ISO 27001 Practice Questions
Security+ and CySA+
QUESTION 1.
What is the primary purpose of ISO/IEC 27001?
A. Define network architectures
B. Establish an Information Security Management System (ISMS)
C. Provide encryption algorithms
D. Replace all regulatory requirements
Answer: B
Explanation: ISO 27001 provides requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
QUESTION 2.
Which three principles form the foundation of information security?
A. CIA Triad
B. AAA Framework
C. Risk Matrix
D. Defense in Depth
Answer: A
Explanation: The CIA Triad consists of Confidentiality, Integrity, and Availability, which ISO 27001 is designed to protect.
QUESTION 3.
What does ISMS stand for?
A. Information Security Monitoring Solution
B. Integrated Security Management Standard
C. Information Security Management System
D. Information Systems Management Service
Answer: C
Explanation: ISMS stands for Information Security Management System. It is the central focus of ISO 27001.
QUESTION 4.
Which ISO 27001 clause focuses on executive responsibility and commitment?
A. Context of the Organization
B. Leadership
C. Support
D. Improvement
Answer: B
Explanation: Clause 5, Leadership, requires management commitment, policy development, and assignment of security responsibilities.
QUESTION 5.
Which risk treatment option involves purchasing cyber insurance?
A. Mitigation
B. Acceptance
C. Avoidance
D. Transfer
Answer: D
Explanation: Risk transfer shifts some financial burden to another party, such as through insurance.
QUESTION 6.
An organization decides not to conduct a risky business activity. Which risk treatment strategy is being used?
A. Mitigate
B. Accept
C. Avoid
D. Transfer
Answer: C
Explanation: Risk avoidance removes exposure entirely by discontinuing the activity.
QUESTION 7.
Which document identifies which Annex A controls are implemented and why?
A. Risk Register
B. Audit Report
C. Incident Log
D. Statement of Applicability
Answer: D
Explanation: The Statement of Applicability (SoA) documents selected controls, exclusions, and justifications.
QUESTION 8.
Which ISO 27001 component is considered the driving force behind control selection?
A. Physical Security
B. Risk Assessment
C. Incident Response
D. Data Classification
Answer: B
Explanation: ISO 27001 uses a risk-based approach. Controls are selected based on identified risks.
QUESTION 9.
What is the purpose of Annex A?
A. List legal penalties
B. Define audit schedules
C. Provide a catalog of security controls
D. Define encryption standards
Answer: C
Explanation: Annex A contains reference security controls used in risk treatment activities.
QUESTION 10.
Which category would security awareness training fall under?
A. Technological Controls
B. People Controls
C. Physical Controls
D. Organizational Controls
Answer: B
Explanation: Security awareness, training, and personnel-related safeguards are People Controls.
QUESTION 11.
Which category includes surveillance cameras and badge readers?
A. Technological Controls
B. Organizational Controls
C. Physical Controls
D. Preventive Controls
Answer: C
Explanation: Physical controls protect facilities, equipment, and physical access points.
QUESTION 12.
A company performs periodic reviews to verify that controls are operating effectively. Which clause best aligns with this activity?
A. Performance Evaluation
B. Support
C. Planning
D. Leadership
Answer: A
Explanation: Clause 9 focuses on monitoring, measurement, internal audits, and management reviews.
QUESTION 13.
Which formula is commonly used during risk assessment?
A. Risk = Assets ÷ Controls
B. Risk = Vulnerability × Security
C. Risk = Likelihood × Impact
D. Risk = Asset × Availability
Answer: C
Explanation: Risk assessments commonly evaluate the likelihood of a threat occurring and the resulting impact.
QUESTION 14.
Which control category would encryption most likely belong to?
A. Physical
B. Technological
C. People
D. Administrative
Answer: B
Explanation: Encryption is a technical safeguard and is classified as a technological control.
QUESTION 15.
What is the primary objective of continuous improvement in ISO 27001?
A. Reduce staffing costs
B. Eliminate all risk
C. Improve security effectiveness over time
D. Remove compliance requirements
Answer: C
Explanation: Clause 10 requires organizations to improve their ISMS continually through corrective actions and lessons learned.
QUESTION 16.
Which activity is most closely associated with CySA+ and ISO 27001?
A. Hardware repair
B. Risk-based vulnerability management
C. Software sales
D. Database design
Answer: B
Explanation: CySA+ emphasizes analyzing, prioritizing, and mitigating vulnerabilities based on risk, a principle central to ISO 27001.
QUESTION 17.
Which of the following is an example of a threat?
A. Unpatched Operating System
B. Weak Password Policy
C. Phishing Campaign
D. Missing Security Awareness Training
Answer: C
Explanation: A threat is a potential cause of harm. Phishing attacks are common threat vectors. The others are vulnerabilities.
QUESTION 18.
Which clause requires organizations to establish security objectives?
A. Planning
B. Support
C. Improvement
D. Context
Answer: A
Explanation: Clause 6 (Planning) requires organizations to establish information security objectives and plans to achieve them.
QUESTION 19.
Which framework is specifically designed as an Information Security Management System standard?
A. PCI DSS
B. GDPR
C. ISO/IEC 27001
D. HIPAA
Answer: C
Explanation: ISO 27001 is the globally recognized ISMS standard based on risk management and continuous improvement.
QUESTION 20.
During an audit, management asks for evidence that security controls were selected based on organizational risk. What document should be provided?
A. Security Awareness Policy
B. Firewall Rule Base
C. Statement of Applicability
D. Vulnerability Scan Report
Answer: C
Explanation: The Statement of Applicability demonstrates which controls were selected, implemented, excluded, and justified based on risk assessment results.
Exam Quick Review
Memorize these high-value exam facts:
• ISO 27001 = Information Security Management System (ISMS)
• CIA Triad = Confidentiality, Integrity, Availability
• Annex A = Security Controls
• SoA = Statement of Applicability
• Risk Responses = Mitigate, Transfer, Accept, Avoid
• Clause 5 = Leadership
• Clause 6 = Planning
• Clause 9 = Performance Evaluation
• Clause 10 = Continuous Improvement
CySA+ Focus = Risk Analysis, Monitoring, Incident Response
Security+ Focus = Governance, Risk, Compliance, Controls
No comments:
Post a Comment