Font size
WorksheetsISMS Assessment
Total questions: 20
Worksheet time: 17mins
Your organization has noticed an increase in phishing attacks. What is the most effective initial response?
Block all emails from external sources.
Conduct security awareness and phishing training for employees.
Purchase a new anti-phishing tool.
Restrict access to email for most employees.
A critical software used by your organization is reaching end-of-life. What should you do?
Keep using it while restricting access.
Negotiate with the vendor for extended support.
Immediately replace it with an alternative.
Plan a migration to supported software.
Following a data breach, what is the first action the company should take?
Revise the incident response plan.
Conduct a post-incident review.
Penalize responsible employees.
Immediately notify customers.
What is the first step in implementing an ISMS in a small company?
Buy cybersecurity tools.
Define the ISMS scope and objectives.
Start employee training on cybersecurity.
Hire a security team.
Sensitive data was accessed by an unauthorized department. What do you do first?
Restrict access and review controls.
Delete the data.
Ignore, since it was internal.
Report to law enforcement.
During a risk assessment, it's discovered that a critical piece of software used by the organization is nearing end-of-life and will no longer receive security updates. What is the BEST course of action?
Continue using the software while restricting access to it.
Seek an extension of support from the software vendor.
Immediately switch to an alternative without a risk analysis.
Plan and execute a migration to a supported software solution.
An employee loses a company-issued laptop containing unencrypted personally identifiable information (PII) of clients. Which of the following actions should be taken FIRST?
Assess the impact of the lost data and determine the breach's severity.
Ignore the incident if the laptop is password protected.
Immediately inform all clients about the potential data breach.
Suspend the responsible employee.
After a recent software update, a critical vulnerability was discovered in an organization’s public-facing web application. What should be the FIRST response?
Temporarily take the affected system offline until a fix is applied.
Inform all customers about the vulnerability.
Wait for the next scheduled update to address the vulnerability.
Publicly disclose the vulnerability to ensure community awareness.
After a recent software update, a critical vulnerability was discovered in an organization’s public-facing web application. What should be the FIRST response?
Temporarily take the affected system offline until a fix is applied.
Inform all customers about the vulnerability.
Wait for the next scheduled update to address the vulnerability.
Publicly disclose the vulnerability to ensure community awareness.
An organization is considering migrating its data storage to a cloud service provider. Which of the following considerations is MOST critical from an ISMS perspective?
The cost-effectiveness of the cloud service provider.
The physical location of the cloud service provider's data centers.
The compatibility of the cloud service with the organization's current IT infrastructure.
The cloud service provider's compliance with relevant information security standards and regulations.
A company wants to ensure that its new remote work policy does not introduce additional risks to its information security. Which of the following should be the PRIMARY focus?
Ensuring all employees have high-speed internet access at home.
Implementing strict access controls and secure VPN connections for remote access.
Requiring employees to work from the office at least twice a week.
Purchasing cybersecurity insurance.
An employee loses a laptop with unencrypted PII. What's the first action?
Assess the impact and severity of the breach.
If the laptop is password-protected, do nothing.
Immediately inform all clients.
Suspend the employee.
A vulnerability is found in your web app after an update. First step?
Take the system offline until fixed.
Inform all customers.
Wait for the next update to fix it.
Publicly disclose the vulnerability.
Before moving data storage to the cloud, what's most critical?
Cost of the cloud service.
Location of data centers.
Compatibility with current IT infrastructure.
Compliance with security standards by the provider.
To secure remote work, what should be prioritized?
Ensuring high-speed internet for employees.
Implementing secure access controls and VPNs.
Mandating office work twice a week.
Buying cybersecurity insurance.
Explain the process for conducting a risk assessment for a new cloud-based storage solution.
How would you respond to a significant security breach involving loss of customer data? Include both immediate actions and long-term preventative measures.
An (a) is any asset, system, device, or network component that can be exploited by a threat to gain unauthorized access to information or disrupt IT operations.
The ISO/IEC (a) is the standard that outlines the specifications for an Information Security Management System (ISMS).
In the context of ISMS, the principle of 'least privilege' means ensuring individuals have only the access necessary to perform their job functions, minimizing the potential for (a) access.
