ISO 27005:2022 - Information Security Risk Treatment Professional Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A financial services firm, operating under stringent regulatory oversight from bodies like the Financial Conduct Authority (FCA) and adhering to data privacy mandates such as the UK GDPR, has identified a residual risk of unauthorized access to sensitive customer financial data. This risk, after the implementation of basic access controls and encryption, is still rated as \'High\' against their defined risk acceptance criteria. The firm is exploring various treatment options. Which of the following approaches best aligns with the principles of ISO 27005:2022 for addressing such a persistent, unacceptable residual risk?

Implementing a multi-factor authentication (MFA) solution for all privileged access accounts and conducting regular, targeted security awareness training for employees handling sensitive data.
Documenting the residual risk as accepted, citing the cost of further mitigation as prohibitive, and relying on the existing controls to deter potential attackers.
Outsourcing the management of the sensitive data to a third-party vendor with a lower security maturity level, assuming they can absorb the risk.
Increasing the frequency of vulnerability scans without implementing any new preventative or detective controls, as this provides more data on potential weaknesses.

About the ISO 27005:2022 - Information Security Risk Treatment Professional Certification

These free practice questions are designed to help you assess your readiness for the ISO 27005:2022 - Information Security Risk Treatment Professional exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.