NEW
Font size
WorksheetsISO 27001 Quizz Section 456 (Day#2B)
Total questions: 20
Worksheet time: 15mins
What is an asset?
Anything that has value to the organization and that, therefore, requires protection
Anything that the organization has developed or purchased
Hardware that the organization has developed or purchased
What type of assets are information or processes of value for an organization?
Primary/business assets
Secondary assets
Tertiary assets
Which of the following is an example of risk avoidance?
Cancellation or modification of an activity or set of activities related to risk
Cancellation or modification of the residual risk
Cancellation or modification of the risk acceptance criteria
What is the main objective of the monitoring and review phase of the risk management process?
To assist interaction with stakeholders, including those with responsibility and accountability for risk management activities
To assure and improve the quality and effectiveness of process design, implementation, and outcomes
To communicate risk management activities and outcomes across the organization
What is the purpose of risk evaluation?
To support decisions that an organization needs to take
To create an organizational policy
To determine the threat actors
What should be considered when selecting a risk assessment methodology?
The identified threats and vulnerabilities
The risk management framework established by ISO 31000
The evaluation criteria established by ISO/IEC 27001:2022
What does risk retention refer to?
Decision to accept the actual level of risk
Decision to share risks with external parties
Decision to accept the inherent risks
What is residual risk?
Risk that the organization cannot avoid
Risk remaining after the treatment of risk
Risk that is unknown to the organization
What is the main objective of an ISMS training program?
To inform the interested parties about information security
To promote the importance of information security within an organization
To enable individuals to acquire general and specific skills related to the implementation of an ISMS.
An employee has received an email with a link that, when clicked, redirects to a malicious website. The IT manager identifies the issue and immediately blocks the email forward system. What action should the organization take to prevent similar situations from recurring?
Conduct an awareness program to address social engineering and risks associated with emails
Conduct a training program to inform the employees about the risks associated with phishing and spams
Conduct an awareness program to address problems related to access control
What information aspect can transparency compromise in an efficient communication strategy, if not done properly?
Ambiguity
Confidentiality
Accuracy
What should an organization do in order to comply with ISO/IEC 27001:2022?
Develop a procedure for the control of the documented information
Develop a form for the control of the documented information that is visible only to the top management
Develop a guideline for the control of the documented information only when requested by an executive
In order to comply with ISO/IEC 27001:2022, organizations should fulfill some mandatory requirements
on how to document controls.
True
False
Disaster recovery (DR) defines the dangers that threaten an organization
and protects the interests of various interested parties.
True
False
What is performance evaluation?
Process of determining the status of a system, process, or activity
Process of determining measurable results
Process of determining a value
An organization has decided to move its information-processing facilities to a place where the risk of flooding is low. What option of risk treatment is this?
Risk avoidance
Risk evaluation
Risk sharing
Internal audits include audits known as second and third party audits.
True
False
What does “SMART” stand for?
Sophisticated, Measurable, Adversary, Realistic, and Timely
Specific, Measurable, Attainable, Realistic, and Timely
Specialized, Maintainable, Attainable, Realistic, and Timely
A non-conformity report should NOT be _______________.
Ambiguous
Explicit
Correct
What is accomplished when the implemented management system fulfills the organization’s needs?
Suitability
Effectiveness
Adequacy
