ISO 27000 Foundation Certification ISO 27000 Foundation Certification MCQ 4 — Questions and Answers
Question 1: What is the scope of ISO 27001 certification?
- It must cover the entire organization without exception
- It is defined by the organization and may cover part or all of the organization (Correct answer)
- It is determined solely by the certification body
- It automatically includes all subsidiaries and third parties
Correct answer: It is defined by the organization and may cover part or all of the organization
The organization defines the ISMS scope, which can include specific departments, locations, or processes rather than the whole organization.
Question 2: In ISO 27000, which of the following is an example of a 'physical' security control?
- Encryption of data at rest
- Access control lists on a server
- Locked server room with badge access (Correct answer)
- Firewall configuration rules
Correct answer: Locked server room with badge access
Physical controls protect assets through tangible means such as locked doors, security cameras, and physical access badges.
Question 3: What does 'information security' protect according to ISO 27000?
- Only digital data stored on servers
- The confidentiality, integrity, and availability of information (Correct answer)
- Solely the organization's financial records
- Physical hardware and network infrastructure only
Correct answer: The confidentiality, integrity, and availability of information
ISO 27000 defines information security as the preservation of confidentiality, integrity, and availability of information.
Question 4: Which document formally authorizes the start of a risk treatment plan under ISO 27001?
- The audit report
- Management review minutes
- Risk treatment plan approved by top management (Correct answer)
- The Statement of Applicability
Correct answer: Risk treatment plan approved by top management
The risk treatment plan, approved by top management, formally documents how identified risks will be treated and by whom.
Question 5: What is the difference between a threat and a threat agent in ISO 27000?
- They are synonymous terms used interchangeably
- A threat is the potential for harm; a threat agent is the entity that exploits a vulnerability (Correct answer)
- A threat agent is a technical vulnerability; a threat is a human actor
- A threat is always accidental; a threat agent is always deliberate
Correct answer: A threat is the potential for harm; a threat agent is the entity that exploits a vulnerability
A threat is the potential cause of an incident, while the threat agent is the specific individual, group, or force that carries out the threat.
Question 6: Under ISO 27001, what must happen if a significant change occurs in the organization?
- The ISMS certification is immediately revoked
- The ISMS scope and risk assessment must be reviewed and updated (Correct answer)
- Only the IT department needs to be notified
- No action is required until the next scheduled audit
Correct answer: The ISMS scope and risk assessment must be reviewed and updated
ISO 27001 requires organizations to review their ISMS, including scope and risk assessment, whenever significant changes occur.
Question 7: What is 'segregation of duties' as referenced in ISO 27001 controls?
- Encrypting duties across multiple servers
- Dividing tasks so no single person controls all aspects of a critical process (Correct answer)
- Assigning all security tasks to one dedicated team
- Separating development and production environments only
Correct answer: Dividing tasks so no single person controls all aspects of a critical process
Segregation of duties reduces the risk of fraud or error by ensuring no single individual can complete a sensitive process without oversight from another.
What is the scope of ISO 27001 certification?