All Practice Exams

100+ Free EBIOS Risk Manager Practice Questions

Prepare for the PECB Certified EBIOS Risk Manager exam with instant access — no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free

Loading practice questions...

2026 Statistics

Key Facts: EBIOS Risk Manager Exam

60 items, 3h

Exam Format (57 MCQ + 3 essay)

PECB Candidate Handbook

70%

Passing Score

PECB Standard

Open-book

Exam Type

PECB Candidate Handbook

USD 1000

Exam-Only Fee

PECB Candidate Handbook

5 Workshops

Methodology Structure

ANSSI / PECB

3 years

Credential Validity

PECB Recertification

PECB Certified EBIOS Risk Manager is an open-book, 3-hour exam of 60 items (57 three-option multiple-choice plus 3 essay questions, passing score 70%) covering the ANSSI EBIOS RM methodology across three official competency domains. This practice bank of 100 four-option MCQs is an English-language study adaptation organized by the five workshops (scoping/baseline, risk origins & ecosystem, strategic scenarios, operational scenarios, and risk treatment); it does not reproduce the essay questions. Exam-only price is USD 1000; the exam is included when taking official PECB partner training.

Sample EBIOS Risk Manager Practice Questions

Try these sample questions to test your EBIOS Risk Manager exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1What is the primary purpose of the EBIOS Risk Manager method?
A.To certify that an information system is free of vulnerabilities
B.To help an organization identify, assess, and treat information security risks in a way that is aligned with its business objectives
C.To replace the organization's existing security policy with a standardized national policy
D.To automate penetration testing of the organization's supporting assets
Explanation: EBIOS Risk Manager is a structured risk management method whose goal is to let an organization identify, assess, and treat the digital risks that threaten its business activities, so that security decisions are made in line with its needs and objectives. It is a decision-support approach, not a certification of systems or a technical testing tool.
2Into how many workshops is an EBIOS Risk Manager study structured?
A.Three
B.Four
C.Five
D.Seven
Explanation: An EBIOS RM study is organized into five workshops: (1) scope and security baseline, (2) risk origins, (3) strategic scenarios, (4) operational scenarios, and (5) risk treatment. The workshops follow an iterative logic and are typically run as collaborative face-to-face working sessions.
3Which body publishes the EBIOS Risk Manager method?
A.ISO (International Organization for Standardization)
B.ANSSI (French National Cybersecurity Agency)
C.NIST (National Institute of Standards and Technology)
D.ISACA
Explanation: EBIOS Risk Manager was created and published by ANSSI (Agence nationale de la sécurité des systèmes d'information), the French national cybersecurity agency, with support from the Club EBIOS. PECB offers training and certification based on this official method.
4In the EBIOS RM vocabulary, what is a 'business asset' (bien métier)?
A.A piece of physical IT hardware such as a server or network switch
B.An essential business process, information asset, or capability that is critical to the organization's mission
C.A commercial software license owned by the organization
D.An external third-party supplier contract
Explanation: A business asset (bien métier or primary asset) is a high-level component of the organization's business activity — such as a core process, critical dataset, or operational capability — whose loss or compromise would directly hurt the organization. IT components supporting it are classified separately as supporting assets.
5What is a 'feared event' (événement redouté) in an EBIOS RM study?
A.A technical vulnerability identified in a web application
B.An anticipated breach of security (loss of availability, integrity, or confidentiality) on a business asset that causes business impact
