NEW
Font size
WorksheetsDay#1 ISO 27001 Lead Auditor
Total questions: 23
Worksheet time: 12mins
What does the ISO/IEC 27001 standard provide?
Guidelines for organizations implementing and maintaining an information security management system
Requirements for establishing, implementing, maintaining, and improving an information security management system
Guidance for auditing an information security management system
Organizations can certification against ISO/IEC 27002 if they implement all the information security controls that are outlined in this standard.
True
False
Which standard provides a set of information security controls that are aligned with the controls of Annex A of ISO/IEC 27001?
ISO/IEC 27002
ISO/IEC 27003
ISO/IEC 27004
What is the aim of intellectual property laws?
To enable organizations to protect certain intangible assets
To enable organizations to ensure that certain assets are regularly reviewed
To enable organizations to provide asset management reports for legal purposes
Which of the following is an objective of the privacy protection policy?
Increasing awareness regarding legal and business requirements for protecting personal information
Increasing awareness regarding cyberattacks that target the organization
Increasing awareness regarding the established procedures and implemented measures for protecting stored data
When are surveillance audits conducted?
After conducting the stage 2 audit
After conducting the audit follow-up
After obtaining certification
ISO performs accreditation and certification activities.
True
False
Which of the following statements regarding certification bodies is NOT correct?
A certification body certifies management systems, persons, processes, products, and services
A certification body is an authoritative, independent organization that verifies whether a conformity assessment body meets established criteria
A certification body can be a governmental or nongovernmental organization, with or without regulatory authority
Which of the activities below occurs before the audit?
Audit preparation
Confirmation of registration
Internal audit and management review
Organizations whose management systems are subject to audits are referred to as:
Auditors
Management system certification bodies
Auditees
Which of the following is an organizational, virtual asset?
Online branding
Email accounts
Medical data
What is the difference between information security and cybersecurity?
Information security refers to the protection of information in any format, whereas cybersecurity refers to the protection of digital data in particular
Information security does not protect digital data, whereas cybersecurity protects digital data
Information security refers to the protection of digital data only, whereas cybersecurity protects information in any format, i.e., physical or digital
A former employee of an organization has gained unauthorized access to the organization’s cloud-based records due to retained login credentials that were not deactivated. What does this present?
A threat that has the potential to harm the assets of the organization, such as information or systems
A vulnerability in the physical security system of the organization
A consequence due to incorrectly implemented data backup procedures
Which of the following principles ensures that only authorized users have access to sensitive data?
Confidentiality
Integrity
Availability
Which of the following is an example of a vulnerability?
Complicated data processing procedures
Power interruption
Data input error by personnel
Which of the following is an example of a consequence on the confidentiality of information that may come as a result of the exploitation of a vulnerability by a threat?
Unavailability of service
Deliberate change of information
Invasion of the privacy of users or customers
Which of the following is a detective control?
Conducting technical reviews of applications
Securing offices and equipment
Separating the development, testing, and production environments
To which classification of security controls does the segregation of duties belong?
A. Detective by function and managerial by type
Preventive by function and administrative by type
Detective by function and administrative by type
Which of the statements below regarding the information security policy is NOT correct?
It must include a commitment to satisfy applicable requirements related to information security
It must be communicated only to personnel relevant to the ISMS
It must be available as documented information
Who is responsible for establishing the information security policy?
Top management
Internal interested parties
The information security manager
What should be considered when selecting a risk assessment methodology, among others?
Only the cost and ease of use of the methodology
Software tools that facilitate the use of the methodology
Compatibility with the guidelines of ISO/IEC 27005
An organization has decided to move its information-processing facilities to a place where the risk of flooding is low. Which risk treatment option has the organization chosen?
Risk retention
Risk modification
Risk avoidance
Why should an organization draft a statement of applicability (SoA)?
To justify the inclusion of all controls, irrespective of their sources, and exclusion of any controls of Annex A of ISO/IEC 27001
To document the justifications for the inclusion only of the controls of Annex A of ISO/IEC 27001
To justify the implementation of all ISO/IEC 27001 requirements
