ISO 27000 Foundation Certification Information Security 3 — Questions and Answers
Question 1: Which of the following is an example of a physical information security control?
- Firewall rule sets
- Encryption algorithms
- Locked server room doors (Correct answer)
- Password complexity policies
Correct answer: Locked server room doors
Physical controls protect assets through tangible means such as locked doors, security cameras, and access badges.
Question 2: ISO 27000 defines 'information security' as preserving which three core properties?
- Privacy, integrity, and availability
- Confidentiality, integrity, and availability (Correct answer)
- Confidentiality, reliability, and durability
- Authentication, authorization, and accountability
Correct answer: Confidentiality, integrity, and availability
ISO 27000 defines information security as preservation of confidentiality, integrity, and availability (the CIA triad).
Question 3: A company decides to purchase cyber insurance to handle a specific risk. Which risk treatment option does this represent?
- Risk avoidance
- Risk reduction
- Risk transfer (Correct answer)
- Risk retention
Correct answer: Risk transfer
Purchasing insurance transfers the financial consequences of a risk to another party (the insurer).
Question 4: What is an 'asset' in the context of ISO 27000?
- Only hardware and software components
- Anything that has value to the organization (Correct answer)
- Financial investments and property only
- Data stored in databases
Correct answer: Anything that has value to the organization
ISO 27000 broadly defines an asset as anything that has value to the organization, including information, software, hardware, and services.
Question 5: Which document in the ISMS formally commits the organization to information security?
- Risk register
- Statement of Applicability
- Information security policy (Correct answer)
- Business continuity plan
Correct answer: Information security policy
The information security policy is the top-level document that formally commits the organization to its security objectives and direction.
Question 6: In ISO 27001, the Statement of Applicability (SoA) must include which of the following?
- Selected controls, justification for inclusion or exclusion, and implementation status (Correct answer)
- Employee names and their security clearance levels
- A full list of identified threats and vulnerabilities
- Budget allocation for each security control
Correct answer: Selected controls, justification for inclusion or exclusion, and implementation status
The SoA documents all Annex A controls with justification for inclusion/exclusion and their current implementation status.
Question 7: What is the relationship between a 'threat' and a 'vulnerability' in ISO 27000 risk terminology?
- They are interchangeable terms for the same concept
- A threat exploits a vulnerability to cause harm to an asset (Correct answer)
- A vulnerability creates a threat automatically
- Threats apply only to physical assets; vulnerabilities apply to logical ones
Correct answer: A threat exploits a vulnerability to cause harm to an asset
A threat source exploits a vulnerability in a system or process to cause an adverse impact on information assets.
Which of the following is an example of a physical information security control?