ISO 27000 Foundation Certification Risk Assessment and Treatment 5 — Questions and Answers
Question 1: When selecting risk treatment options, which ISO/IEC 27001 principle requires that control costs should be proportionate to the risks they address?
- Risk elimination principle
- Cost-benefit analysis (Correct answer)
- Zero-risk tolerance
- Mandatory compliance
Correct answer: Cost-benefit analysis
ISO/IEC 27001 encourages cost-benefit analysis to ensure that the cost of implementing a control does not exceed the value of the risk being mitigated.
Question 2: An organization uses a heat map with color-coded cells to communicate risk severity to senior management. What type of tool is this?
- Quantitative risk model
- Risk register
- Risk matrix (Correct answer)
- Business impact analysis
Correct answer: Risk matrix
A risk matrix (or heat map) plots likelihood against impact using a color-coded grid to visually communicate risk severity levels.
Question 3: Which of the following scenarios BEST illustrates the risk treatment option of risk modification?
- Outsourcing data processing to a cloud provider under a liability agreement
- Accepting that a low-impact risk does not require further action
- Installing a firewall to reduce the likelihood of unauthorized network access (Correct answer)
- Stopping the use of a legacy application entirely
Correct answer: Installing a firewall to reduce the likelihood of unauthorized network access
Installing a firewall modifies (reduces) the risk by lowering the likelihood of a threat exploiting a vulnerability.
Question 4: What is the PRIMARY input to the risk treatment process in an ISMS?
- The organization's annual budget
- The results of the risk assessment (Correct answer)
- Employee satisfaction surveys
- Previous audit findings only
Correct answer: The results of the risk assessment
The risk assessment output, including prioritized risks and their levels, is the primary input used to determine appropriate treatment options.
Question 5: In ISO/IEC 27001, which party must formally approve the risk treatment plan and accept residual risks?
- External certification auditors
- The IT department head
- Risk owners (Correct answer)
- Insurance providers
Correct answer: Risk owners
Risk owners are responsible for approving the treatment plan for risks within their scope and formally accepting any residual risk.
Question 6: A threat agent has high motivation but lacks the technical skills to exploit a complex vulnerability. How does this affect the likelihood score?
- Likelihood increases because motivation is the only factor
- Likelihood decreases because capability is insufficient to exploit the vulnerability (Correct answer)
- Likelihood is unaffected because only vulnerability severity matters
- Likelihood becomes critical because intent alone constitutes a risk
Correct answer: Likelihood decreases because capability is insufficient to exploit the vulnerability
Likelihood depends on both motivation and capability; without sufficient technical capability, the threat agent is unlikely to successfully exploit the vulnerability.
Question 7: Which of the following is NOT typically a component recorded in a risk register?
- Risk description and identifier
- Likelihood and impact ratings
- Employee performance appraisal scores (Correct answer)
- Risk owner and treatment status
Correct answer: Employee performance appraisal scores
Employee performance appraisals are an HR function and are not relevant entries in an information security risk register.
When selecting risk treatment options, which ISO/IEC 27001 principle requires that control costs should be proportionate to the risks they address?