あなたを合格させるISO-IEC-27002-Foundation試験問題集で使おう(更新された42問があります) [Q17-Q33]

Share

あなたを合格させるISO-IEC-27002-Foundation試験問題集で使おう(更新された42問があります)

ISO-IEC-27002-Foundation試験問題集でPECB練習テスト問題

質問 # 17
According to ISO/IEC 27002, which of the following statements is correct?

  • A. Supporting utilities should be tested only at the beginning of the process
  • B. Equipment is NOT affected by power failures or other disruptions
  • C. Equipment should be sited securely and protected to reduce the risks from environmental and physical threats

正解:C

解説:
ISO/IEC 27002 requires equipment to be sited and protected in a way that reduces risks from physical and environmental threats. These threats include fire, flood, dust, vibration, electrical interference, unauthorized access, power instability, temperature extremes, and other environmental hazards. Option A is correct because secure siting and protection of equipment are essential to preserving confidentiality, integrity, and availability of information processing facilities. Option B is incorrect because equipment can absolutely be affected by power failures, utility disruptions, voltage fluctuations, overheating, and related events. Option C is incorrect because supporting utilities should be maintained, monitored, and tested as appropriate over time, not only at the beginning. ISO/IEC 27002 physical controls emphasize that technical systems depend on the physical environment. Servers, network devices, storage, and endpoint systems need appropriate location, power, cooling, cabling protection, and resilience measures. Equipment placement should also reduce unauthorized viewing, tampering, theft, and environmental exposure. The verified answer is option A because it reflects the physical protection objective in ISO/IEC 27002. References/Chapters: ISO/IEC 27002:2022, Control 7.8 Equipment siting and protection; Control 7.5 Protecting against physical and environmental threats; Control
7.11 Supporting utilities.


質問 # 18
In which group of controls does Control 5.7 Threat intelligence belong?

  • A. Technological
  • B. People
  • C. Organizational

正解:C

解説:
Control 5.7, Threat intelligence, belongs to the organizational control group. ISO/IEC 27002:2022 organizes controls by clauses: Clause 5 contains organizational controls, Clause 6 contains people controls, Clause 7 contains physical controls, and Clause 8 contains technological controls. Threat intelligence is classified as organizational because it supports governance, decision-making, risk awareness, planning, prioritization, and security strategy across the organization. It involves collecting, analyzing, and using information about existing or emerging threats so the organization can reduce risk and improve controls. Threat intelligence can influence vulnerability management, incident response, monitoring, supplier risk management, awareness training, security architecture, and risk treatment plans. Although threat intelligence may use technological tools, its ISO/IEC 27002 placement is organizational because its primary purpose is to guide security decisions and readiness. Option A is incorrect because technological controls are Clause 8. Option B is incorrect because people controls are Clause 6. The verified answer is option C. References/Chapters: ISO
/IEC 27002:2022, Clause 5 Organizational controls; Control 5.7 Threat intelligence; Clause 4 Structure of the standard.


質問 # 19
What should the organization's management define and approve to ensure appropriate direction and support for information security?

  • A. A risk management program
  • B. The list of assets that should be protected
  • C. An information policy

正解:C

解説:
Management should define and approve an information security policy to provide direction and support for information security. In ISO/IEC 27002:2022, Control 5.1 requires policies for information security to be defined, approved by management, published, communicated to relevant personnel and interested parties, and reviewed at planned intervals or when significant changes occur. The policy establishes management intent, expectations, responsibilities, and the basis for more detailed topic-specific policies. Option B, a risk management program, is important, but it is not the specific item required by this control to provide overall direction and support. Option C, a list of assets, is also important because asset inventories support control implementation, but it does not replace the policy framework. The policy is the governing statement that aligns information security with business objectives, legal requirements, and risk treatment. It gives authority to procedures, standards, and operational controls. Therefore, the correct answer is option A, understood as the organization's information security policy. References/Chapters: ISO/IEC 27002:2022, Control 5.1 Policies for information security; Control 5.2 Information security roles and responsibilities; Control 5.9 Inventory of information and other associated assets.


質問 # 20
According to Control 5.27 Learning from information security incidents, how can organizations use the information gained from the evaluation of information security incidents?

