โ† All ISO 27000 Foundation Certification Flashcard Decks

ISO 27000 Foundation Certification MCQ Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 ISO 27000 Foundation Certification MCQ flashcards as text
  1. Which ISO standard provides guidance specifically on information security incident management?

    Answer: ISO 27035

    ISO 27035 provides guidelines for planning, detecting, reporting, assessing, and responding to information security incidents.

  2. What is the primary objective of a Business Continuity Plan (BCP) in the context of an ISMS?

    Answer: To ensure critical business functions can continue during and after a disruption

    A BCP ensures that essential business activities can be maintained or rapidly recovered following a significant disruption.

  3. In ISO 27001, what is the purpose of a management review?

    Answer: To evaluate the ISMS performance and make decisions for continual improvement

    Management reviews assess the continuing suitability, adequacy, and effectiveness of the ISMS and drive improvements.

  4. What does 'asset classification' involve under ISO 27001?

    Answer: Categorizing assets based on their value and sensitivity to apply appropriate protection

    Asset classification assigns labels such as public, internal, confidential, or secret to determine the level of protection each asset requires.

  5. Which of the following best describes 'risk transfer' as a risk treatment option?

    Answer: Moving risk responsibility to another party such as via insurance or outsourcing

    Risk transfer involves shifting the financial or operational consequences of a risk to a third party, such as purchasing cyber insurance.

  6. What is the key difference between corrective action and preventive action in ISO 27001?

    Answer: Corrective action eliminates the cause of a detected nonconformity; preventive action avoids potential nonconformities

    Corrective action deals with actual nonconformities that have occurred, while preventive action aims to prevent potential nonconformities before they happen.

  7. Under ISO 27001, what is required when an organization outsources a process relevant to its ISMS?

    Answer: The organization must ensure outsourced processes are controlled and documented within the ISMS

    ISO 27001 requires that outsourced processes remain under the organization's ISMS controls through supplier agreements and monitoring.