Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Day#2A;Quiz LI Multimatics

Total questions: 15

Worksheet time: 8mins

Name
Class
Date
1.

According to ISO/IEC 27001, who is responsible for establishing the information security policy?

a)

The top management

b)

The ISMS project manager

c)

The information security manager

2.

What is the difference between a policy and a guideline?

a)

A policy states the intentions and direction of an organization, whereas a guideline states how something should be done

b)

A policy is a type of a guideline that provides guidance for different topics

c)

A policy is a document stating how something should be done, whereas a guideline is an explanation of procedures

3.

Which type of policies specifies the internal requirements of another policy and covers a particular target audience?

a)

High-level general policies

b)

High-level specific policies

c)

Topic-specific policies

4.

Which of the following is a high-level specific policy?

a)

Incident management policy

b)

Information security policy

c)

Policy on cryptography

5.

What is the first phase of the information security policy development life cycle?

a)

Policy construction

b)

Policy monitoring and maintenance

c)

Risk assessment

6.

What does ISO/IEC 27005 provide?

a)

Requirements for information security risk management

b)

Guidelines for managing any type of risk, regardless of its nature or consequences

c)

Guidelines for information security risk management

7.

What should be considered when selecting a risk assessment methodology when implementing an ISMS, among others?

a)

The scalability of the methodology to integrate various project sizes and complexities

b)

Compatibility of the methodology with all the criteria of ISO/IEC 27001

c)

Residual risks documented in the risk treatment plan

8.

Which of the following best defines primary/business assets in the context of an organization’s information security?

a)

Primary/business assets include physical infrastructure like buildings and warehouse

b)

Primary/business assets are components of the information system that support other asset

c)

Primary/business assets refer to information or processes of value for an organization

9.

Which phase of risk assessment aims to find, recognize, and describe risks?

a)

Risk identification

b)

Risk evaluation

c)

Risk analysis

10.

Which of the following processes involves comparing the results of the risk analysis with the risk criteria to determine whether the risk and its magnitude is acceptable or tolerable?

a)

Risk treatment

b)

Risk evaluation

c)

Risk acceptance

11.

Which process modifies risk?

a)

Risk evaluation

b)

Risk identification

c)

Risk treatment

12.

Which of the following factors that may influence risks should organizations continually monitor, among others?

a)

New sources of risk

b)

Changes is laws and regulations

c)

Both A and B

13.

According to ISO/IEC 27001, what must the Statement of Applicability contain?

a)

The timeframes for auditing the controls

b)

The justification for excluding any of the Annex A controls

c)

The names of individuals responsible for the effectiveness of the controls

14.

How does an organization select the security controls of ISO/IEC 27001, Annex A?

a)

Based on the risk assessment results

b)

Based on the top management’s decision

c)

Based on the internal audit report

15.

Which of the following is a common reason for excluding controls of Annex A of ISO/IEC 27001?

a)

Streamline of the organization’s operational processes and complexity reduction

b)

Violation of legal, statutory, or contractual requirements

c)

Potential conflicts with industry best practices and guidelines