wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Day#3 LI-Certiprof

Total questions: 20

Worksheet time: 14mins

Name
Class
Date
1.

It has been detected that some sensitive information was leaked to competitors by a form employee after his separation from the company. Which of the ISO/IEC 27001:2022 ANNEX A controls are most applicable to this case?

a)

6.2

b)

6.5 and 6.6

c)

6.1

d)

None of the above

2.

Environmental threats and competitive drivers are elements that are considered for:

a)

Information security policies

b)

Information security priorities and requirements

c)

Internal audit

d)

None of the above

3.

Which control in ANNEX A of ISO IEC 27001:2022 ensures that information systems are designed, implemented, and operated securely within the development life cycle:

a)

8.27

b)

8.28

c)

8.20

d)

5.1

4.

Opportunities to improve the audit program may include:

a)

A. Align audit dates with the availability of the auditee's key personnel

b)

B. Allow multiple audits in a single visit

c)

C. Minimize audit time

d)

A, B and C

5.

Reporting to senior management on the performance of the ISMS is an assigned responsibility:

a)

The information security leader.

b)

Senior Management.

c)

Management of the organization.

d)

The leader of each process.

6.

Which of these statements do you agree with?

a)

An audit team should be selected, considering the academic knowledge required to achieve the objectives.

b)

An audit team should be selected, considering the degree of commitment to achieve the objectives.

c)

An audit team should be selected, considering the competence required to achieve the objectives.

d)

An audit team should be selected, considering the skills needed to achieve the objectives.

7.

During a visit to the physical facilities the auditor finds that the PCs have different dates and times. Which control in Annex A of ISO IEC 27001:2022 has not been properly implemented?

a)

8.17.

b)

8.14.

c)

5.2.

d)

5.1.

8.

The following aspects should be considered when determining the need for internal and external communications about the ISMS:

a)

On what to communicate.

b)

How to communicate.

c)

When to communicate.

d)

All of the above.

9.

Your boss asks you to expedite reports while you are traveling, so you use airport and hotel Wi-Fi with local storage and cloud synchronization. Which control in Annex A of ISO IEC 27001:2022 is not correctly met?

a)

7.9

b)

5.10.

c)

7.11.

d)

5.1.

10.

According to ISO 19011:2018, audit criteria are:

a)

A set of requirements used as a reference against which objective evidence is compared.

b)

Only known to the Company's senior management and the auditor.

c)

Detailed by the auditor in conjunction with the Company and the audited process.

d)

They are related in detail in the audit report.

11.

In the morning hours people were asked to work from home by connecting from a secure VPN, since there was no electricity supply in the Company. Unfortunately, the DATACENTER where sensitive information is stored was connected to a UPS that failed within two hours of being turned on and mission critical activities could not be carried out. The company's penalties were large because it had ensured that the availability was 99.7%. What is the control of ANNEX A of ISO IEC 27001:2022 that most applies to this case?

a)

5.1.

b)

6.3.

c)

7.2.

d)

8.14.

12.

Regarding documented information, ISO 27001:2022 indicates it may include:

a)

A.     Documented information of external origin, determined by the organization as necessary for the planning and operation of the information security management system.

b)

B.     Documented information required by the information security management system and by this international regulation.

c)

C.    Documented information that the organization has determined is necessary for the effectiveness of the information security management system.

d)

D.    All of the above.

13.

During a security audit, it was found that the organization did not have a clear policy for managing access rights to sensitive information. Which control in Annex A of ISO IEC 27001:2022 is most relevant to this issue?

a)

9.4

b)

9.3

c)

9.2

d)

9.1

14.

What is the primary purpose of conducting a risk assessment as per ISO 27001:2022?

a)

To identify vulnerabilities in the information security management system.

b)

To ensure compliance with legal requirements.

c)

To evaluate the organization's overall performance.

d)

To determine the effectiveness of security controls.

15.

Which of the following is a key benefit of implementing an Information Security Management System (ISMS) according to ISO 27001:2022?

a)

Increased operational costs.

b)

Reduced employee productivity.

c)

Limited access to information.

d)

Improved stakeholder confidence.

16.

What is the main objective of establishing an information security policy within an organization?

a)

To limit access to sensitive data.

b)

To increase the number of employees.

c)

To reduce operational costs.

d)

To ensure compliance with regulations.

17.

What is a key requirement for the documentation of the Information Security Management System (ISMS) as per ISO 27001:2022?

a)

It should include personal opinions of the management.

b)

It must be accessible only to senior management.

c)

It should be regularly reviewed and updated.

d)

It must be stored in a physical format only.

18.

Which of the following statements regarding ISO/IEC 27004 is correct?

a)

ISO/IEC 27004 provides guidelines to help organizations in evaluating the ISMS performance

b)

Organizations can obtain certification against ISO/IEC 27004

c)

ISO/IEC 27004 does NOT elaborate on what and when to monitor and measure

19.

What is the main purpose of control 6.1 Screening of Annex A of ISO/IEC 27001?

a)

To protect the organization’s interests as part of the process of any changes in employment

b)

To ensure that employees and contractors are aware of and fulfil their information security responsibilities

c)

To ensure that all personnel are eligible and suitable for their roles

20.

Among others, what must organizations do, to comply with clause 7.5.1 Documented information of ISO/IEC 27001?

a)

Develop a comprehensive database for the control of the documented information, storing all records in an encrypted format

b)

Develop a guide for the control of the documented information that is accessible only by the top management

c)

Develop a procedure for the control of the documented information