>_ CYBERVERSE.AI
GRC interview question
Walk me through how you would conduct an ISO 27001 risk assessment.
What interviewers are really testing
Scope and asset inventory first
A clear likelihood x impact methodology
Treatment plan tied to the SoA
A strong answer framework
Define scope and risk acceptance criteria
Build the asset inventory with owners
Identify threats and vulnerabilities per asset
Score likelihood x impact
Choose treatment: mitigate, transfer, avoid, accept
Record in the risk register and map controls to the SoA
Follow-ups you should be ready for
Qualitative vs quantitative - when each?
How often must you reassess?
Who accepts residual risk?
Reading answers is not the same as defending them.
Practice this question live with an AI interviewer that scores you out of 100.
Practice this question free at CyberVerse AI →
More real GRC interview questions
A domain controller is making outbound connections to an external IP on port 443. No maintenance is scheduled. How do you investigate?
A user reports clicking a link in a phishing email. Walk me through your response.
How would you write a Splunk search to detect multiple failed logins followed by a success?