ISO 27000 Foundation Certification Prior Knowledge 4 — Questions and Answers
Question 1: Which of the following best describes 'non-repudiation' in information security?
- Ensuring data cannot be accessed without a password
- Preventing authorized users from being locked out
- Ensuring a party cannot deny having performed an action (Correct answer)
- Encrypting communications between two parties
Correct answer: Ensuring a party cannot deny having performed an action
Non-repudiation ensures that parties to a transaction cannot deny having sent or received information, often achieved through digital signatures.
Question 2: In ISO 27000, which term describes a weakness in an asset or control that a threat could exploit?
- Risk
- Impact
- Vulnerability (Correct answer)
- Incident
Correct answer: Vulnerability
A vulnerability is a weakness in an asset, system, or control that can be exploited by a threat to cause harm.
Question 3: Which statement correctly describes the Plan-Do-Check-Act (PDCA) cycle as applied to an ISMS?
- It is used only during the initial implementation of the ISMS
- It is a one-time process completed before certification
- It is a continual improvement cycle applied to ISMS maintenance (Correct answer)
- It applies only to technical controls, not management processes
Correct answer: It is a continual improvement cycle applied to ISMS maintenance
The PDCA cycle is a continual improvement model that helps organizations systematically improve their ISMS over time.
Question 4: A company decides to stop offering a high-risk online service to remove the associated information security risk. Which risk treatment is this?
- Risk modification
- Risk acceptance
- Risk avoidance (Correct answer)
- Risk transfer
Correct answer: Risk avoidance
Risk avoidance involves ceasing the activity that creates the risk entirely, removing the risk at its source.
Question 5: Which of the following is an example of a technical control in information security?
- Security awareness training program
- Visitor sign-in log at reception
- Multi-factor authentication system (Correct answer)
- Clean desk policy
Correct answer: Multi-factor authentication system
Technical controls are implemented through technology; multi-factor authentication is a software/hardware-based security measure.
Question 6: What does the term 'information security incident' mean in ISO 27000?
- Any planned maintenance activity that affects system availability
- A single or series of unwanted events that compromise information security (Correct answer)
- A scheduled risk assessment review
- A routine vulnerability scan finding
Correct answer: A single or series of unwanted events that compromise information security
An information security incident is an unwanted or unexpected event (or series of events) that has a significant probability of compromising business operations.
Question 7: Which ISO 27000 family standard specifically focuses on guidelines for information security controls?
- ISO 27000
- ISO 27001
- ISO 27002 (Correct answer)
- ISO 27005
Correct answer: ISO 27002
ISO 27002 provides a reference set of information security controls and implementation guidance for organizations.
Which of the following best describes 'non-repudiation' in information security?