โ† All ISO 27000 Foundation Certification Flashcard Decks

Prior Knowledge Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Prior Knowledge flashcards as text
  1. Which of the following best describes 'information security' as defined in ISO 27000?

    Answer: Preservation of confidentiality, integrity, and availability of information

    ISO 27000 defines information security as the preservation of confidentiality, integrity, and availability (CIA triad) of information.

  2. In the context of ISO 27001, what is the primary purpose of an Information Security Management System (ISMS)?

    Answer: To provide a systematic approach to managing sensitive information and risks

    An ISMS provides a systematic, risk-based approach to managing sensitive company information and protecting it.

  3. Which term in ISO 27000 refers to the potential for a threat to exploit a vulnerability?

    Answer: Risk

    Risk in ISO 27000 is the potential that a threat will exploit a vulnerability, causing harm to the organization.

  4. What does 'availability' mean as a core property of information security?

    Answer: Information is accessible only to authorized users at all times

    Availability means that information and systems are accessible to authorized users whenever needed.

  5. Which ISO standard provides the vocabulary and definitions used across the ISO 27000 family?

    Answer: ISO 27000

    ISO 27000 is the overview and vocabulary standard that provides common terms and definitions for the entire ISO 27000 family.

  6. A company stores customer data on a server. In ISO 27000 terms, the server is an example of which concept?

    Answer: Asset

    An asset is anything of value to the organization, including hardware like servers that store or process information.

  7. Which statement about the relationship between threats and vulnerabilities is correct?

    Answer: A threat exploits a vulnerability to cause harm to an asset

    A threat acts as the agent that exploits an existing vulnerability to cause harm to an information asset.