ISO 27005:2022 - Information Security Risk Manager Professional Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A financial services firm, following ISO 27005:2022 guidelines, has identified a residual risk of data leakage through compromised employee credentials, even after implementing basic password policies and initial security awareness training. The risk treatment plan proposes several control options to further mitigate this risk. When evaluating these options, what is the paramount consideration for selecting the most appropriate control(s) to address this residual risk, ensuring alignment with the organization\'s risk appetite and the principles of effective risk management?

The demonstrable effectiveness of the control in reducing the likelihood and/or impact of the identified risk to an acceptable level.
The extent to which the control aligns with current data protection regulations, such as GDPR or CCPA.
The ease with which the control can be implemented and integrated into existing IT infrastructure.
The availability of existing security tools and technologies within the organization that can be repurposed.

About the ISO 27005:2022 - Information Security Risk Manager Professional Certification

These free practice questions are designed to help you assess your readiness for the ISO 27005:2022 - Information Security Risk Manager Professional exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.