ISO 27000 Foundation Certification Information Security Risk Management 4 — Questions and Answers
Question 1: In ISO 27000 terminology, which term refers to the combination of the probability of an event and its consequence?
- Vulnerability
- Threat
- Risk (Correct answer)
- Control
Correct answer: Risk
Risk is defined as the effect of uncertainty on objectives, typically expressed as the combination of likelihood and impact.
Question 2: An organization scores each risk by multiplying a likelihood score (1–5) by an impact score (1–5). This approach is an example of which assessment method?
- Purely qualitative assessment
- Semi-quantitative assessment (Correct answer)
- Fully quantitative assessment
- Delphi technique
Correct answer: Semi-quantitative assessment
Semi-quantitative assessment uses numerical scales (like 1–5) that are ordinal rather than true monetary values, combining elements of both qualitative and quantitative approaches.
Question 3: Which process ensures that the ISMS risk treatment remains effective as the organization's environment changes over time?
- Risk identification
- Risk acceptance
- Risk monitoring and review (Correct answer)
- Risk communication
Correct answer: Risk monitoring and review
Risk monitoring and review is an ongoing process that verifies whether risk treatment measures remain effective and whether new risks have emerged.
Question 4: Under ISO 27001, which document formally records top management's decision to accept residual risks?
- The risk register
- The Statement of Applicability
- The risk treatment plan
- Signed risk acceptance records (Correct answer)
Correct answer: Signed risk acceptance records
Formal records of risk acceptance decisions must be maintained and are typically documented as signed acceptance statements by authorized risk owners.
Question 5: The Annual Loss Expectancy (ALE) calculation is associated with which type of risk assessment methodology?
- Qualitative
- Semi-quantitative
- Quantitative (Correct answer)
- Scenario-based
Correct answer: Quantitative
ALE (Single Loss Expectancy × Annual Rate of Occurrence) is a quantitative method that expresses risk in monetary terms.
Question 6: Which of the following is an example of a PREVENTIVE control in information security risk management?
- Security incident logs
- Intrusion detection alerts
- Access control policies (Correct answer)
- Forensic investigation procedures
Correct answer: Access control policies
Preventive controls, like access control policies, are designed to stop security incidents from occurring in the first place.
Question 7: According to ISO 27005, risk context establishment should include defining which of the following?
- The specific CVEs applicable to the organization's software
- The organization's basic criteria, scope, and boundaries for risk management (Correct answer)
- The names and contact details of all risk owners
- The annual IT security budget
Correct answer: The organization's basic criteria, scope, and boundaries for risk management
Establishing context defines the scope, boundaries, and criteria that will guide the entire risk management process.
In ISO 27000 terminology, which term refers to the combination of the probability of an event and its consequence?