Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Day#3A: Quiz 14-15-16

Total questions: 16

Worksheet time: 8mins

Name
Class
Date
1.

What does an organization’s security architecture represent?

a)

A set of practices used to address security requirements at a tactical level

b)

A set of practices used to address security requirements at an operational level

c)

A set of practices used to address security requirements at a system level

2.

Which of the following security services aim to facilitate user identification and support shared authentication across the organization?

a)

Boundary control

b)

Access control

c)

Cryptographic

3.

What are the six cascading levels covered in the SABSA matrix for security architecture development?

a)

Elements, purpose, procedures, personnel, area, and schedule

b)

Functions, planning, procedures, personnel, geography, and duration

c)

Asset, motivation, process, people, location, and time

4.

Which of the following steps should organizations take when preparing for the implementation of information security controls, among others?

a)

Prepare the required documented information

b)

Conduct a cost analysis

c)

Both A and B

5.

Why should organizations involve employees in the process of drafting information security procedures and policies?

a)

Because it saves time and resources during the drafting process

b)

Because it motivates them to contribute in the implementation of the information security controls

c)

Because it is a requirement of ISO/IEC 27001

6.

ISO/IEC 27001 provides a specific documentation method to be used for designing and describing controls.

a)

True

b)

False

7.

In how many themes are the 93 controls of Annex A grouped?

a)

Five

b)

Three

c)

Four

8.

What is the main purpose of control 6.1 Screening of Annex A of ISO/IEC 27001?

a)

To ensure that all personnel are eligible and suitable for their roles

b)

To ensure that employees and contractors are aware of and fulfil their information security responsibilities

c)

To protect the organization’s interests as part of the process of any changes in employment

9.

Who should have access to documented operating procedures for information processing facilities?

a)

Only the top management

b)

Only the person responsible for operating procedures

c)

Any user that needs them

10.

What is the main requirement of control 8.34 Protection of information systems during audit testing of Annex A?

a)

The tester and appropriate management must appropriately manage test information

b)

The tester and appropriate management must plan and agree on audit tests and other assurance activities involving assessment of operational systems

c)

The tester must separate and secure the development, testing, and production environments

11.

What is the purpose of control 5.7 Threat intelligence of Annex A?

a)

To provide awareness of the organization’s threat environment so that the appropriate mitigation actions can be taken

b)

To ensure appropriate flow of information

c)

To ensure information security risks related to deliverables are effectively addressed in project management throughout the project life cycle

12.

Among others, what must organizations do, to comply with clause 7.5.1 Documented information of ISO/IEC 27001?

a)

Develop a procedure for the control of the documented information

b)

Develop a guide for the control of the documented information that is accessible only by the top management

c)

Develop a comprehensive database for the control of the documented information, storing all records in an encrypted format

13.

In order to comply with ISO/IEC 27001, organizations should establish a complex document control system.

a)

True

b)

False

14.

What does a procedure describe?

a)

An outline of specific instructions on the steps to be taken

b)

A detailed instruction on the use or installation, maintenance, or operation of something to an actual description of policies

c)

A detailed explanation of the functioning of a process

15.

What is the main purpose of the approval stage in the process of controlling and managing documents for the ISMS?

a)

To distribute the document to all interested parties

b)

To finalize and sign off on the documents

c)

To identify opportunities for improvement

16.

What are the benefits of a documented information management system?

a)

Facilitating access to, referencing, disseminating, and archiving documents

b)

Ensuring traceability of the documented information

c)

Both A and B