โ† All ISO 27000 Foundation Certification Flashcard Decks

ISO 27000 Foundation Certification MCQ Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 ISO 27000 Foundation Certification MCQ flashcards as text
  1. What is the primary purpose of ISO 27002 in relation to ISO 27001?

    Answer: It provides guidance on implementing the controls referenced in ISO 27001 Annex A

    ISO 27002 is a code of practice that provides implementation guidance for the information security controls listed in ISO 27001 Annex A.

  2. In ISO 27000 terminology, what is a 'vulnerability'?

    Answer: A weakness that could be exploited by a threat

    A vulnerability is a weakness in an asset or control that could be exploited by one or more threats.

  3. Which ISO 27000 standard specifically addresses information security for cloud services?

    Answer: ISO 27017

    ISO 27017 provides guidelines for information security controls applicable to the provision and use of cloud services.

  4. What does 'risk acceptance' mean in an ISO 27001 risk treatment context?

    Answer: Deciding to tolerate a risk without further treatment

    Risk acceptance means the organization consciously decides to retain the risk because the cost of treatment outweighs the potential impact.

  5. Which clause of ISO 27001 covers 'Context of the Organization'?

    Answer: Clause 4

    Clause 4 requires organizations to understand their internal and external context, interested parties, and the scope of the ISMS.

  6. What is the role of an internal audit in an ISO 27001 ISMS?

    Answer: To provide independent assurance that the ISMS conforms to requirements

    Internal audits provide objective evidence that the ISMS is effectively implemented and conforms to ISO 27001 requirements.

  7. Which term refers to the remaining risk after security controls have been applied?

    Answer: Residual risk

    Residual risk is the level of risk that remains after risk treatment measures have been implemented.