Prior Knowledge Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Prior Knowledge flashcards as text
Which of the following best describes 'non-repudiation' in information security?
Answer: Ensuring a party cannot deny having performed an action
Non-repudiation ensures that parties to a transaction cannot deny having sent or received information, often achieved through digital signatures.
In ISO 27000, which term describes a weakness in an asset or control that a threat could exploit?
Answer: Vulnerability
A vulnerability is a weakness in an asset, system, or control that can be exploited by a threat to cause harm.
Which statement correctly describes the Plan-Do-Check-Act (PDCA) cycle as applied to an ISMS?
Answer: It is a continual improvement cycle applied to ISMS maintenance
The PDCA cycle is a continual improvement model that helps organizations systematically improve their ISMS over time.
A company decides to stop offering a high-risk online service to remove the associated information security risk. Which risk treatment is this?
Answer: Risk avoidance
Risk avoidance involves ceasing the activity that creates the risk entirely, removing the risk at its source.
Which of the following is an example of a technical control in information security?
Answer: Multi-factor authentication system
Technical controls are implemented through technology; multi-factor authentication is a software/hardware-based security measure.
What does the term 'information security incident' mean in ISO 27000?
Answer: A single or series of unwanted events that compromise information security
An information security incident is an unwanted or unexpected event (or series of events) that has a significant probability of compromising business operations.
Which ISO 27000 family standard specifically focuses on guidelines for information security controls?
Answer: ISO 27002
ISO 27002 provides a reference set of information security controls and implementation guidance for organizations.