  • A. To enhance the incident management plan
  • B. Both A and C
  • C. To enhance user awareness and training

正解:B

解説:
Information gained from evaluating information security incidents should be used to improve both user awareness and training and the incident management plan. Control 5.27 focuses on learning from incidents so that organizations reduce the likelihood or impact of recurrence. Incident evaluation can reveal root causes, control failures, user mistakes, unclear procedures, delayed escalation, insufficient logging, poor communication, supplier weaknesses, or technical vulnerabilities. If users contributed to the incident through phishing response, mishandling of information, weak passwords, or reporting delays, awareness and training should be improved. If the incident response process showed weaknesses in roles, escalation, evidence collection, communication, containment, recovery, or decision-making, the incident management plan should be updated. ISO/IEC 27002 treats incidents as a feedback mechanism for continual improvement, not merely isolated events to close. Option B is correct because both listed uses are valid and mutually reinforcing.
Strong incident learning improves controls, procedures, monitoring, user behavior, and readiness for future events. References/Chapters: ISO/IEC 27002:2022, Control 5.27 Learning from information security incidents; Control 5.24 Information security incident management planning and preparation; Control 6.3 Information security awareness, education and training.


質問 # 21
What is risk assessment?

  • A. The overall process of risk identification, risk analysis, and risk evaluation
  • B. The process of finding, recognizing, and describing risks
  • C. The process to comprehend the nature of risk and to determine the level of risk

正解:A

解説:
Risk assessment is the overall process of risk identification, risk analysis, and risk evaluation. Option A describes only one component: risk identification. This is where risks are found, recognized, and described.
Option B describes risk analysis, where the organization understands the nature of risk and determines the level of risk, often by considering likelihood and consequence. A full assessment also requires risk evaluation, where the analyzed risk is compared against criteria to determine whether it is acceptable or requires treatment. ISO/IEC 27002 relies on this risk-based logic because controls should be selected according to actual security needs. The standard provides guidance on controls, but it does not require every organization to implement every control in the same way. Risk assessment helps determine which controls are necessary, how strongly they should be implemented, and what residual risk remains. This is why option C is the complete and correct answer. ISO/IEC 27002 control implementation is meaningful only when linked to risk, context, business value, and obligations. References/Chapters: ISO/IEC 27002:2022, Clause 4 control selection and attributes; ISO/IEC 27001 risk assessment and treatment; ISO/IEC 27005 risk management terminology.


質問 # 22
Which control of ISO/IEC 27002 aims to ensure the correct and secure operation of information processing facilities?

  • A. Control 5.35 Independent review of information security
  • B. Control 7.2 Physical entry
  • C. Control 5.37 Documented operating procedures

正解:C

解説:
Control 5.37, Documented operating procedures, aims to ensure the correct and secure operation of information processing facilities. Operating procedures translate security and operational requirements into repeatable instructions for administrators, operators, support teams, and users. They can cover system startup and shutdown, backup, restoration, logging, error handling, media handling, job scheduling, maintenance, incident escalation, access administration, and secure processing steps. Without documented procedures, operations become inconsistent and dependent on individual memory or informal practice, increasing the likelihood of mistakes, outages, unauthorized changes, or insecure handling. Control 7.2, Physical entry, protects secure physical areas by controlling access to facilities, but it does not define operational procedures.
Control 5.35, Independent review of information security, assesses whether the information security approach remains suitable, adequate, and effective, but it does not provide the day-to-day operating instructions. ISO
/IEC 27002 places documented procedures in the organizational control group because reliable operation requires governance, clarity, and repeatability. Therefore, option B is the verified answer. References
/Chapters: ISO/IEC 27002:2022, Control 5.37 Documented operating procedures; Control 7.2 Physical entry; Control 5.35 Independent review of information security.


質問 # 23
Which of the following controls should the organization implement to ensure that its approach to managing information security continues to be suitable, adequate and effective?

  • A. Control 5.24 Information security incident management planning and preparation
  • B. Control 5.4 Management responsibilities
  • C. Control 5.35 Independent review of information security

正解:C

解説:
Control 5.35, Independent review of information security, is the control intended to ensure that the organization's approach to managing information security remains suitable, adequate, and effective.
Independent reviews provide objective evaluation of whether policies, processes, controls, responsibilities, and implementation remain aligned with business needs, risks, legal requirements, and the organization's security objectives. The review may consider governance, control design, control operation, risk treatment, compliance, incident trends, technology changes, supplier dependencies, and audit results. Control 5.4, Management responsibilities, is important because management must ensure personnel apply security according to policies and procedures, but it is not the control specifically focused on independent review.
Control 5.24 concerns planning and preparation for incident management, which supports response capability but does not broadly assess the continuing suitability of the whole security approach. The phrase "suitable, adequate and effective" is a strong indicator of review and assurance. ISO/IEC 27002 uses independent review to challenge assumptions, detect weaknesses, and support continual improvement. Therefore, option B is the verified answer. References/Chapters: ISO/IEC 27002:2022, Control 5.35 Independent review of information security; Control 5.36 Compliance with policies, rules and standards for information security; Control 5.4 Management responsibilities.


