ISO/IEC 27035:2023 - Information security incident management Foundation Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

Consider a scenario where a critical server in a financial institution experiences an unauthorized data exfiltration event. The incident response team is activated. Which of the following actions, when prioritized within the incident response plan, best reflects the foundational principles of ISO/IEC 27035:2023 for effective incident management?

Immediate isolation of affected systems to prevent further data loss, followed by a systematic eradication of the threat and a structured recovery of services, culminating in a detailed post-incident analysis to identify root causes and improve future responses.
Promptly notifying all relevant regulatory bodies, such as those overseeing financial data privacy, and initiating a broad communication campaign to inform all stakeholders about the breach.
Focusing primarily on restoring affected services to their pre-incident state as quickly as possible, with secondary attention given to identifying the exact method of intrusion.
Conducting an extensive forensic investigation to pinpoint every single compromised system and data element before any containment or recovery actions are taken.

About the ISO/IEC 27035:2023 - Information security incident management Foundation Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27035:2023 - Information security incident management Foundation exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.