ISO 27000 Foundation Certification Risk Assessment and Treatment 2 — Questions and Answers
Question 1: Which term describes the combination of the likelihood of a threat exploiting a vulnerability and the resulting impact on the organization?
- Vulnerability
- Risk (Correct answer)
- Control
- Asset value
Correct answer: Risk
Risk is defined as the combination of the probability of a threat event occurring and the magnitude of its impact.
Question 2: In ISO 27005, which step directly follows risk identification in the risk assessment process?
- Risk treatment
- Risk evaluation
- Risk estimation (Correct answer)
- Risk acceptance
Correct answer: Risk estimation
Risk estimation follows risk identification and involves assigning values to the likelihood and impact of identified risks.
Question 3: An organization decides to purchase cyber insurance to handle a particular information security risk. Which risk treatment option does this represent?
- Risk avoidance
- Risk modification
- Risk retention
- Risk sharing (Correct answer)
Correct answer: Risk sharing
Transferring risk via insurance is an example of risk sharing, where the financial consequence is distributed to another party.
Question 4: What is the PRIMARY purpose of establishing a risk acceptance criteria in an ISMS?
- To eliminate all risks before treatment
- To define the level of risk the organization is willing to tolerate (Correct answer)
- To identify new vulnerabilities in systems
- To document past security incidents
Correct answer: To define the level of risk the organization is willing to tolerate
Risk acceptance criteria set the threshold above which risks require treatment and below which residual risks may be accepted.
Question 5: Which of the following BEST describes a qualitative risk assessment approach?
- Assigns monetary values to assets and computes expected annual loss
- Uses descriptive scales such as high, medium, and low to rate likelihood and impact (Correct answer)
- Calculates exact probabilities using historical incident data
- Automates risk scoring through a SIEM platform
Correct answer: Uses descriptive scales such as high, medium, and low to rate likelihood and impact
Qualitative risk assessment uses subjective descriptive scales rather than precise numerical calculations.
Question 6: When a risk owner accepts a residual risk after controls are applied, what document typically formalizes this decision?
- Statement of Applicability
- Risk treatment plan
- Risk acceptance record (Correct answer)
- Business continuity plan
Correct answer: Risk acceptance record
A risk acceptance record formally documents that the risk owner has reviewed and accepted the residual risk.
Question 7: Which factor is considered when estimating the likelihood of a threat in an ISO 27005 risk assessment?
- The replacement cost of hardware assets
- The motivation and capability of potential threat agents (Correct answer)
- The number of employees in the IT department
- The organization's annual revenue
Correct answer: The motivation and capability of potential threat agents
Likelihood estimation considers threat agent attributes such as motivation, capability, and the opportunity presented by existing vulnerabilities.
Which term describes the combination of the likelihood of a threat exploiting a vulnerability and the resulting impact on the organization?