C.The failure of an internal security audit
D.A change in regulatory requirements governing the organization
Explanation: A feared event (ER) represents an unacceptable condition affecting a business asset — for example, unauthorized disclosure of customer records or prolonged unavailability of payment processing — which generates direct or indirect impacts for the organization.
6What does a risk origin/target objective (RO/TO) pair represent in EBIOS RM?
A.A combination of a specific threat actor (risk origin) and the motive or result they seek to achieve (target objective)
B.A pairing of a software bug and a patch release date
C.A list of compliance requirements mapped to security controls
D.An operational incident report paired with its root cause
Explanation: In Workshop 2, EBIOS RM identifies Risk Origins (SR - Sources de risques, e.g. state-sponsored actors, cybercriminals) and pairs them with Targeted Objectives (OV - Objectifs visés, e.g. financial extortion, espionage, disruption). This pairing forms the basis for modeling strategic attack scenarios.
7What does the 'ecosystem' refer to in an EBIOS RM study?
A.The set of software applications hosted on internal servers
B.The network of external partners, suppliers, sub-contractors, and clients interacting with the target system
C.The physical environment surrounding the datacenter, including climate control
D.The internal organizational structure of the cybersecurity department
Explanation: EBIOS RM defines the ecosystem as all external entities (partners, service providers, subcontractors, cloud hosts, clients) that interact with the organization's information system. Workshop 2 analyzes how threat actors might exploit the ecosystem to reach the primary target.
8What distinguishes a strategic scenario from an operational scenario in EBIOS RM?
A.Strategic scenarios focus on high-level attack paths through the ecosystem to business assets, whereas operational scenarios detail technical modes of attack against supporting assets
B.Strategic scenarios are written by IT staff, while operational scenarios are written by executive board members
C.Strategic scenarios only cover natural disasters, while operational scenarios cover cyber attacks
D.Strategic scenarios are quantitative, while operational scenarios are strictly qualitative
Explanation: Strategic scenarios (Workshop 3) illustrate how a risk origin could leverage ecosystem stakeholders to reach primary assets and trigger feared events. Operational scenarios (Workshop 4) drill down into technical attack sequences (modes opératoires) targeting specific supporting assets.
9Which set of options represents the classic risk treatment strategies evaluated in Workshop 5?
A.Ignore, suppress, delay, report
B.Avoid, reduce (mitigate), transfer (share), accept
C.Encrypt, backup, audit, authenticate
D.Monitor, log, isolate, terminate
Explanation: In Workshop 5, risk treatment options follow standard ISO 31000 logic: risk avoidance (modifying activity to eliminate risk), risk reduction/mitigation (implementing controls), risk transfer/sharing (insurance, contracts), and risk acceptance (formal management sign-off of residual risk).
10Why is the EBIOS RM approach described as iterative?
A.Because workshops must be repeated every week indefinitely
B.Because findings in later workshops may require refining assumptions, scopes, or ratings made in earlier workshops
C.Because the software generating the report must loop five times
D.Because it requires hiring iterative software developers to conduct the study
Explanation: EBIOS RM is iterative because risk analysis is progressive. For example, insights gained when detailing operational scenarios in Workshop 4 may reveal new ecosystem dependencies or supporting asset vulnerabilities that prompt adjusting the strategic scenario or security baseline evaluated in earlier workshops.

