ISO 27035-1:2016 – Information Security Incident Management – Part 1: Principles of Incident Management Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

EcoSolutions, a company specializing in renewable energy solutions, experiences a simultaneous crisis: a chemical leak from a solar panel manufacturing process (potentially violating ISO 14001:2015) and a ransomware attack that compromises the customer database, including sensitive environmental impact assessment reports (requiring adherence to ISO 27035-1:2016). The chemical leak triggers local environmental regulations requiring immediate containment and reporting to environmental protection agencies. The ransomware attack encrypts critical operational data, hindering the initial assessment of the leak\'s environmental impact. The CEO, Anya Sharma, convenes an emergency meeting with the environmental safety manager, the IT security manager, the legal counsel, and the public relations officer. Considering the requirements of both ISO 14001:2015 and ISO 27035-1:2016, what is the MOST appropriate initial course of action for EcoSolutions?

Implement separate but coordinated incident response plans for both the chemical leak and the ransomware attack, prioritizing containment of the chemical leak to minimize environmental damage while simultaneously initiating the information security incident management process to assess and contain the data breach, and establish a unified communication strategy.
Prioritize the ransomware attack response, as data recovery is essential for assessing the environmental impact of the chemical leak and fulfilling regulatory reporting requirements, temporarily suspending environmental containment efforts to allocate resources to IT recovery.
Focus solely on containing the chemical leak, as environmental regulations supersede data breach concerns, and postpone the ransomware investigation until the environmental situation is fully under control and reported to the relevant agencies.
Issue a public statement acknowledging both incidents but defer detailed action until a comprehensive internal investigation can determine the root cause of both the chemical leak and the ransomware attack to avoid premature or misinformed responses.

About the ISO 27035-1:2016 – Information Security Incident Management – Part 1: Principles of Incident Management Certification

These free practice questions are designed to help you assess your readiness for the ISO 27035-1:2016 – Information Security Incident Management – Part 1: Principles of Incident Management exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.