ISO 27000 Foundation Certification Risk Assessment and Treatment 4 — Questions and Answers
Question 1: What is the role of the Statement of Applicability (SoA) in relation to risk treatment?
- It lists all threats identified during risk assessment
- It documents which Annex A controls are applicable and justifies inclusions or exclusions (Correct answer)
- It records the financial cost of each risk
- It describes the organization's business continuity procedures
Correct answer: It documents which Annex A controls are applicable and justifies inclusions or exclusions
The SoA maps the selected controls to identified risks and justifies why each Annex A control is included or excluded.
Question 2: An organization implements multi-factor authentication to reduce the risk of unauthorized access. This is an example of which type of control?
- Corrective control
- Detective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Multi-factor authentication prevents unauthorized access from occurring, making it a preventive control.
Question 3: Which of the following BEST describes risk evaluation in the ISO 27005 process?
- Identifying all assets and their owners
- Comparing estimated risk levels against risk criteria to prioritize treatment (Correct answer)
- Implementing security controls to reduce risk
- Documenting residual risks in an acceptance form
Correct answer: Comparing estimated risk levels against risk criteria to prioritize treatment
Risk evaluation involves comparing risk estimates against acceptance criteria to determine which risks require treatment and in what order.
Question 4: A company keeps a small amount of sensitive data on an unencrypted laptop and decides the cost of a breach is acceptable given the low probability. This decision represents:
- Risk modification
- Risk avoidance
- Risk retention (Correct answer)
- Risk sharing
Correct answer: Risk retention
Knowingly accepting a risk without applying additional controls, because the expected impact is acceptable, is risk retention.
Question 5: Which of the following is TRUE about the relationship between assets, threats, and vulnerabilities in risk assessment?
- A threat can only target one type of asset
- A vulnerability alone constitutes a risk
- Risk arises when a threat exploits a vulnerability affecting an asset (Correct answer)
- Assets must be quantified in monetary terms for risk assessment
Correct answer: Risk arises when a threat exploits a vulnerability affecting an asset
Risk materializes when a threat agent exploits a vulnerability to cause harm to an asset, combining all three elements.
Question 6: How often does ISO/IEC 27001 require organizations to perform information security risk assessments?
- Only once during ISMS implementation
- At planned intervals and when significant changes occur (Correct answer)
- Every five years as mandated by the standard
- Only after a security incident has been recorded
Correct answer: At planned intervals and when significant changes occur
ISO/IEC 27001 requires risk assessments at planned intervals and whenever significant changes arise that may affect information security.
Question 7: Which quantitative measure expresses the expected monetary loss from a specific threat occurring once?
- Annualized Loss Expectancy (ALE)
- Single Loss Expectancy (SLE) (Correct answer)
- Annualized Rate of Occurrence (ARO)
- Exposure Factor (EF)
Correct answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) represents the monetary loss expected each time a specific threat event occurs.
What is the role of the Statement of Applicability (SoA) in relation to risk treatment?