wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

ISO 27001 Quizz Section 456 (Day#2B)

Total questions: 20

Worksheet time: 15mins

Name
Class
Date
1.

What is an asset?

a)

Anything that has value to the organization and that, therefore, requires protection

b)

Anything that the organization has developed or purchased

c)

Hardware that the organization has developed or purchased

2.

What type of assets are information or processes of value for an organization?

a)

Primary/business assets

b)

Secondary assets

c)

Tertiary assets

3.

Which of the following is an example of risk avoidance?

a)

Cancellation or modification of an activity or set of activities related to risk

b)

Cancellation or modification of the residual risk

c)

Cancellation or modification of the risk acceptance criteria

4.

What is the main objective of the monitoring and review phase of the risk management process?

a)

To assist interaction with stakeholders, including those with responsibility and accountability for risk management activities

b)

To assure and improve the quality and effectiveness of process design, implementation, and outcomes

c)

To communicate risk management activities and outcomes across the organization

5.

What is the purpose of risk evaluation?

a)

To support decisions that an organization needs to take

b)

To create an organizational policy

c)

To determine the threat actors

6.

What should be considered when selecting a risk assessment methodology?

a)

The identified threats and vulnerabilities

b)

The risk management framework established by ISO 31000

c)

The evaluation criteria established by ISO/IEC 27001:2022

7.

What does risk retention refer to?

a)

Decision to accept the actual level of risk

b)

Decision to share risks with external parties

c)

Decision to accept the inherent risks

8.

What is residual risk?

a)

Risk that the organization cannot avoid

b)

Risk remaining after the treatment of risk

c)

Risk that is unknown to the organization

9.

What is the main objective of an ISMS training program?

a)

To inform the interested parties about information security

b)

To promote the importance of information security within an organization

c)

To enable individuals to acquire general and specific skills related to the implementation of an ISMS.

10.

An employee has received an email with a link that, when clicked, redirects to a malicious website. The IT manager identifies the issue and immediately blocks the email forward system. What action should the organization take to prevent similar situations from recurring?

a)

Conduct an awareness program to address social engineering and risks associated with emails

b)

Conduct a training program to inform the employees about the risks associated with phishing and spams

c)

Conduct an awareness program to address problems related to access control

11.

What information aspect can transparency compromise in an efficient communication strategy, if not done properly?

a)

Ambiguity

b)

Confidentiality

c)

Accuracy

12.

What should an organization do in order to comply with ISO/IEC 27001:2022?

a)

Develop a procedure for the control of the documented information

b)

Develop a form for the control of the documented information that is visible only to the top management

c)

Develop a guideline for the control of the documented information only when requested by an executive

13.

In order to comply with ISO/IEC 27001:2022, organizations should fulfill some mandatory requirements

on how to document controls.

a)

True

b)

False

14.

Disaster recovery (DR) defines the dangers that threaten an organization

and protects the interests of various interested parties.

a)

True

b)

False

15.

What is performance evaluation?

a)

Process of determining the status of a system, process, or activity

b)

Process of determining measurable results

c)

Process of determining a value

16.

An organization has decided to move its information-processing facilities to a place where the risk of flooding is low. What option of risk treatment is this?

a)

Risk avoidance

b)

Risk evaluation

c)

Risk sharing

17.

Internal audits include audits known as second and third party audits.

a)

True

b)

False

18.

What does “SMART” stand for?

a)

Sophisticated, Measurable, Adversary, Realistic, and Timely

b)

Specific, Measurable, Attainable, Realistic, and Timely

c)

Specialized, Maintainable, Attainable, Realistic, and Timely

19.

A non-conformity report should NOT be _______________.

a)

Ambiguous

b)

Explicit

c)

Correct

20.

What is accomplished when the implemented management system fulfills the organization’s needs?

a)

Suitability

b)

Effectiveness

c)

Adequacy