MANAGEMENT MASTER PRACTICE
EXAMINATION WITH ORIGINAL
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1.
An organization operating an international logistics network is
implementing an ISO 28000 supply chain security management system
(SCSMS). During the initial assessment, management identifies threats
involving cargo theft, unauthorized access to warehouses, falsification of
shipping documentation, cyberattacks against logistics systems, insider
misconduct, and disruption caused by natural disasters. What is the most
appropriate first step for systematically addressing these issues within
the SCSMS?
A. Immediately purchase additional physical security equipment for all
facilities
B. Establish a systematic process for identifying security threats,
assessing associated risks, and determining appropriate controls
C. Require every employee to undergo security training before
conducting any risk assessment
D. Outsource the entire security management function to an external
security company
Answer: B.
1
,Rationale: ISO 28000 is based on a systematic security-management
approach rather than simply purchasing security equipment or
outsourcing security responsibilities. The organization needs to
identify relevant threats and risks affecting its supply-chain activities,
evaluate them according to defined criteria, and determine suitable
controls. This provides the foundation for establishing, implementing,
maintaining, and continually improving the SCSMS.
2.
A multinational freight-forwarding company has facilities in several
countries. Its security manager argues that ISO 28000 requires the
company to identify every possible security threat worldwide, regardless
of whether that threat can affect its operations. Which approach is most
consistent with effective ISO 28000 implementation?
A. Identify every conceivable threat regardless of relevance
B. Focus only on threats that have previously resulted in an incident
C. Determine security threats and risks relevant to the organization's
supply-chain activities and operating context
D. Consider only threats identified by government authorities
Answer: C.
Rationale: An effective SCSMS must be relevant to the organization's
context and activities. Risk identification should be systematic and
sufficiently comprehensive to capture significant threats, but it should
remain connected to the organization's supply-chain operations,
assets, people, information, processes, and interested-party
requirements.
3.
2
,A company has completed its security risk assessment. One identified
threat is unauthorized access to a high-value pharmaceutical storage
area. The likelihood is assessed as high and the consequences as severe.
Which response is most appropriate?
A. Accept the risk without additional action because no incident has yet
occurred
B. Eliminate all warehouse operations permanently
C. Determine and implement proportionate security controls based on
the organization's risk evaluation and acceptance criteria
D. Transfer all responsibility for the risk to individual security guards
Answer: C.
Rationale: Significant risks require an appropriate risk treatment
response. Controls should be selected according to the organization's
established risk criteria and should be proportionate to the nature and
significance of the risk. Responsibility cannot simply be transferred to
individual guards because security is a management-system
responsibility.
4.
During an ISO 28000 audit, the auditor discovers that a logistics
company has a sophisticated CCTV system but no documented process
for evaluating whether security controls are effective. What is the
principal concern?
A. CCTV systems are prohibited under ISO 28000
B. Security controls must be connected to systematic risk management
and evaluated for effectiveness
C. The company must replace CCTV with physical guards
D. Documentation is unnecessary when technological controls exist
Answer: B.
3
, Rationale: The presence of security technology does not by itself
demonstrate an effective SCSMS. Controls should address identified
risks and their effectiveness should be monitored and evaluated. ISO
28000 emphasizes management-system processes rather than isolated
security devices.
5.
A company defines its SCSMS scope as “all company operations.”
However, its security procedures actually exclude a third-party
warehouse where company-owned cargo is routinely stored before
export. What should the organization do?
A. Leave the scope unchanged because third parties are automatically
excluded
B. Ensure that the scope accurately reflects relevant activities, locations,
processes, and supply-chain interfaces
C. Remove the warehouse from the organization's supply chain
D. Treat the warehouse as irrelevant because it is not owned by the
company
Answer: B.
Rationale: Supply-chain security extends across relevant interfaces
and activities, including those involving external providers where they
can affect security performance. The SCSMS scope should accurately
represent what the organization manages and what can affect its
ability to achieve intended security outcomes.
6.
A company identifies customs authorities, transport regulators,
customers, employees, contractors, logistics providers, and local
4