ISO 27000 Foundation Certification Prior Knowledge 3 — Questions and Answers
Question 1: Which of the following is an example of an administrative (organizational) control in information security?
- Installing antivirus software
- Using encryption on laptops
- Implementing an acceptable use policy (Correct answer)
- Adding a security camera at server room entrance
Correct answer: Implementing an acceptable use policy
Administrative controls are policy-based measures like acceptable use policies that govern how people interact with information.
Question 2: In ISO 27000, what is meant by 'residual risk'?
- Risk that is transferred to a third party
- Risk that remains after controls have been applied (Correct answer)
- Risk that is deemed acceptable by top management
- Risk identified during the initial assessment phase
Correct answer: Risk that remains after controls have been applied
Residual risk is the remaining level of risk after risk treatment controls have been implemented.
Question 3: Which of the four risk treatment options involves sharing the risk with another party?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk modification
Correct answer: Risk transfer
Risk transfer (also called risk sharing) involves passing the financial or operational impact of a risk to another party, such as an insurer.
Question 4: What does 'integrity' mean as a core property of information security?
- Only authorized people can view information
- Information is accurate and has not been improperly altered (Correct answer)
- Systems remain operational during attacks
- Information is stored in an encrypted format
Correct answer: Information is accurate and has not been improperly altered
Integrity ensures that information remains accurate and complete, and is only modified by authorized processes.
Question 5: Which role is typically responsible for approving the information security policy in an ISO 27001-aligned organization?
- IT security analyst
- System administrator
- Top management (Correct answer)
- External auditor
Correct answer: Top management
ISO 27001 requires top management to approve and demonstrate commitment to the information security policy.
Question 6: An attacker sends a deceptive email to trick an employee into revealing login credentials. Which threat category does this represent?
- Physical security breach
- Social engineering (Correct answer)
- Technical vulnerability exploitation
- Denial of service
Correct answer: Social engineering
Phishing and deceptive emails fall under social engineering, where attackers manipulate people rather than systems.
Question 7: What is the main objective of a risk assessment in the context of ISO 27001?
- To eliminate all identified risks
- To identify, analyze, and evaluate information security risks (Correct answer)
- To satisfy regulatory requirements only
- To document past security incidents
Correct answer: To identify, analyze, and evaluate information security risks
Risk assessment aims to identify risks, analyze their likelihood and impact, and evaluate them against risk criteria.
Which of the following is an example of an administrative (organizational) control in information security?