Search Header Logo

ISO 27001 FOUNDATION EN D2 - EX 5

Other

Professional Development

Used 149+ times

ISO 27001 FOUNDATION EN D2 - EX 5
AI

AI Actions

Add similar questions

Adjust reading levels

Convert to real-world scenario

Translate activity

More...

    Content View

    Student View

10 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

What is an information security policy?

A. A document presenting results to be achieved in information security

B. Intentions and direction of an organization about information security, as formally expressed by its top management

C. A high level document that affects the whole organization and defines security roles and responsibilities

D. A set of information security procedures that work together to address risks

2.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

When designing a backup plan, what following item should NOT be taken into consideration?

1

2

3

4

3.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

Risk assessment consists of the following activities:

A. Identification, Evaluation, Analysis, Treatment

B. Identification, Analysis, Evaluation

C. Identification, Response, Evaluation

D. Identification, Analysis, Evaluation, Treatment

4.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

For what MAIN reason should risk communication be carried out?

A. To provide assurance of the outcome of the organization’s risk management

B. To obtain new information security knowledge

C. To address risk owners’ security concerns

D. To ensure that residual risks are explicitly accepted by top management

5.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

Choose the BEST explanation about the difference between consequence and impact

A. A consequence extent of damage to the organization’s objectives resulting from a risk while an impact is an adverse change to the level of business objectives achieved. Both are mainly negative

B. A consequence is the outcome of an event affecting objectives while an impact is an adverse change to the level of business objectives achieved. Both are usually negative

C. A consequence is an adverse change to the level of business objectives achieved and is mainly negative while an impact is the outcome of an event affecting objectives and can be as positive as negative

D. A consequence is the extent of damage to the organization’s objectives resulting from a risk while an impact is an adverse change to the level of business objectives achieved. Both can be positive or negative

6.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

In what type of document would the statement “maintaining a chain of custody for information while in transit” be the MOST relevant?

A. Email policy

B. Network topology

C. Network access policy

D. Information transfer agreement

7.

MULTIPLE CHOICE QUESTION

1 min • 1 pt

When is it better to put several physical barriers around the organization’s premises?

A. Always

B. When the related area contains either sensitive or critical information and information processing facilities

C. When the related area contains sensitive information and information processing facilities

D. When the related area contains critical information and information processing facilities

Access all questions and much more by creating a free account

Create resources

Host any resource

Get auto-graded reports

Google

Continue with Google

Email

Continue with Email

Classlink

Continue with Classlink

Clever

Continue with Clever

or continue with

Microsoft

Microsoft

Apple

Apple

Others

Others

Already have an account?