โ† All ISO 27000 Foundation Certification Flashcard Decks

Risk Assessment and Treatment Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Assessment and Treatment flashcards as text
  1. When selecting risk treatment options, which ISO/IEC 27001 principle requires that control costs should be proportionate to the risks they address?

    Answer: Cost-benefit analysis

    ISO/IEC 27001 encourages cost-benefit analysis to ensure that the cost of implementing a control does not exceed the value of the risk being mitigated.

  2. An organization uses a heat map with color-coded cells to communicate risk severity to senior management. What type of tool is this?

    Answer: Risk matrix

    A risk matrix (or heat map) plots likelihood against impact using a color-coded grid to visually communicate risk severity levels.

  3. Which of the following scenarios BEST illustrates the risk treatment option of risk modification?

    Answer: Installing a firewall to reduce the likelihood of unauthorized network access

    Installing a firewall modifies (reduces) the risk by lowering the likelihood of a threat exploiting a vulnerability.

  4. What is the PRIMARY input to the risk treatment process in an ISMS?

    Answer: The results of the risk assessment

    The risk assessment output, including prioritized risks and their levels, is the primary input used to determine appropriate treatment options.

  5. In ISO/IEC 27001, which party must formally approve the risk treatment plan and accept residual risks?

    Answer: Risk owners

    Risk owners are responsible for approving the treatment plan for risks within their scope and formally accepting any residual risk.

  6. A threat agent has high motivation but lacks the technical skills to exploit a complex vulnerability. How does this affect the likelihood score?

    Answer: Likelihood decreases because capability is insufficient to exploit the vulnerability

    Likelihood depends on both motivation and capability; without sufficient technical capability, the threat agent is unlikely to successfully exploit the vulnerability.

  7. Which of the following is NOT typically a component recorded in a risk register?

    Answer: Employee performance appraisal scores

    Employee performance appraisals are an HR function and are not relevant entries in an information security risk register.