質問 # 24
What does ISO/IEC 27002 recommend regarding audit testing?

  • A. The organization should temporarily stop its operational systems and business processes during audits and other assurance activities
  • B. Audit tests should be planned and agreed upon between the tester and the appropriate management
  • C. Audit tests and other assurance activities should be conducted ad hoc to determine the effectiveness of operational systems and business processes

正解:B

解説:
ISO/IEC 27002 recommends that audit testing should be planned and agreed upon between the tester and appropriate management. The purpose is to obtain assurance without creating unnecessary disruption, exposure, or operational risk. Audit tests can involve access attempts, vulnerability checks, sampling, transaction tracing, configuration review, log review, or control validation. If such activities are unmanaged, they may overload systems, expose sensitive information, interrupt services, conflict with change windows, or create false incident signals. Option B is incorrect because ad hoc assurance testing can be risky and inconsistent unless properly authorized and controlled. Option C is incorrect because audits should not normally require stopping operational systems and business processes; rather, they should be designed to minimize disruption while preserving evidence quality. ISO/IEC 27002 treats audit and assurance activities as important but controlled. Planning should define scope, timing, method, responsibilities, data handling, access requirements, and communication. The verified answer is option A because it balances assurance with operational security and business continuity. References/Chapters: ISO/IEC 27002:2022, Control 8.34 Protection of information systems during audit testing; Control 5.35 Independent review of information security.


質問 # 25
Which control of ISO/IEC 27002 helps organizations ensure that employees and contractors are suitable for their roles?

  • A. Control 6.1 Screening
  • B. Control 6.4 Disciplinary process
  • C. Control 6.7 Remote working

正解:A

解説:
Control 6.1 Screening is the ISO/IEC 27002 control that helps organizations ensure employees and contractors are suitable for their roles. Screening is performed before employment or engagement, and it should be proportionate to business requirements, information classification, access levels, legal requirements, and the risks associated with the role. It may include verification of identity, qualifications, employment history, references, criminal record checks where lawful and appropriate, and professional credentials. The goal is not unnecessary intrusion; the goal is to reduce the risk that unsuitable individuals receive access to sensitive information, systems, facilities, or responsibilities. Control 6.4, Disciplinary process, deals with responding to policy violations after employment has begun. Control 6.7, Remote working, addresses security arrangements for work outside organizational premises. Neither directly verifies suitability before assigning a role. ISO/IEC 27002 treats people controls as essential because insider risk, negligence, excessive access, and role mismatch can create significant security exposure. Therefore, option A is the verified answer. References
/Chapters: ISO/IEC 27002:2022, Control 6.1 Screening; Control 6.2 Terms and conditions of employment; Control 6.3 Information security awareness, education and training.


質問 # 26
How can organizations manage the security of large networks?

  • A. By avoiding the integration of information services, users, and information systems into large networks
  • B. By dividing networks into separate network domains and including them into the public network
  • C. By dividing networks into separate network domains and separating them from the public network

正解:C

解説:
Organizations can manage the security of large networks by dividing them into separate network domains and separating them from the public network where appropriate. This reflects the principle of network segregation, which reduces the ability of an attacker, malware, or unauthorized user to move freely across the environment. Separate domains can be based on trust level, business function, system criticality, data sensitivity, user group, supplier access, development environment, or regulatory requirement. ISO/IEC 27002 supports this through network security, network segregation, access control, and secure architecture practices.
Option B is incorrect because including internal domains into the public network would increase exposure and weaken boundaries. Option C is not realistic or aligned with modern enterprise architecture; organizations often need integrated services, users, and systems, but they must integrate them securely. Segmentation allows controlled communication through firewalls, gateways, routing rules, access controls, monitoring, and filtering. The goal is not isolation for its own sake, but risk-based separation and controlled connectivity.
Therefore, option A is verified. References/Chapters: ISO/IEC 27002:2022, Control 8.20 Network security; Control 8.22 Segregation of networks; Control 5.15 Access control.


質問 # 27
Which of the following controls aims to protect the production environment and data?

