ISO 27035-2:2016 – Information security incident management – Part 2: Guidelines to plan and prepare for incident response Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

GlobalCorp, a multinational manufacturing firm, recently achieved ISO 14001:2015 certification for its Environmental Management System (EMS). The EMS outlines stringent protocols for minimizing environmental impact across all operational areas. Concurrently, GlobalCorp is diligently implementing ISO 27035-2:2016 to enhance its information security incident management capabilities. A sophisticated cyberattack leads to the exfiltration of sensitive data from the company\'s environmental monitoring systems, which track emissions, waste management, and resource consumption. The incident response team is activated, and initial analysis suggests that immediate containment and recovery actions are necessary to prevent further data loss and potential disruption of environmental control processes. Considering GlobalCorp\'s commitment to both information security and environmental responsibility as enshrined in its ISO 14001 certified EMS, what is the MOST appropriate initial course of action for the incident response team?

Prioritize containment and recovery to minimize data loss and system disruption, while simultaneously consulting with environmental specialists to assess and mitigate any potential environmental impacts resulting from the incident or the response measures.
Immediately suspend all incident response activities until a comprehensive environmental impact assessment can be completed to ensure that all actions align with the ISO 14001 certified EMS requirements, even if it delays containment.
Focus exclusively on restoring the affected systems and recovering the compromised data, deferring any environmental impact assessments until after the incident is fully resolved to avoid hindering the security response.
Halt all incident response procedures indefinitely until the organization's environmental compliance officer can provide explicit guidance on how to proceed without violating any environmental regulations, effectively pausing incident management.

About the ISO 27035-2:2016 – Information security incident management – Part 2: Guidelines to plan and prepare for incident response Certification

These free practice questions are designed to help you assess your readiness for the ISO 27035-2:2016 – Information security incident management – Part 2: Guidelines to plan and prepare for incident response exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.