GAQM ISO / IEC 27002 - Lead Implementer Exam Practice Test

Who is authorized to change the classification of a document?

You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of threats and risks. What is the relation between a threat, risk and risk analysis?

You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?

What do employees need to know to report a security incident?

Select the controls that correspond to the domain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)

What is the ISO / IEC 27002 standard?

