ISO 27000 Foundation Certification MCQ Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISO 27000 Foundation Certification MCQ flashcards as text
What is the scope of ISO 27001 certification?
Answer: It is defined by the organization and may cover part or all of the organization
The organization defines the ISMS scope, which can include specific departments, locations, or processes rather than the whole organization.
In ISO 27000, which of the following is an example of a 'physical' security control?
Answer: Locked server room with badge access
Physical controls protect assets through tangible means such as locked doors, security cameras, and physical access badges.
What does 'information security' protect according to ISO 27000?
Answer: The confidentiality, integrity, and availability of information
ISO 27000 defines information security as the preservation of confidentiality, integrity, and availability of information.
Which document formally authorizes the start of a risk treatment plan under ISO 27001?
Answer: Risk treatment plan approved by top management
The risk treatment plan, approved by top management, formally documents how identified risks will be treated and by whom.
What is the difference between a threat and a threat agent in ISO 27000?
Answer: A threat is the potential for harm; a threat agent is the entity that exploits a vulnerability
A threat is the potential cause of an incident, while the threat agent is the specific individual, group, or force that carries out the threat.
Under ISO 27001, what must happen if a significant change occurs in the organization?
Answer: The ISMS scope and risk assessment must be reviewed and updated
ISO 27001 requires organizations to review their ISMS, including scope and risk assessment, whenever significant changes occur.
What is 'segregation of duties' as referenced in ISO 27001 controls?
Answer: Dividing tasks so no single person controls all aspects of a critical process
Segregation of duties reduces the risk of fraud or error by ensuring no single individual can complete a sensitive process without oversight from another.