ISO 27000 Foundation Certification Information Security Risk Management 2 — Questions and Answers
Question 1: Which ISO/IEC 27005 process step involves determining the consequences of a risk materializing?
- Risk evaluation
- Risk identification
- Risk estimation (Correct answer)
- Risk treatment
Correct answer: Risk estimation
Risk estimation involves determining the likelihood and consequences (impact) of a risk to produce a level of risk.
Question 2: An organization decides to purchase cyber-insurance to address a specific information security risk. Which risk treatment option does this represent?
- Risk avoidance
- Risk modification
- Risk sharing (Correct answer)
- Risk retention
Correct answer: Risk sharing
Risk sharing (also called risk transfer) involves distributing the financial burden of a risk to a third party such as an insurer.
Question 3: In the context of ISO 27001, what is the PRIMARY purpose of a Statement of Applicability (SoA)?
- To list all identified risks and their owners
- To document which Annex A controls are applicable and their justification (Correct answer)
- To record residual risk acceptance decisions
- To define the risk appetite of the organization
Correct answer: To document which Annex A controls are applicable and their justification
The SoA documents which of the ISO 27001 Annex A controls have been selected or excluded and the reasons why.
Question 4: What distinguishes a 'vulnerability' from a 'threat' in information security risk terminology?
- A vulnerability is an external actor; a threat is an internal weakness
- A threat is a potential cause of harm; a vulnerability is a weakness that can be exploited by a threat (Correct answer)
- A vulnerability causes impact; a threat reduces likelihood
- There is no distinction — the terms are interchangeable in ISO 27000
Correct answer: A threat is a potential cause of harm; a vulnerability is a weakness that can be exploited by a threat
ISO 27000 defines a threat as a potential cause of an unwanted incident, while a vulnerability is a weakness that may be exploited by one or more threats.
Question 5: Which term describes the risk that remains after risk treatment controls have been applied?
- Inherent risk
- Residual risk (Correct answer)
- Transferred risk
- Accepted risk
Correct answer: Residual risk
Residual risk is the level of risk remaining after controls and other risk treatment measures have been implemented.
Question 6: Who is ultimately accountable for approving the organization's information security risk treatment plan according to ISO 27001?
- The IT Security Manager
- The external auditor
- Top management (Correct answer)
- The risk assessment team
Correct answer: Top management
ISO 27001 requires top management to approve the risk treatment plan and accept residual risks.
Question 7: A company stops offering an online service because the associated data-breach risk is too high. Which risk treatment option has been applied?
- Risk retention
- Risk modification
- Risk avoidance (Correct answer)
- Risk sharing
Correct answer: Risk avoidance
Risk avoidance involves deciding not to start or continue an activity that gives rise to the risk.
Which ISO/IEC 27005 process step involves determining the consequences of a risk materializing?