โ† All ISO 27000 Foundation Certification Flashcard Decks

Prior Knowledge Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Prior Knowledge flashcards as text
  1. Which of the following is an example of an administrative (organizational) control in information security?

    Answer: Implementing an acceptable use policy

    Administrative controls are policy-based measures like acceptable use policies that govern how people interact with information.

  2. In ISO 27000, what is meant by 'residual risk'?

    Answer: Risk that remains after controls have been applied

    Residual risk is the remaining level of risk after risk treatment controls have been implemented.

  3. Which of the four risk treatment options involves sharing the risk with another party?

    Answer: Risk transfer

    Risk transfer (also called risk sharing) involves passing the financial or operational impact of a risk to another party, such as an insurer.

  4. What does 'integrity' mean as a core property of information security?

    Answer: Information is accurate and has not been improperly altered

    Integrity ensures that information remains accurate and complete, and is only modified by authorized processes.

  5. Which role is typically responsible for approving the information security policy in an ISO 27001-aligned organization?

    Answer: Top management

    ISO 27001 requires top management to approve and demonstrate commitment to the information security policy.

  6. An attacker sends a deceptive email to trick an employee into revealing login credentials. Which threat category does this represent?

    Answer: Social engineering

    Phishing and deceptive emails fall under social engineering, where attackers manipulate people rather than systems.

  7. What is the main objective of a risk assessment in the context of ISO 27001?

    Answer: To identify, analyze, and evaluate information security risks

    Risk assessment aims to identify risks, analyze their likelihood and impact, and evaluate them against risk criteria.