WorksheetsDay#1A - Certiprof
Total questions: 20
Worksheet time: 10mins
What does ISO/IEC 27001 provide?
Guidelines for implementing an information security management system
Requirements for implementing an information security management system
Guidelines and requirements for implementing a privacy information management system
Which of the following statements is correct?
Organizations can obtain certification against ISO/IEC 27001
Organizations can obtain certification against ISO/IEC 27003
Organizations can obtain certification against ISO/IEC 27005
Which of the following standards provides a reference set of information security controls and guidelines for their implementation?
ISO/IEC 27002
ISO/IEC 27701
ISO/IEC 27005
What is an integrated management system (IMS)?
A management system that integrates all the guidelines and best practices so as to enable the achievement of its purpose and mission
A management system that integrates all the components of a business into a coherent system so as to enable the achievement of its purpose and mission
A management system that integrates all frameworks and resources so as to enable the achievement of its purpose and mission
Which of the following is a benefit of an effective ISMS?
Reducing information security risks
Completely eliminating information security risks
Preventing all data breaches
Which of the following is considered a virtual organizational asset?
Email accounts
Intellectual property
Digital customer identity
What does confidentiality require?
That only authorized users have access to protected and sensitive information
That information is accurate and complete and not modified during storage or transit
That information is accessible when, where, and as required and to the person requiring
Which of the following is NOT an example of a threat?
Theft of media or documents
Unencrypted data
Unauthorized use of a system
Which information security principle would likely be impacted by a service interruption?
Availability
Confidentiality
Integrity
Vulnerability is a weakness of an asset or control that can be exploited by one or more threats.
True
False
What function does the control for the separation of the development, testing, and operating environments have?
Preventive
Detective
Corrective
Why is it important to understand the mission, objectives, values, and strategies of an organization?
To facilitate the internal audit process
To create a map of all the processes
To ensure consistent alignment with information security goals
Which of the following is NOT an element that should be considered when analyzing the organization’s internal context?
Competitors
Governance and organizational structure
Information flows and decision-making processes
Which of the following statements regarding the ISMS scope is correct?
The ISMS scope should be classified as confidential information
The ISMS scope does not have to consider the needs and expectations of interested parties
The ISMS scope should be available as documented information
What is the recommended process for making changes in ISMS scope?
Changes must be automatically implemented if the organization is certified by a conformity assessment body (CAB)
Changes should be justified and approved during a management review
Changes should be documented and be approved only by the ISMS project manager
ISO 27001:2022 states that when the organization determines the need for
changes to the ISMS, the changes shall be carried out in a planned manner in its
clause :
Clause 6.3
Clause 6.2
Clause 10.1
Clause 7.1
It establishes that the organization must define a risk assessment process:
a) Clause 6.1.1
b) Clause 6.1.2
c) Clause 8.1
d) B and C are valid
The ISMS Contributes to the Organization in:
Risk management to determine the appropriate controls to achieve acceptable levels of risk.
Information security as an essential component of the processes.
Active prevention and detection of information security incidents.
All of the above.
The following definition: "Property that determines that the information is not available or disclosed to unauthorized parties", refers to:
I do not repudiate.
Confidentiality
Integrity
Availability
Which of the following requirements of interested parties must organizations consider, according to clause 4.2 of ISO/IEC 27001?
B. Legal and regulatory requirements
A. Climate change requirements
Both A and B
