Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Day#1A - Certiprof

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

What does ISO/IEC 27001 provide?

a)

Guidelines for implementing an information security management system

b)

Requirements for implementing an information security management system

c)

Guidelines and requirements for implementing a privacy information management system

2.

Which of the following statements is correct?

a)

Organizations can obtain certification against ISO/IEC 27001

b)

Organizations can obtain certification against ISO/IEC 27003

c)

Organizations can obtain certification against ISO/IEC 27005

3.

Which of the following standards provides a reference set of information security controls and guidelines for their implementation?

a)

ISO/IEC 27002

b)

ISO/IEC 27701

c)

ISO/IEC 27005

4.

What is an integrated management system (IMS)?

a)

A management system that integrates all the guidelines and best practices so as to enable the achievement of its purpose and mission

b)

A management system that integrates all the components of a business into a coherent system so as to enable the achievement of its purpose and mission

c)

A management system that integrates all frameworks and resources so as to enable the achievement of its purpose and mission

5.

Which of the following is a benefit of an effective ISMS?

a)

Reducing information security risks

b)

Completely eliminating information security risks

c)

Preventing all data breaches

6.

Which of the following is considered a virtual organizational asset?

a)

Email accounts

b)

Intellectual property

c)

Digital customer identity

7.

What does confidentiality require?

a)

That only authorized users have access to protected and sensitive information

b)

That information is accurate and complete and not modified during storage or transit

c)

That information is accessible when, where, and as required and to the person requiring

8.

Which of the following is NOT an example of a threat?

a)

Theft of media or documents

b)

Unencrypted data

c)

Unauthorized use of a system

9.

Which information security principle would likely be impacted by a service interruption?

a)

Availability

b)

Confidentiality

c)

Integrity

10.

Vulnerability is a weakness of an asset or control that can be exploited by one or more threats.

a)

True

b)

False

11.

What function does the control for the separation of the development, testing, and operating environments have?

a)

Preventive

b)

Detective

c)

Corrective

12.

Why is it important to understand the mission, objectives, values, and strategies of an organization?

a)

To facilitate the internal audit process

b)

To create a map of all the processes

c)

To ensure consistent alignment with information security goals

13.

Which of the following is NOT an element that should be considered when analyzing the organization’s internal context?

a)

Competitors

b)

Governance and organizational structure

c)

Information flows and decision-making processes

14.

Which of the following statements regarding the ISMS scope is correct?

a)

The ISMS scope should be classified as confidential information

b)

The ISMS scope does not have to consider the needs and expectations of interested parties

c)

The ISMS scope should be available as documented information

15.

What is the recommended process for making changes in ISMS scope?

a)

Changes must be automatically implemented if the organization is certified by a conformity assessment body (CAB)

b)

Changes should be justified and approved during a management review

c)

Changes should be documented and be approved only by the ISMS project manager

16.

ISO 27001:2022 states that when the organization determines the need for

changes to the ISMS, the changes shall be carried out in a planned manner in its

clause :

a)

Clause 6.3

b)

Clause 6.2

c)

Clause 10.1

d)

Clause 7.1

17.

It establishes that the organization must define a risk assessment process:

a)

a) Clause 6.1.1

b)

b) Clause 6.1.2

c)

c) Clause 8.1

d)

d) B and C are valid

18.

The ISMS Contributes to the Organization in:

a)

Risk management to determine the appropriate controls to achieve acceptable levels of risk.

b)

Information security as an essential component of the processes.

c)
  1. Active prevention and detection of information security incidents.

d)

All of the above.

19.

The following definition: "Property that determines that the information is not available or disclosed to unauthorized parties", refers to:

a)

I do not repudiate.

b)

Confidentiality

c)

Integrity

d)

Availability

20.

Which of the following requirements of interested parties must organizations consider, according to clause 4.2 of ISO/IEC 27001?

a)

B. Legal and regulatory requirements

b)

A. Climate change requirements

c)

Both A and B