wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Pre-Test ISO27001 (Multimatics)

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Overview and Vocabulary standard of ISMS (Information Security Management System) are provided in:

a)

ISO 27000

b)

ISO 27001

c)

ISO 27002

d)

ISO 27003

2.

Which process PDCA model does ISO/IEC 27001 adopt?

a)

Product, Do, Check, Adopt

b)

Plan, Do, Confidentiality, Availability

c)

Plan, Do, Check, Act

d)

Plan, Direct, Check, Act

3.

Which standard supports the controls of Annex A?

a)

ISO/IEC 27001

b)

ISO/IEC 27002

c)

ISO/IEC 27003

d)

ISO/IEC 27004

4.

Which of the option below is one benefit of effective of ISMS?

a)

Reducing information security risk and minimize exposure to information security breach

b)

Exposing confidentiality of sensitive information

c)

Processing and removing redundant information

d)

Profit oriented based on business need

5.

What is CIA in information security terminology?

a)

Confidentiality, Intrusive, Adoptable

b)

Constructive, Integrity, Availability

c)

Confidentiality, Integrity, Availability

d)

Cooperative, Integrity, Availability

6.

Which of the options below represent an ISMS objective?

a)

Integration of new technology

b)

Protection of critical asset

c)

Improvement of information security technology

d)

Reduce cost of Human Resources in IT Department

7.

Who must approve the ISMS business case and project plan?

a)

Any of the organization’s employees

b)

Head of IT Department

c)

IT Director

d)

The Organization’s Management

8.

What is an Audit?

a)

Subjective opinion on the state

b)

Interrogative process by specified expert

c)

A systematic, independent and documented process

d)

A symmetric and objective documentation

9.

What should be reviewed and updated on a continual basis?

a)

The information security incidents

b)

The information security failures

c)

The information security training

d)

The information security policy

10.

What does confidentiality ensure?

a)

The information is accessible by the authorise people

b)

The information is accurate and complete

c)

The information in valid for the user

d)

The information is protected by IT device

11.

Which of the following IS NOT an example of threat?

a)

Theft of media or document

b)

Un-authorised use of equipment

c)

Complicated user interface

d)

Un-discipline people to protect data

12.

When an employee is to be terminated, which of the following should be done?

a)

Inform the employee a few hours before they are officially terminated.

b)

Send out a broadcast email informing everyone that a specific employee is to be terminated.

c)

Disabled the employee’s network access just as they are informed of the termination

d)

Wait until you and the employee are the only people remaining in the building before announcing termination

13.

Which of the following IS NOT an advantage of ISO/IEC 27001?

a)

Increase quality of security incident

b)

Improvement of information security

c)

Company image/reputation

d)

Good governance

14.

What is the main content of ISO 27002?

a)

Overview and vocabulary to the ISO 27000 series

b)

Requirements for ISMS standard

c)

Code of practice for information security controls & control objective

d)

Risk management for information security

15.

What type of controls are segregation of duties, job rotation and approval process?

a)

Technical control

b)

Administrative control

c)

Managerial control

d)

Full control

16.

Performance degradation can have an impact on the ………………. of information

a)

Integrity

b)

Confidentiality

c)

Availability

d)

Productivity

17.

What is the main objective of the audit follow-up?

a)

To validate the operational control of the auditee processes

b)

To verify the “design” of the management system

c)

To validate the action plans and corrective actions implemented by the auditee

d)

To improve information security management

18.

What is the correlation between continual improvement and information security errors?

a)

Continual improvement introduces new error

b)

Continual improvement help increase number of errors

c)

Continual improvement help decrease number of errors

d)

Continual improvement eliminate the security breach

19.

Which standard below provides requirements for an Information Security Management System (ISMS)?

a)

ISO/IEC 90001

b)

ISO/IEC 14001

c)

ISO/IEC 18001

d)

ISO/IEC 27001

20.

What are information, software, services and people considered as?

a)

Resources

b)

Assets

c)

Information

d)

Inventory