ISO 27000 Foundation Certification ISO 27000 Foundation Certification MCQ 5 — Questions and Answers
Question 1: Which ISO standard provides guidance specifically on information security incident management?
- ISO 27003
- ISO 27005
- ISO 27035 (Correct answer)
- ISO 27017
Correct answer: ISO 27035
ISO 27035 provides guidelines for planning, detecting, reporting, assessing, and responding to information security incidents.
Question 2: What is the primary objective of a Business Continuity Plan (BCP) in the context of an ISMS?
- To eliminate all risks to business operations
- To ensure critical business functions can continue during and after a disruption (Correct answer)
- To replace the need for data backups
- To document all security incidents for regulatory reporting
Correct answer: To ensure critical business functions can continue during and after a disruption
A BCP ensures that essential business activities can be maintained or rapidly recovered following a significant disruption.
Question 3: In ISO 27001, what is the purpose of a management review?
- To perform a technical vulnerability scan of all systems
- To evaluate the ISMS performance and make decisions for continual improvement (Correct answer)
- To replace the internal audit process
- To renegotiate contracts with third-party suppliers
Correct answer: To evaluate the ISMS performance and make decisions for continual improvement
Management reviews assess the continuing suitability, adequacy, and effectiveness of the ISMS and drive improvements.
Question 4: What does 'asset classification' involve under ISO 27001?
- Encrypting all organizational assets
- Categorizing assets based on their value and sensitivity to apply appropriate protection (Correct answer)
- Disposing of assets that are no longer in use
- Inventorying only physical hardware assets
Correct answer: Categorizing assets based on their value and sensitivity to apply appropriate protection
Asset classification assigns labels such as public, internal, confidential, or secret to determine the level of protection each asset requires.
Question 5: Which of the following best describes 'risk transfer' as a risk treatment option?
- Reducing the likelihood of a threat occurring
- Moving risk responsibility to another party such as via insurance or outsourcing (Correct answer)
- Eliminating the asset that carries the risk
- Accepting that the risk is within tolerance levels
Correct answer: Moving risk responsibility to another party such as via insurance or outsourcing
Risk transfer involves shifting the financial or operational consequences of a risk to a third party, such as purchasing cyber insurance.
Question 6: What is the key difference between corrective action and preventive action in ISO 27001?
- Corrective action addresses future risks; preventive action fixes past incidents
- Corrective action eliminates the cause of a detected nonconformity; preventive action avoids potential nonconformities (Correct answer)
- They are identical processes with different names
- Corrective action is performed by auditors; preventive action by IT staff
Correct answer: Corrective action eliminates the cause of a detected nonconformity; preventive action avoids potential nonconformities
Corrective action deals with actual nonconformities that have occurred, while preventive action aims to prevent potential nonconformities before they happen.
Question 7: Under ISO 27001, what is required when an organization outsources a process relevant to its ISMS?
- The process is excluded from the ISMS scope automatically
- The organization must ensure outsourced processes are controlled and documented within the ISMS (Correct answer)
- Outsourcing transfers all ISMS responsibilities to the supplier
- The certification body takes over oversight of outsourced processes
Correct answer: The organization must ensure outsourced processes are controlled and documented within the ISMS
ISO 27001 requires that outsourced processes remain under the organization's ISMS controls through supplier agreements and monitoring.
Which ISO standard provides guidance specifically on information security incident management?