ISO 27000 Foundation Certification ISO 27000 Foundation Certification MCQ 3 — Questions and Answers
Question 1: What is the primary purpose of ISO 27002 in relation to ISO 27001?
- It certifies organizations for ISMS compliance
- It provides guidance on implementing the controls referenced in ISO 27001 Annex A (Correct answer)
- It defines the risk assessment methodology organizations must use
- It specifies requirements for cloud security
Correct answer: It provides guidance on implementing the controls referenced in ISO 27001 Annex A
ISO 27002 is a code of practice that provides implementation guidance for the information security controls listed in ISO 27001 Annex A.
Question 2: In ISO 27000 terminology, what is a 'vulnerability'?
- A potential cause of an unwanted incident
- A weakness that could be exploited by a threat (Correct answer)
- The likelihood of a security breach occurring
- A safeguard implemented to reduce risk
Correct answer: A weakness that could be exploited by a threat
A vulnerability is a weakness in an asset or control that could be exploited by one or more threats.
Question 3: Which ISO 27000 standard specifically addresses information security for cloud services?
- ISO 27005
- ISO 27017 (Correct answer)
- ISO 27003
- ISO 27035
Correct answer: ISO 27017
ISO 27017 provides guidelines for information security controls applicable to the provision and use of cloud services.
Question 4: What does 'risk acceptance' mean in an ISO 27001 risk treatment context?
- Transferring the risk to a third party
- Implementing controls to reduce the risk
- Deciding to tolerate a risk without further treatment (Correct answer)
- Eliminating the activity that causes the risk
Correct answer: Deciding to tolerate a risk without further treatment
Risk acceptance means the organization consciously decides to retain the risk because the cost of treatment outweighs the potential impact.
Question 5: Which clause of ISO 27001 covers 'Context of the Organization'?
- Clause 4 (Correct answer)
- Clause 5
- Clause 6
- Clause 9
Correct answer: Clause 4
Clause 4 requires organizations to understand their internal and external context, interested parties, and the scope of the ISMS.
Question 6: What is the role of an internal audit in an ISO 27001 ISMS?
- To certify the organization against the standard
- To provide independent assurance that the ISMS conforms to requirements (Correct answer)
- To replace the need for a management review
- To identify and implement new security controls
Correct answer: To provide independent assurance that the ISMS conforms to requirements
Internal audits provide objective evidence that the ISMS is effectively implemented and conforms to ISO 27001 requirements.
Question 7: Which term refers to the remaining risk after security controls have been applied?
- Inherent risk
- Residual risk (Correct answer)
- Transferred risk
- Accepted risk
Correct answer: Residual risk
Residual risk is the level of risk that remains after risk treatment measures have been implemented.
What is the primary purpose of ISO 27002 in relation to ISO 27001?