Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.

Exam ISO-IEC-27001-Lead-Auditor Topic 1 Question 147 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 147
Topic #: 1
Question:
Which of the following statements regarding threats and vulnerabilities in information security is NOT correct?

Suggested Answer: C Vote an answer

Comprehensive and Detailed In-Depth Explanation:
* C. Incorrect Statement - Not all vulnerabilities require immediate remediation. Risk assessment determines whether controls are necessary. Some vulnerabilities pose low risks and may not need urgent fixes.
* A. Correct Statement - Vulnerabilities can be intrinsic (inherent flaws) or extrinsic (caused by external misconfigurations).
* B. Correct Statement - Threats must exploit vulnerabilities to cause harm.
This aligns with ISO/IEC 27001:2022 Annex A Control A.8.8 (Management of Technical Vulnerabilities).

by Peter at Feb 18, 2026, 11:00 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.