โ† All ISO 27000 Foundation Certification Flashcard Decks

Risk Assessment and Treatment Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment and Treatment flashcards as text
  1. Which term describes the combination of the likelihood of a threat exploiting a vulnerability and the resulting impact on the organization?

    Answer: Risk

    Risk is defined as the combination of the probability of a threat event occurring and the magnitude of its impact.

  2. In ISO 27005, which step directly follows risk identification in the risk assessment process?

    Answer: Risk estimation

    Risk estimation follows risk identification and involves assigning values to the likelihood and impact of identified risks.

  3. An organization decides to purchase cyber insurance to handle a particular information security risk. Which risk treatment option does this represent?

    Answer: Risk sharing

    Transferring risk via insurance is an example of risk sharing, where the financial consequence is distributed to another party.

  4. What is the PRIMARY purpose of establishing a risk acceptance criteria in an ISMS?

    Answer: To define the level of risk the organization is willing to tolerate

    Risk acceptance criteria set the threshold above which risks require treatment and below which residual risks may be accepted.

  5. Which of the following BEST describes a qualitative risk assessment approach?

    Answer: Uses descriptive scales such as high, medium, and low to rate likelihood and impact

    Qualitative risk assessment uses subjective descriptive scales rather than precise numerical calculations.

  6. When a risk owner accepts a residual risk after controls are applied, what document typically formalizes this decision?

    Answer: Risk acceptance record

    A risk acceptance record formally documents that the risk owner has reviewed and accepted the residual risk.

  7. Which factor is considered when estimating the likelihood of a threat in an ISO 27005 risk assessment?

    Answer: The motivation and capability of potential threat agents

    Likelihood estimation considers threat agent attributes such as motivation, capability, and the opportunity presented by existing vulnerabilities.