Information Security Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security flashcards as text
A hacker sends a deceptive email pretending to be the CEO to trick an employee into transferring funds. This is an example of which attack type?
Answer: Social engineering / phishing
Phishing/social engineering attacks manipulate people into divulging information or performing actions by impersonating trusted entities.
Which of the following best describes 'risk appetite' in an information security context?
Answer: The amount and type of risk an organization is willing to accept
Risk appetite is the amount and type of risk that an organization is willing to pursue or accept in pursuit of its objectives.
Under ISO 27001, what must an organization do when a nonconformity is identified?
Answer: Take corrective action to eliminate the cause and prevent recurrence
Clause 10.1 requires organizations to react to nonconformities and take corrective action to prevent recurrence.
What is the main difference between ISO/IEC 27001 and ISO/IEC 27002?
Answer: 27001 specifies ISMS requirements; 27002 provides guidance on implementing controls
ISO 27001 is the certifiable requirements standard, while ISO 27002 is a supporting guide with best-practice control implementation advice.
Which of the following is an administrative (managerial) information security control?
Answer: Security awareness training programs
Administrative controls are policies, procedures, and training programs that govern people's behavior and organizational processes.
When is information security risk assessment required to be performed under ISO 27001?
Answer: At planned intervals and when significant changes occur
ISO 27001 clause 8.2 requires risk assessments at planned intervals and whenever significant changes are proposed or occur.
Which concept describes the process of identifying the value of information assets and the impact of their loss?
Answer: Business impact analysis
Business impact analysis (BIA) identifies critical assets and quantifies the consequences of their loss or disruption to the organization.