โ† All ISO 27000 Foundation Certification Flashcard Decks

Risk Assessment and Treatment Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment and Treatment flashcards as text
  1. What is the role of the Statement of Applicability (SoA) in relation to risk treatment?

    Answer: It documents which Annex A controls are applicable and justifies inclusions or exclusions

    The SoA maps the selected controls to identified risks and justifies why each Annex A control is included or excluded.

  2. An organization implements multi-factor authentication to reduce the risk of unauthorized access. This is an example of which type of control?

    Answer: Preventive control

    Multi-factor authentication prevents unauthorized access from occurring, making it a preventive control.

  3. Which of the following BEST describes risk evaluation in the ISO 27005 process?

    Answer: Comparing estimated risk levels against risk criteria to prioritize treatment

    Risk evaluation involves comparing risk estimates against acceptance criteria to determine which risks require treatment and in what order.

  4. A company keeps a small amount of sensitive data on an unencrypted laptop and decides the cost of a breach is acceptable given the low probability. This decision represents:

    Answer: Risk retention

    Knowingly accepting a risk without applying additional controls, because the expected impact is acceptable, is risk retention.

  5. Which of the following is TRUE about the relationship between assets, threats, and vulnerabilities in risk assessment?

    Answer: Risk arises when a threat exploits a vulnerability affecting an asset

    Risk materializes when a threat agent exploits a vulnerability to cause harm to an asset, combining all three elements.

  6. How often does ISO/IEC 27001 require organizations to perform information security risk assessments?

    Answer: At planned intervals and when significant changes occur

    ISO/IEC 27001 requires risk assessments at planned intervals and whenever significant changes arise that may affect information security.

  7. Which quantitative measure expresses the expected monetary loss from a specific threat occurring once?

    Answer: Single Loss Expectancy (SLE)

    Single Loss Expectancy (SLE) represents the monetary loss expected each time a specific threat event occurs.