ISO 27000 Foundation Certification ISO 27000 Foundation Certification MCQ 2 — Questions and Answers
Question 1: Which ISO 27000 series standard provides requirements for establishing an Information Security Management System (ISMS)?
- ISO 27001 (Correct answer)
- ISO 27002
- ISO 27005
- ISO 27017
Correct answer: ISO 27001
ISO 27001 is the standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS.
Question 2: In the context of ISO 27000, what does 'availability' mean in the CIA triad?
- Data is encrypted at rest
- Authorized users can access information when needed (Correct answer)
- Information is not disclosed to unauthorized parties
- Data has not been altered without authorization
Correct answer: Authorized users can access information when needed
Availability means ensuring that authorized users have access to information and associated assets when required.
Question 3: What is the purpose of a Statement of Applicability (SoA) in ISO 27001?
- To list all employees with access to sensitive data
- To document which controls are applicable and why others are excluded (Correct answer)
- To define the organization's risk appetite
- To record all security incidents over the past year
Correct answer: To document which controls are applicable and why others are excluded
The SoA documents the controls selected from Annex A, justifies their inclusion, and explains why any controls were excluded.
Question 4: Which term describes the potential for a threat to exploit a vulnerability?
- Impact
- Risk (Correct answer)
- Control
- Residual risk
Correct answer: Risk
Risk is the combination of the likelihood that a threat will exploit a vulnerability and the resulting impact on the organization.
Question 5: What does the Plan phase of the PDCA cycle involve in an ISMS context?
- Monitoring and measuring ISMS performance
- Implementing security controls
- Establishing ISMS policies, objectives, and risk treatment plans (Correct answer)
- Taking corrective and preventive actions
Correct answer: Establishing ISMS policies, objectives, and risk treatment plans
The Plan phase involves defining the ISMS scope, policy, risk assessment methodology, and selecting appropriate controls.
Question 6: Which of the following best describes 'non-repudiation' in information security?
- Preventing unauthorized access to data
- Ensuring a party cannot deny performing an action (Correct answer)
- Encrypting data during transmission
- Recovering data after a system failure
Correct answer: Ensuring a party cannot deny performing an action
Non-repudiation ensures that a party cannot deny having sent or received information or performed an action.
Question 7: Under ISO 27001, who holds ultimate accountability for the ISMS?
- The IT security manager
- The external auditor
- Top management (Correct answer)
- The risk committee
Correct answer: Top management
ISO 27001 requires top management to demonstrate leadership and commitment, making them ultimately accountable for the ISMS.
Which ISO 27000 series standard provides requirements for establishing an Information Security Management System (ISMS)?