wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Day#1 ISO 27001 Lead Auditor

Total questions: 23

Worksheet time: 12mins

Name
Class
Date
1.

What does the ISO/IEC 27001 standard provide?

a)

Guidelines for organizations implementing and maintaining an information security management system

b)

Requirements for establishing, implementing, maintaining, and improving an information security management system

c)

Guidance for auditing an information security management system

2.

Organizations can certification against ISO/IEC 27002 if they implement all the information security controls that are outlined in this standard.

a)

True

b)

False

3.

Which standard provides a set of information security controls that are aligned with the controls of Annex A of ISO/IEC 27001?

a)

ISO/IEC 27002

b)

ISO/IEC 27003

c)

ISO/IEC 27004

4.

What is the aim of intellectual property laws?

a)

To enable organizations to protect certain intangible assets

b)

To enable organizations to ensure that certain assets are regularly reviewed

c)

To enable organizations to provide asset management reports for legal purposes

5.

Which of the following is an objective of the privacy protection policy?

a)

Increasing awareness regarding legal and business requirements for protecting personal information

b)

Increasing awareness regarding cyberattacks that target the organization

c)

Increasing awareness regarding the established procedures and implemented measures for protecting stored data 

6.

When are surveillance audits conducted?

a)

After conducting the stage 2 audit

b)

After conducting the audit follow-up

c)

After obtaining certification

7.

ISO performs accreditation and certification activities.

a)

True

b)

False

8.

Which of the following statements regarding certification bodies is NOT correct?

a)

A certification body certifies management systems, persons, processes, products, and services

b)

A certification body is an authoritative, independent organization that verifies whether a conformity assessment body meets established criteria

c)

A certification body can be a governmental or nongovernmental organization, with or without regulatory authority

9.

Which of the activities below occurs before the audit?

a)

Audit preparation

b)

Confirmation of registration

c)

Internal audit and management review

10.

Organizations whose management systems are subject to audits are referred to as:

a)

Auditors

b)

Management system certification bodies

c)

Auditees

11.

Which of the following is an organizational, virtual asset?

a)

Online branding

b)

Email accounts

c)

Medical data

12.

What is the difference between information security and cybersecurity?

a)

Information security refers to the protection of information in any format, whereas cybersecurity refers to the protection of digital data in particular

b)

Information security does not protect digital data, whereas cybersecurity protects digital data

c)

Information security refers to the protection of digital data only, whereas cybersecurity protects information in any format, i.e., physical or digital

13.

A former employee of an organization has gained unauthorized access to the organization’s cloud-based records due to retained login credentials that were not deactivated. What does this present?

a)

A threat that has the potential to harm the assets of the organization, such as information or systems

b)

A vulnerability in the physical security system of the organization

c)

A consequence due to incorrectly implemented data backup procedures

14.

Which of the following principles ensures that only authorized users have access to sensitive data?

a)

Confidentiality

b)

Integrity

c)

Availability

15.

Which of the following is an example of a vulnerability?

a)

Complicated data processing procedures

b)

Power interruption

c)

Data input error by personnel

16.

Which of the following is an example of a consequence on the confidentiality of information that may come as a result of the exploitation of a vulnerability by a threat?

a)

Unavailability of service

b)

Deliberate change of information

c)

Invasion of the privacy of users or customers

17.

Which of the following is a detective control? 

a)

Conducting technical reviews of applications

b)

Securing offices and equipment

c)

Separating the development, testing, and production environments

18.

To which classification of security controls does the segregation of duties belong?

a)

A.     Detective by function and managerial by type

b)

Preventive by function and administrative by type

c)

Detective by function and administrative by type

19.

Which of the statements below regarding the information security policy is NOT correct?

a)

It must include a commitment to satisfy applicable requirements related to information security

b)

It must be communicated only to personnel relevant to the ISMS

c)

It must be available as documented information

20.

Who is responsible for establishing the information security policy?

a)

Top management

b)

Internal interested parties

c)

The information security manager

21.

What should be considered when selecting a risk assessment methodology, among others?

a)

Only the cost and ease of use of the methodology

b)

Software tools that facilitate the use of the methodology

c)

Compatibility with the guidelines of ISO/IEC 27005

22.

An organization has decided to move its information-processing facilities to a place where the risk of flooding is low. Which risk treatment option has the organization chosen?

a)

Risk retention

b)

Risk modification

c)

Risk avoidance

23.

Why should an organization draft a statement of applicability (SoA)?

a)

To justify the inclusion of all controls, irrespective of their sources, and exclusion of any controls of Annex A of ISO/IEC 27001

b)

To document the justifications for the inclusion only of the controls of Annex A of ISO/IEC 27001

c)

To justify the implementation of all ISO/IEC 27001 requirements