PCIRM Sample Questions & Answers
Identifying information assets and threats ties with analyzing and evaluating risk for the biggest share, ahead of risk treatment options, establishing a risk programme, foundational concepts and standards, monitoring and review, and presenting a business case.
Launch the full PCIRM simulator →Showing 4 of 8 free samples.
- Question 1Beginner
Information Risk Management Fundamentals · Fundamentals of information security
True or False: The concept of 'non-repudiation' within information security ensures that a system remains operational and accessible to authorised users even during a disruptive event.
Show answer & explanation
Correct answer: B
False. The scenario describes 'Availability' or 'Resilience'. Non-repudiation is the assurance that someone cannot deny the validity of something (e.g., denying that they sent a specific message or executed a specific transaction).
- Question 2Advanced
Information Risk Management Fundamentals · IRM standards and good practice guides
An enterprise risk manager is looking to align the organisation's specific information security risk management processes with its broader, enterprise-wide risk management framework. Which combination of ISO standards should the practitioner use to ensure seamless integration between the specific IT risks and the overarching corporate risk governance?
Show answer & explanation
Correct answer: A
ISO 31000 provides the overarching guidelines for enterprise-wide risk management applicable to any type of risk. ISO 27005 provides specific guidelines for information security risk management. Using them together ensures that information security risks are managed in a way that aligns perfectly with corporate risk governance.
- Question 3IntermediateSelect 2
Information Risk Management Fundamentals · IRM standards and good practice guides
A UK-based healthcare provider is establishing a new platform to share anonymised patient research data with universities across the European Union. Which TWO of the following legal and regulatory instruments are MOST critical to consider during the information risk assessment for this platform? (Select TWO)
Show answer & explanation
Correct answers: B, D
The General Data Protection Regulation (GDPR) and the Data Protection Act 2018 are the critical legal instruments here. They govern the processing, anonymisation, and cross-border transfer of personal healthcare data. The Official Secrets Act applies to state secrets, and PCI DSS applies to payment card data.
The Data Protection Act 2018 (UK's implementation of GDPR) and the General Data Protection Regulation (GDPR) are the critical legal instruments here. They govern the processing, anonymisation, and cross-border transfer of personal healthcare data. The Official Secrets Act applies to state secrets, and PCI DSS applies to payment card data.
- Question 4Intermediate
Information Risk Management Fundamentals · Process of information risk management
During the establishment of an information risk management process, a dispute arises between the Head of HR and the Chief Information Security Officer (CISO). The Head of HR claims that because IT manages the servers, the CISO is the 'Risk Owner' for a newly identified risk regarding unauthorised access to employee payroll records. According to IRM best practices, who should be the Risk Owner in this scenario?
Show answer & explanation
Correct answer: D
The Risk Owner is the person or entity with the accountability and authority to manage a risk. Because the Head of HR owns the business process (payroll) and would bear the business impact of a compromise, they are the Risk Owner. IT/Security acts as a custodian implementing controls on their behalf.
Ready for the real thing?
The full PCIRM simulator has every exam-style question, timed mode, and instant scoring.