PCIRM BCS Practitioner Certificate in Information Risk Management Practice Questions
Prepare for PCIRM with more than an answer.
- Exam fee
- $290 USD
- Time limit
- 90 minutes
- Passing score
- 39/60 (65%)
- Level
- Practitioner
- Valid for
- No expiry - lifetime certification
Domains covered on the exam 8
- The Concepts and Framework of Information Risk Management5%
- Information Risk Management Fundamentals10%
- Establishing an Information Risk Management Programme12%
- Risk Identification21%
- Risk Assessment21%
- Risk Treatment19%
- Monitor and Review6%
- Presenting Risks and Business Case6%
- 1
An organisation has decided to implement a new Intrusion Prevention System (IPS) to automatically block malicious network traffic before it reaches internal servers. In the context of information risk terms and definitions, how should this control be classified?
Show answer details
Correct answer: C
At a tactical level, an IPS blocking traffic is a Preventative control (it stops the incident from occurring). At an operational level, it is a Technical (or logical) control because it relies on hardware/software mechanisms rather than physical barriers or human procedures.
- 2
A manufacturing enterprise is establishing an Information Security Management System (ISMS) aligned with the Deming Cycle. The organisation has recently completed a comprehensive risk assessment and drafted a risk treatment plan.
According to the PDCA model, what is the NEXT logical phase the organisation must execute, and what primary activity characterises this phase?
flowchart LR P[Plan] --> D[Do] D --> C[Check] C --> A[Act] A --> PShow answer details
Correct answer: D
In the PDCA (Plan-Do-Check-Act) model, establishing the context, conducting the risk assessment, and formulating the risk treatment plan occur in the 'Plan' phase. The immediate next step is the 'Do' phase, where the organisation actually implements the risk treatment plan and operates the chosen controls.
- 3
A regional healthcare trust is overhauling its information risk management strategy. The Chief Information Officer (CIO) insists that risk management should only commence once a new IT system is deployed into the production environment. As an information risk practitioner, how should you address this assertion based on the information lifecycle?
Show answer details
Correct answer: D
Information risk management must be applied throughout the entire information lifecycle—from creation/collection, storage, use, sharing, archiving, to final destruction. Waiting until a system is in production ignores risks during the design, development, and data collection phases, violating the 'secure by design' principle.
- 4
A multinational financial institution is evaluating the potential consequences of not undertaking a formal Information Risk Management (IRM) programme. Which of the following represents the MOST significant long-term business consequence of failing to implement IRM?
Show answer details
Correct answer: D
While all options represent negative outcomes, the most severe and long-term consequence of lacking an IRM programme is the failure to demonstrate due diligence. In regulated industries, this leads to loss of stakeholder confidence, reputational ruin, and massive regulatory penalties (e.g., under GDPR or FCA regulations), which can threaten the organisation's survival.
