ISO 27000 Foundation Certification MCQ Flashcards
7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 ISO 27000 Foundation Certification MCQ flashcards as text
Which ISO 27000 series standard provides requirements for establishing an Information Security Management System (ISMS)?
Answer: ISO 27001
ISO 27001 is the standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS.
In the context of ISO 27000, what does 'availability' mean in the CIA triad?
Answer: Authorized users can access information when needed
Availability means ensuring that authorized users have access to information and associated assets when required.
What is the purpose of a Statement of Applicability (SoA) in ISO 27001?
Answer: To document which controls are applicable and why others are excluded
The SoA documents the controls selected from Annex A, justifies their inclusion, and explains why any controls were excluded.
Which term describes the potential for a threat to exploit a vulnerability?
Answer: Risk
Risk is the combination of the likelihood that a threat will exploit a vulnerability and the resulting impact on the organization.
What does the Plan phase of the PDCA cycle involve in an ISMS context?
Answer: Establishing ISMS policies, objectives, and risk treatment plans
The Plan phase involves defining the ISMS scope, policy, risk assessment methodology, and selecting appropriate controls.
Which of the following best describes 'non-repudiation' in information security?
Answer: Ensuring a party cannot deny performing an action
Non-repudiation ensures that a party cannot deny having sent or received information or performed an action.
Under ISO 27001, who holds ultimate accountability for the ISMS?
Answer: Top management
ISO 27001 requires top management to demonstrate leadership and commitment, making them ultimately accountable for the ISMS.