PECB Certified ISO/IEC 27001 : 2022 Lead Implementer exam ISO-IEC-27001-Lead-Implementer Question # 36 Topic 4 Discussion

PECB Certified ISO/IEC 27001 : 2022 Lead Implementer exam ISO-IEC-27001-Lead-Implementer Question # 36 Topic 4 Discussion

ISO-IEC-27001-Lead-Implementer Exam Topic 4 Question 36 Discussion:
Question #: 36
Topic #: 4

Upon the risk assessment outcomes. Socket Inc. decided to:

• Require the use of passwords with at least 12 characters containing uppercase and lowercase letters, symbols, and numbers

• Require the change of passwords at least once every 60 days

• Keep backup copies of files on IT-provided network drives

• Assign users to a separate network when they have access to cloud storage files storing customers' personal data.

Based on scenario 5. Socket Inc. decided to use cloud storage to store customers' personal data considering that the identified risks have low likelihood and high impact, is this acceptable?


A.

Yes. because the calculated level of risk is below the acceptable threshold


B.

No, because the impact of the identified risks is considered in he high


C.

No. because the identified risks fall above the risk acceptable criteria threshold


Get Premium ISO-IEC-27001-Lead-Implementer Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.