About the EBIOS Risk Manager Exam

The PECB Certified EBIOS Risk Manager certification validates an individual's competence to conduct, facilitate, and manage information security risk assessments using the EBIOS Risk Manager method developed by ANSSI (the French National Cybersecurity Agency). The official exam is scored across three competency domains (fundamental principles and concepts, the EBIOS-based risk management framework, and risk assessment using EBIOS RM); this practice bank is organized by the method's five workshops for study convenience.

Questions

60 scored questions

Time Limit

3 hours

Passing Score

70%

Exam Fee

USD 1000 exam-only; included in PECB partner training (PECB (Professional Evaluation and Certification Board))

EBIOS Risk Manager Exam Content Outline

~20%

Domain 1: Fundamental Principles and Concepts of Information Security Risk Management

Understand core risk concepts, ANSSI EBIOS RM methodology architecture, alignment with ISO 31000 and ISO/IEC 27005, top-down business asset orientation, and the multidisciplinary workshop facilitation framework.

~20%

Domain 2: Workshop 1 - Scope and Security Baseline

Define study boundaries, identify primary business assets (biens métier) and supporting assets (biens supports), characterize feared events (événements redoutés) across CIA criteria, rate business impact severity, evaluate baseline hygiene compliance, and perform gap analysis.

~20%

Domain 3: Workshop 2 - Risk Origins and Target Ecosystem

Identify intentional Risk Origins (Sources de Risques - SR) and Targeted Objectives (Objectifs Visés - OV), construct SR/OV pairs, map the external ecosystem (partners, suppliers, cloud hosts), rate ecosystem threat exposure levels, and select priority risk origins.

~20%

Domain 4: Workshop 3 - Strategic Scenarios

Model strategic attack paths from Risk Origins through ecosystem relay points to business assets, evaluate scenario severity and likelihood, build the Strategic Risk Matrix, and specify strategic governance security measures.

~20%

Domain 5: Workshop 4 & 5 - Operational Scenarios and Risk Treatment

Detail technical attack modes (modes opératoires) on supporting assets (integrating MITRE ATT&CK / Cyber Kill Chain), evaluate operational feasibility, select risk treatment strategies (avoid, mitigate, transfer, accept), build the Risk Treatment Plan (PTR), and secure Sponsor residual risk acceptance.

How to Pass the EBIOS Risk Manager Exam

What You Need to Know

  • Passing score: 70%
  • Exam length: 60 questions
  • Time limit: 3 hours
  • Exam fee: USD 1000 exam-only; included in PECB partner training

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

EBIOS Risk Manager Study Tips from Top Performers

1Master the distinction between primary business assets (biens métier) and supporting assets (biens supports) — business assets represent organizational value, while supporting assets host the infrastructure
2Memorize the 5 workshop sequence and the specific deliverables produced at the end of each workshop
3Understand the 4-level qualitative scale (1-Faible to 4-Très fort) used for severity, ecosystem exposure, and operational feasibility
4Know how strategic scenarios (high-level ecosystem paths in Workshop 3) connect to operational scenarios (technical attack modes in Workshop 4)
5Study the structure of the Risk Treatment Plan (PTR) in Workshop 5, including Socle (baseline), Stratégique (governance), and Opérationnel (technical) measure tiers
6Tab and organize your PECB training materials for quick reference during the open-book exam

Frequently Asked Questions

What is the format of the PECB EBIOS Risk Manager exam?

The official exam contains 60 items over 3 hours with a 70% passing score: 57 three-option multiple-choice questions plus 3 essay-type questions, spanning three competency domains. It includes both stand-alone and scenario-based questions. It is an open-book exam: candidates may consult a hard copy of the EBIOS RM method, printed PECB training course materials, and personal notes during the test.

How does this practice bank compare to the official exam?

This free question bank provides 100 high-quality practice MCQs organized by the five EBIOS RM workshops. Note the differences: the official exam has 57 three-option multiple-choice questions plus 3 essay questions (60 total), while our bank uses 100 four-option MCQs and does not reproduce the essay questions. Use it to build the underlying method knowledge, then practise structuring written answers separately.

What is the relationship between EBIOS Risk Manager and ANSSI?

EBIOS Risk Manager is the official risk management methodology published by ANSSI (Agence nationale de la sécurité des systèmes d'information), the French national cybersecurity agency. PECB provides training and certification accredited to evaluate candidate competence in applying this official ANSSI method.

How much does the PECB EBIOS Risk Manager exam cost?

The standalone exam fee for PECB Risk Manager level exams is USD 1000. When candidates enroll in an official training course through a PECB authorized partner, the exam attempt, one free retake (within 12 months), certification application fee, and first-year annual maintenance fee are included in the course bundle.

What are the five workshops of EBIOS Risk Manager?

The five workshops are: Workshop 1 (Scope & Security Baseline), Workshop 2 (Risk Origins & Ecosystem), Workshop 3 (Strategic Scenarios), Workshop 4 (Operational Scenarios), and Workshop 5 (Risk Treatment Plan & Residual Risk Acceptance).

What happens if I fail the exam?

There is no limit on total retakes, but you must wait 15 days after a failed attempt before taking the exam again. Candidates who completed training with a PECB authorized partner can take one free retake within 12 months of course completion.