ITPEC FE Morning April 2020 Question 58

Source exam: ITPEC FE Morning April 2020Topic: IT Service Management

ITPEC FE Morning April 2020 — Question 58 of 80

The auditor should record (a) as a finding: risk acceptance criteria were determined after risk assessment was performed.

Under ISO 27001, the correct sequence is:

  • Define risk acceptance criteria first
  • Then perform risk assessment against those criteria

Determining criteria after the assessment reverses the required order, meaning risks were evaluated without a defined benchmark — a clear non-conformity.

Why not others:
- (b) Reporting erroneous disposal of personal information to authorities via specified procedures — correct incident response

- (c) Detecting and disinfecting spyware via malware scan — normal operational security

- (d) Permitting USB use in accordance with defined procedures — proper access control

Key rule: In ISO 27001, risk acceptance criteria must exist before risk assessment — not be reverse-engineered from results.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official FE past-paper collection or Report an issue.