← All ISO 27000 Foundation Certification Flashcard Decks

Prior Knowledge Flashcards

7 cards from real ISO 27000 Foundation Certification practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Prior Knowledge flashcards as text
  1. In ISO 27000, what is the difference between a 'threat' and a 'threat actor'?

    Answer: A threat is the potential cause of harm; a threat actor is the entity that exploits it

    A threat is the potential cause of an unwanted incident, while a threat actor (or threat source) is the human or environmental entity that carries it out.

  2. Which of the following correctly describes 'confidentiality' in the CIA triad?

    Answer: Ensuring information is not disclosed to unauthorized individuals or processes

    Confidentiality means restricting information access so that only authorized individuals or systems can view it.

  3. What is the purpose of a Statement of Applicability (SoA) in ISO 27001?

    Answer: To list controls selected from ISO 27002 and justify their inclusion or exclusion

    The SoA documents which ISO 27002 controls have been selected, why others were excluded, and whether they are implemented.

  4. Which concept describes the degree to which an asset is exposed based on the likelihood of a threat exploiting a vulnerability?

    Answer: Risk

    Risk in ISO 27000 combines the likelihood of a threat exploiting a vulnerability with the potential impact on the organization.

  5. An employee accidentally deletes critical business records stored on a shared drive. Which CIA property is primarily affected?

    Answer: Availability

    Deleting data removes access to it, which directly impacts availability — the ability of authorized users to access information when needed.

  6. Which of the following is a key characteristic of an effective information security policy?

    Answer: It should be approved by top management and communicated to all relevant parties

    An effective information security policy requires top management approval and must be communicated to all employees and relevant external parties.

  7. Which of the following best illustrates the concept of 'defense in depth' as a foundational security principle?

    Answer: Using multiple layers of controls so that if one fails, others still protect the asset

    Defense in depth applies multiple overlapping controls across different layers so that no single point of failure compromises overall security.