← All ISO 27000 Foundation Certification Flashcard Decks

Information Security Risk Management Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Information Security Risk Management flashcards as text
  1. In a qualitative risk assessment, risks are most commonly expressed using which scale?

    Answer: Descriptive categories such as Low, Medium, and High

    Qualitative risk assessments use descriptive scales (e.g., Low/Medium/High) rather than precise numerical values.

  2. Which of the following best describes the concept of 'risk appetite' in ISO 27000?

    Answer: The amount and type of risk an organization is willing to pursue or retain

    Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives.

  3. Which asset type is BEST described as 'the reputation and image of the organization'?

    Answer: Intangible asset

    Reputation and image are intangible assets — they have significant value but no physical form.

  4. According to ISO 27005, which input is REQUIRED before conducting a risk assessment?

    Answer: Established risk evaluation criteria

    Risk evaluation criteria must be established beforehand so that assessed risk levels can be compared and prioritized consistently.

  5. What is the main goal of the risk communication and consultation process in ISO 27005?

    Answer: To ensure stakeholders are informed and their input is considered throughout risk management

    Risk communication and consultation ensures that stakeholders share information and contribute to risk decisions throughout the process.

  6. A threat source that acts without intent or direction, such as a natural disaster, is classified as which type of threat?

    Answer: Environmental

    Environmental threats are naturally occurring events like floods, earthquakes, or fires that are neither deliberate nor the result of human error.

  7. Which of the following scenarios illustrates a risk treatment strategy of 'risk modification'?

    Answer: Installing a firewall to reduce the likelihood of unauthorized network access

    Risk modification involves applying controls that change the likelihood or impact of a risk — installing a firewall reduces likelihood.