6.3. Practice Questions
Q1. A security manager discovers that a critical vulnerability exists on a production payment server. Patching immediately requires a two-hour outage during business hours. What should the security manager do FIRST?
A. Apply the patch immediately to eliminate the vulnerability B. Present the risk and outage trade-off to the business owner accountable for the payment system C. Wait until the next scheduled maintenance window regardless of risk D. Escalate to the CISO to make the final technical decision
Correct: B. The security manager's role is to make the trade-off visible to the accountable business owner, not to unilaterally decide (A, C) or hand a business-risk decision to another technical role (D).
Q2. During an active ransomware incident, an analyst wants to immediately power off an affected server. What is the primary risk of this action?
A. It will alert the attacker to the response effort B. It may destroy volatile memory evidence needed for investigation C. It violates the business continuity plan D. It requires executive approval that hasn't been obtained
Correct: B. Immediate shutdown risks destroying forensic evidence held in volatile memory — this is the core containment trade-off covered in 5.2.3.
Q3. An organization has fully implemented ISO/IEC 27001 and holds current certification. A new industry-specific regulation introduces a requirement the standard doesn't address. What does this scenario best illustrate?
A. The organization's ISO/IEC 27001 implementation was deficient B. Framework certification does not guarantee compliance with every applicable regulatory requirement C. ISO/IEC 27001 should be abandoned in favor of the new regulation D. The regulation is invalid since a recognized framework is already in place
Correct: B. Frameworks organize security decisions; they don't automatically cover every regulatory requirement that applies to a specific organization (2.2.2, 4.1.3).
Q4. A risk register entry shows a risk that was accepted eighteen months ago, with no review since. What should a security manager recommend?
A. No action is needed since the risk was already formally accepted B. Re-evaluate the risk, since residual risk and business context may have changed since acceptance C. Automatically escalate to mitigation, since acceptance was clearly a mistake D. Remove the entry from the register, since it has been resolved by acceptance
Correct: B. Risk treatment requires ongoing monitoring — acceptance is not a permanent, one-time decision (3.2.3).
Q5. Two months after a minor, quickly resolved security incident with no data loss, no post-incident review has been conducted. What is the primary risk of skipping this review?
A. Regulatory penalties for failing to document the incident B. The organization misses a low-cost opportunity to uncover systemic gaps the incident may have revealed C. The incident response plan will need to be entirely rewritten D. Insurance claims related to the incident cannot be filed
Correct: B. Even minor incidents often reveal the same systemic gaps as major ones, and reviewing them is a low-cost improvement opportunity (5.2.5).