NEW
Font size
WorksheetsPre-Test ISO27001 (Multimatics)
Total questions: 20
Worksheet time: 10mins
Overview and Vocabulary standard of ISMS (Information Security Management System) are provided in:
ISO 27000
ISO 27001
ISO 27002
ISO 27003
Which process PDCA model does ISO/IEC 27001 adopt?
Product, Do, Check, Adopt
Plan, Do, Confidentiality, Availability
Plan, Do, Check, Act
Plan, Direct, Check, Act
Which standard supports the controls of Annex A?
ISO/IEC 27001
ISO/IEC 27002
ISO/IEC 27003
ISO/IEC 27004
Which of the option below is one benefit of effective of ISMS?
Reducing information security risk and minimize exposure to information security breach
Exposing confidentiality of sensitive information
Processing and removing redundant information
Profit oriented based on business need
What is CIA in information security terminology?
Confidentiality, Intrusive, Adoptable
Constructive, Integrity, Availability
Confidentiality, Integrity, Availability
Cooperative, Integrity, Availability
Which of the options below represent an ISMS objective?
Integration of new technology
Protection of critical asset
Improvement of information security technology
Reduce cost of Human Resources in IT Department
Who must approve the ISMS business case and project plan?
Any of the organization’s employees
Head of IT Department
IT Director
The Organization’s Management
What is an Audit?
Subjective opinion on the state
Interrogative process by specified expert
A systematic, independent and documented process
A symmetric and objective documentation
What should be reviewed and updated on a continual basis?
The information security incidents
The information security failures
The information security training
The information security policy
What does confidentiality ensure?
The information is accessible by the authorise people
The information is accurate and complete
The information in valid for the user
The information is protected by IT device
Which of the following IS NOT an example of threat?
Theft of media or document
Un-authorised use of equipment
Complicated user interface
Un-discipline people to protect data
When an employee is to be terminated, which of the following should be done?
Inform the employee a few hours before they are officially terminated.
Send out a broadcast email informing everyone that a specific employee is to be terminated.
Disabled the employee’s network access just as they are informed of the termination
Wait until you and the employee are the only people remaining in the building before announcing termination
Which of the following IS NOT an advantage of ISO/IEC 27001?
Increase quality of security incident
Improvement of information security
Company image/reputation
Good governance
What is the main content of ISO 27002?
Overview and vocabulary to the ISO 27000 series
Requirements for ISMS standard
Code of practice for information security controls & control objective
Risk management for information security
What type of controls are segregation of duties, job rotation and approval process?
Technical control
Administrative control
Managerial control
Full control
Performance degradation can have an impact on the ………………. of information
Integrity
Confidentiality
Availability
Productivity
What is the main objective of the audit follow-up?
To validate the operational control of the auditee processes
To verify the “design” of the management system
To validate the action plans and corrective actions implemented by the auditee
To improve information security management
What is the correlation between continual improvement and information security errors?
Continual improvement introduces new error
Continual improvement help increase number of errors
Continual improvement help decrease number of errors
Continual improvement eliminate the security breach
Which standard below provides requirements for an Information Security Management System (ISMS)?
ISO/IEC 90001
ISO/IEC 14001
ISO/IEC 18001
ISO/IEC 27001
What are information, software, services and people considered as?
Resources
Assets
Information
Inventory
