
ISO 27001 FOUNDATION EN D2 - EX 5
Other
Professional Development
Used 149+ times

AI Actions
Add similar questions
Adjust reading levels
Convert to real-world scenario
Translate activity
More...
Content View
Student View
10 questions
Show all answers
1.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
What is an information security policy?
A. A document presenting results to be achieved in information security
B. Intentions and direction of an organization about information security, as formally expressed by its top management
C. A high level document that affects the whole organization and defines security roles and responsibilities
D. A set of information security procedures that work together to address risks
2.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
When designing a backup plan, what following item should NOT be taken into consideration?
1
2
3
4
3.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Risk assessment consists of the following activities:
A. Identification, Evaluation, Analysis, Treatment
B. Identification, Analysis, Evaluation
C. Identification, Response, Evaluation
D. Identification, Analysis, Evaluation, Treatment
4.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
For what MAIN reason should risk communication be carried out?
A. To provide assurance of the outcome of the organization’s risk management
B. To obtain new information security knowledge
C. To address risk owners’ security concerns
D. To ensure that residual risks are explicitly accepted by top management
5.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
Choose the BEST explanation about the difference between consequence and impact
A. A consequence extent of damage to the organization’s objectives resulting from a risk while an impact is an adverse change to the level of business objectives achieved. Both are mainly negative
B. A consequence is the outcome of an event affecting objectives while an impact is an adverse change to the level of business objectives achieved. Both are usually negative
C. A consequence is an adverse change to the level of business objectives achieved and is mainly negative while an impact is the outcome of an event affecting objectives and can be as positive as negative
D. A consequence is the extent of damage to the organization’s objectives resulting from a risk while an impact is an adverse change to the level of business objectives achieved. Both can be positive or negative
6.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
In what type of document would the statement “maintaining a chain of custody for information while in transit” be the MOST relevant?
A. Email policy
B. Network topology
C. Network access policy
D. Information transfer agreement
7.
MULTIPLE CHOICE QUESTION
1 min • 1 pt
When is it better to put several physical barriers around the organization’s premises?
A. Always
B. When the related area contains either sensitive or critical information and information processing facilities
C. When the related area contains sensitive information and information processing facilities
D. When the related area contains critical information and information processing facilities
Access all questions and much more by creating a free account
Create resources
Host any resource
Get auto-graded reports

Continue with Google

Continue with Email

Continue with Classlink

Continue with Clever
or continue with

Microsoft
%20(1).png)
Apple
Others
Already have an account?