ISO 27000 Foundation Certification Information Security 5 — Questions and Answers
Question 1: A hacker sends a deceptive email pretending to be the CEO to trick an employee into transferring funds. This is an example of which attack type?
- Denial of Service
- Social engineering / phishing (Correct answer)
- SQL injection
- Man-in-the-middle
Correct answer: Social engineering / phishing
Phishing/social engineering attacks manipulate people into divulging information or performing actions by impersonating trusted entities.
Question 2: Which of the following best describes 'risk appetite' in an information security context?
- The maximum impact a single incident can cause
- The amount and type of risk an organization is willing to accept (Correct answer)
- The probability of a threat exploiting a vulnerability
- The budget allocated to risk treatment activities
Correct answer: The amount and type of risk an organization is willing to accept
Risk appetite is the amount and type of risk that an organization is willing to pursue or accept in pursuit of its objectives.
Question 3: Under ISO 27001, what must an organization do when a nonconformity is identified?
- Immediately suspend ISMS certification
- Take corrective action to eliminate the cause and prevent recurrence (Correct answer)
- Report it to the national certification body within 24 hours
- Disclose it publicly in the annual report
Correct answer: Take corrective action to eliminate the cause and prevent recurrence
Clause 10.1 requires organizations to react to nonconformities and take corrective action to prevent recurrence.
Question 4: What is the main difference between ISO/IEC 27001 and ISO/IEC 27002?
- 27001 applies to large enterprises; 27002 applies to small businesses
- 27001 specifies ISMS requirements; 27002 provides guidance on implementing controls (Correct answer)
- 27001 covers physical security; 27002 covers logical security
- 27001 is for certification; 27002 is a legal compliance standard
Correct answer: 27001 specifies ISMS requirements; 27002 provides guidance on implementing controls
ISO 27001 is the certifiable requirements standard, while ISO 27002 is a supporting guide with best-practice control implementation advice.
Question 5: Which of the following is an administrative (managerial) information security control?
- Biometric door locks
- Data encryption at rest
- Security awareness training programs (Correct answer)
- Intrusion detection systems
Correct answer: Security awareness training programs
Administrative controls are policies, procedures, and training programs that govern people's behavior and organizational processes.
Question 6: When is information security risk assessment required to be performed under ISO 27001?
- Only at initial ISMS implementation
- At planned intervals and when significant changes occur (Correct answer)
- Every five years during recertification audits
- Only after a security incident is reported
Correct answer: At planned intervals and when significant changes occur
ISO 27001 clause 8.2 requires risk assessments at planned intervals and whenever significant changes are proposed or occur.
Question 7: Which concept describes the process of identifying the value of information assets and the impact of their loss?
- Business impact analysis (Correct answer)
- Threat modeling
- Vulnerability scanning
- Penetration testing
Correct answer: Business impact analysis
Business impact analysis (BIA) identifies critical assets and quantifies the consequences of their loss or disruption to the organization.
A hacker sends a deceptive email pretending to be the CEO to trick an employee into transferring funds.
This is an example of which attack type?