ISO 27000 Foundation Certification Prior Knowledge 2 — Questions and Answers
Question 1: Which of the following best describes 'information security' as defined in ISO 27000?
- Protecting only digital assets from cyber threats
- Preservation of confidentiality, integrity, and availability of information (Correct answer)
- Encrypting all data stored on company servers
- Installing firewalls to prevent unauthorized network access
Correct answer: Preservation of confidentiality, integrity, and availability of information
ISO 27000 defines information security as the preservation of confidentiality, integrity, and availability (CIA triad) of information.
Question 2: In the context of ISO 27001, what is the primary purpose of an Information Security Management System (ISMS)?
- To eliminate all information security risks entirely
- To provide a systematic approach to managing sensitive information and risks (Correct answer)
- To ensure 100% uptime of IT systems
- To comply with national cybersecurity laws only
Correct answer: To provide a systematic approach to managing sensitive information and risks
An ISMS provides a systematic, risk-based approach to managing sensitive company information and protecting it.
Question 3: Which term in ISO 27000 refers to the potential for a threat to exploit a vulnerability?
- Impact
- Risk (Correct answer)
- Control
- Asset
Correct answer: Risk
Risk in ISO 27000 is the potential that a threat will exploit a vulnerability, causing harm to the organization.
Question 4: What does 'availability' mean as a core property of information security?
- Information is accessible only to authorized users at all times (Correct answer)
- Information cannot be modified by unauthorized parties
- Information is kept secret from all external parties
- Information is encrypted at rest and in transit
Correct answer: Information is accessible only to authorized users at all times
Availability means that information and systems are accessible to authorized users whenever needed.
Question 5: Which ISO standard provides the vocabulary and definitions used across the ISO 27000 family?
- ISO 27001
- ISO 27002
- ISO 27000 (Correct answer)
- ISO 27005
Correct answer: ISO 27000
ISO 27000 is the overview and vocabulary standard that provides common terms and definitions for the entire ISO 27000 family.
Question 6: A company stores customer data on a server. In ISO 27000 terms, the server is an example of which concept?
- Threat
- Vulnerability
- Asset (Correct answer)
- Control
Correct answer: Asset
An asset is anything of value to the organization, including hardware like servers that store or process information.
Question 7: Which statement about the relationship between threats and vulnerabilities is correct?
- A threat is always internal; a vulnerability is always external
- A threat exploits a vulnerability to cause harm to an asset (Correct answer)
- A vulnerability causes harm without a threat present
- Threats and vulnerabilities are interchangeable terms in ISO 27000
Correct answer: A threat exploits a vulnerability to cause harm to an asset
A threat acts as the agent that exploits an existing vulnerability to cause harm to an information asset.
Which of the following best describes 'information security' as defined in ISO 27000?