โ† All ISO 27000 Foundation Certification Flashcard Decks

Information Security Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Security flashcards as text
  1. Which of the following is an example of a physical information security control?

    Answer: Locked server room doors

    Physical controls protect assets through tangible means such as locked doors, security cameras, and access badges.

  2. ISO 27000 defines 'information security' as preserving which three core properties?

    Answer: Confidentiality, integrity, and availability

    ISO 27000 defines information security as preservation of confidentiality, integrity, and availability (the CIA triad).

  3. A company decides to purchase cyber insurance to handle a specific risk. Which risk treatment option does this represent?

    Answer: Risk transfer

    Purchasing insurance transfers the financial consequences of a risk to another party (the insurer).

  4. What is an 'asset' in the context of ISO 27000?

    Answer: Anything that has value to the organization

    ISO 27000 broadly defines an asset as anything that has value to the organization, including information, software, hardware, and services.

  5. Which document in the ISMS formally commits the organization to information security?

    Answer: Information security policy

    The information security policy is the top-level document that formally commits the organization to its security objectives and direction.

  6. In ISO 27001, the Statement of Applicability (SoA) must include which of the following?

    Answer: Selected controls, justification for inclusion or exclusion, and implementation status

    The SoA documents all Annex A controls with justification for inclusion/exclusion and their current implementation status.

  7. What is the relationship between a 'threat' and a 'vulnerability' in ISO 27000 risk terminology?

    Answer: A threat exploits a vulnerability to cause harm to an asset

    A threat source exploits a vulnerability in a system or process to cause an adverse impact on information assets.