ISO 27000 Foundation Certification Prior Knowledge 5 — Questions and Answers
Question 1: In ISO 27000, what is the difference between a 'threat' and a 'threat actor'?
- They are synonymous terms used interchangeably
- A threat is the potential cause of harm; a threat actor is the entity that exploits it (Correct answer)
- A threat actor is a technical vulnerability; a threat is a business risk
- A threat only applies to digital assets; a threat actor applies to physical assets
Correct answer: A threat is the potential cause of harm; a threat actor is the entity that exploits it
A threat is the potential cause of an unwanted incident, while a threat actor (or threat source) is the human or environmental entity that carries it out.
Question 2: Which of the following correctly describes 'confidentiality' in the CIA triad?
- Ensuring information is available when needed by authorized users
- Ensuring information is not disclosed to unauthorized individuals or processes (Correct answer)
- Ensuring information has not been altered without authorization
- Ensuring all information is encrypted using strong algorithms
Correct answer: Ensuring information is not disclosed to unauthorized individuals or processes
Confidentiality means restricting information access so that only authorized individuals or systems can view it.
Question 3: What is the purpose of a Statement of Applicability (SoA) in ISO 27001?
- To document all identified risks and their likelihood
- To list controls selected from ISO 27002 and justify their inclusion or exclusion (Correct answer)
- To record security incidents and corrective actions taken
- To define the scope of the external audit
Correct answer: To list controls selected from ISO 27002 and justify their inclusion or exclusion
The SoA documents which ISO 27002 controls have been selected, why others were excluded, and whether they are implemented.
Question 4: Which concept describes the degree to which an asset is exposed based on the likelihood of a threat exploiting a vulnerability?
- Impact
- Risk (Correct answer)
- Exposure
- Control gap
Correct answer: Risk
Risk in ISO 27000 combines the likelihood of a threat exploiting a vulnerability with the potential impact on the organization.
Question 5: An employee accidentally deletes critical business records stored on a shared drive. Which CIA property is primarily affected?
- Confidentiality
- Integrity
- Availability (Correct answer)
- Non-repudiation
Correct answer: Availability
Deleting data removes access to it, which directly impacts availability — the ability of authorized users to access information when needed.
Question 6: Which of the following is a key characteristic of an effective information security policy?
- It should be highly technical and written by the IT department only
- It should be approved by top management and communicated to all relevant parties (Correct answer)
- It must be kept confidential and shared only with security staff
- It should be updated daily to reflect emerging threats
Correct answer: It should be approved by top management and communicated to all relevant parties
An effective information security policy requires top management approval and must be communicated to all employees and relevant external parties.
Question 7: Which of the following best illustrates the concept of 'defense in depth' as a foundational security principle?
- Relying on a single strong firewall to protect all assets
- Using multiple layers of controls so that if one fails, others still protect the asset (Correct answer)
- Encrypting only the most sensitive data in the organization
- Assigning all security responsibilities to the IT department
Correct answer: Using multiple layers of controls so that if one fails, others still protect the asset
Defense in depth applies multiple overlapping controls across different layers so that no single point of failure compromises overall security.
In ISO 27000, what is the difference between a 'threat' and a 'threat actor'?