Information Security Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security flashcards as text
Which of the following is an example of a physical information security control?
Answer: Locked server room doors
Physical controls protect assets through tangible means such as locked doors, security cameras, and access badges.
ISO 27000 defines 'information security' as preserving which three core properties?
Answer: Confidentiality, integrity, and availability
ISO 27000 defines information security as preservation of confidentiality, integrity, and availability (the CIA triad).
A company decides to purchase cyber insurance to handle a specific risk. Which risk treatment option does this represent?
Answer: Risk transfer
Purchasing insurance transfers the financial consequences of a risk to another party (the insurer).
What is an 'asset' in the context of ISO 27000?
Answer: Anything that has value to the organization
ISO 27000 broadly defines an asset as anything that has value to the organization, including information, software, hardware, and services.
Which document in the ISMS formally commits the organization to information security?
Answer: Information security policy
The information security policy is the top-level document that formally commits the organization to its security objectives and direction.
In ISO 27001, the Statement of Applicability (SoA) must include which of the following?
Answer: Selected controls, justification for inclusion or exclusion, and implementation status
The SoA documents all Annex A controls with justification for inclusion/exclusion and their current implementation status.
What is the relationship between a 'threat' and a 'vulnerability' in ISO 27000 risk terminology?
Answer: A threat exploits a vulnerability to cause harm to an asset
A threat source exploits a vulnerability in a system or process to cause an adverse impact on information assets.