the risk materializes

- Likelihood — probability of occurrence

In short: level of risk = consequences × likelihood

Why not others:
- (b) Risk criteria — terms of reference for evaluating significance

- (c) Risk prioritization — the order in which risks are handled

- (d) Vulnerability — a weakness that can be exploited by threats

Key rule: ISO 27000 risk terms to remember:
- Risk = effect of uncertainty on objectives

- Level of risk = consequences × likelihood

- Risk criteria = benchmarks for evaluating risk significance

- Vulnerability = exploitable weakness

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.