ISO 27000 Foundation Certification Information Security Risk Management 3 — Questions and Answers
Question 1: In a qualitative risk assessment, risks are most commonly expressed using which scale?
- Exact monetary values calculated by actuaries
- Descriptive categories such as Low, Medium, and High (Correct answer)
- Binary values: acceptable or unacceptable
- Standard deviation from a statistical baseline
Correct answer: Descriptive categories such as Low, Medium, and High
Qualitative risk assessments use descriptive scales (e.g., Low/Medium/High) rather than precise numerical values.
Question 2: Which of the following best describes the concept of 'risk appetite' in ISO 27000?
- The maximum financial loss an organization can sustain from a breach
- The amount and type of risk an organization is willing to pursue or retain (Correct answer)
- The list of risks that must always be avoided regardless of cost
- The budget allocated annually for information security controls
Correct answer: The amount and type of risk an organization is willing to pursue or retain
Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives.
Question 3: Which asset type is BEST described as 'the reputation and image of the organization'?
- Physical asset
- Software asset
- Intangible asset (Correct answer)
- Human asset
Correct answer: Intangible asset
Reputation and image are intangible assets — they have significant value but no physical form.
Question 4: According to ISO 27005, which input is REQUIRED before conducting a risk assessment?
- A completed penetration test report
- Established risk evaluation criteria (Correct answer)
- A list of previously implemented controls
- Approval from an external regulator
Correct answer: Established risk evaluation criteria
Risk evaluation criteria must be established beforehand so that assessed risk levels can be compared and prioritized consistently.
Question 5: What is the main goal of the risk communication and consultation process in ISO 27005?
- To formally accept all residual risks identified during assessment
- To ensure stakeholders are informed and their input is considered throughout risk management (Correct answer)
- To transfer risk information to an external insurance provider
- To document risk owners for audit purposes
Correct answer: To ensure stakeholders are informed and their input is considered throughout risk management
Risk communication and consultation ensures that stakeholders share information and contribute to risk decisions throughout the process.
Question 6: A threat source that acts without intent or direction, such as a natural disaster, is classified as which type of threat?
- Deliberate
- Accidental
- Environmental (Correct answer)
- Structural
Correct answer: Environmental
Environmental threats are naturally occurring events like floods, earthquakes, or fires that are neither deliberate nor the result of human error.
Question 7: Which of the following scenarios illustrates a risk treatment strategy of 'risk modification'?
- Accepting a low-impact risk without implementing any controls
- Installing a firewall to reduce the likelihood of unauthorized network access (Correct answer)
- Buying liability insurance for a data breach event
- Discontinuing a legacy system that cannot be secured
Correct answer: Installing a firewall to reduce the likelihood of unauthorized network access
Risk modification involves applying controls that change the likelihood or impact of a risk — installing a firewall reduces likelihood.
In a qualitative risk assessment, risks are most commonly expressed using which scale?