  • A. Control 8.31 Separation of development, testing and operational environments
  • B. Control 5.13 Labelling of information
  • C. Control 6.6 Confidentiality or non-disclosure agreements

正解:A

解説:
Control 8.31, Separation of development, testing and operational environments, aims to protect the production environment and production data from unauthorized or inappropriate change, exposure, or disruption.
Development and testing activities often involve code changes, debugging, experimental configurations, test accounts, incomplete controls, and simulated transactions. If these activities occur directly in production, they can compromise confidentiality, integrity, and availability. Separation reduces the risk that untested software, test data, developer privileges, or debugging tools affect live systems and real business information. Control
5.13, Labelling of information, supports correct handling by communicating classification and protection needs, but it does not specifically protect production environments. Control 6.6, Confidentiality or non- disclosure agreements, supports legal and people-related confidentiality commitments, but it does not directly separate technical environments. The exam logic focuses on the control whose stated purpose is to protect production systems and data from risks introduced by development and testing. Therefore, option B is correct.
References/Chapters: ISO/IEC 27002:2022, Control 8.31 Separation of development, testing and operational environments; Control 8.32 Change management; Control 8.29 Security testing in development and acceptance.


質問 # 28
What does information security determine?

  • A. How to protect information and what to protect it from
  • B. What information needs to be protected and why it should be protected
  • C. Both A and B

正解:C

解説:
Information security determines both what needs to be protected and how protection should be applied. The first part is understanding information assets, their value, their sensitivity, their owners, their business purpose, and the consequences if they are disclosed, altered, lost, or unavailable. This answers what must be protected and why. The second part is understanding threats, vulnerabilities, risk levels, legal obligations, contractual duties, and control options. This answers what the information must be protected from and how security controls should be designed. ISO/IEC 27002 supports both dimensions. Asset inventory and classification clarify protection needs. Access control, cryptography, backup, logging, network security, secure development, incident management, and physical security define protection methods. Option A is correct but incomplete. Option B is also correct but incomplete. Option C is therefore the verified answer because information security is a complete discipline covering asset understanding, risk understanding, control selection, implementation, monitoring, and improvement. The ISO/IEC 27002 control set is structured to support that full protection lifecycle. References/Chapters: ISO/IEC 27002:2022, Control 5.9 Inventory of information and other associated assets; Control 5.12 Classification of information; Controls 5-8.


質問 # 29
Which of the following controls aims to ensure the integrity of operational systems and prevent exploitation of technical vulnerabilities?

  • A. Control 8.15 Logging
  • B. Control 8.17 Clock synchronization
  • C. Control 8.19 Installation of software on operational systems

正解:C

解説:
Control 8.19, Installation of software on operational systems, aims to ensure the integrity of operational systems and prevent exploitation of technical vulnerabilities. Software installed in production can introduce malware, insecure configurations, untested functionality, compatibility problems, unauthorized tools, or vulnerable components. ISO/IEC 27002 therefore expects installation on operational systems to be controlled, authorized, tested, and managed. This protects live systems from unauthorized or inappropriate software that could weaken security or disrupt operations. Control 8.15, Logging, records events and supports monitoring, investigation, accountability, and detection, but it does not primarily control software installation. Control
8.17, Clock synchronization, ensures consistent time settings across systems so logs, events, and transactions can be correlated accurately. It is important but not the control aimed at preventing exploitation through software installation weaknesses. The exam phrase "integrity of operational systems" is directly aligned with controlling what software is installed in production. Therefore, option A is verified. References/Chapters: ISO
/IEC 27002:2022, Control 8.19 Installation of software on operational systems; Control 8.8 Management of technical vulnerabilities; Control 8.32 Change management.


質問 # 30
Which information security principle is compromised by accidental changes in information?

  • A. Integrity
  • B. Confidentiality
  • C. Availability

正解:A

解説:
Accidental changes compromise integrity. Integrity is the property that information remains accurate, complete, and protected against unauthorized or improper modification. Even when a change is accidental rather than malicious, the effect is the same from an integrity perspective: the information may no longer be trustworthy. ISO/IEC 27002 supports integrity through many controls, including access control, change management, configuration management, backup, logging, secure coding, malware protection, segregation of duties, and separation of development, test, and production environments. Availability would be affected if information or systems were not accessible or usable when required. Confidentiality would be affected if information were disclosed or made available to unauthorized parties. The question specifically mentions accidental changes, not unavailability or disclosure, so integrity is the correct principle. This distinction is central to information security because different principles require different controls. For example, preventing accidental changes may require access restrictions, validation, change approval, version control, monitoring, and recovery procedures. References/Chapters: ISO/IEC 27002:2022, Clause 4 control attributes; Control
8.32 Change management; Control 8.9 Configuration management; Control 8.13 Information backup.


質問 # 31
What, among others, should be considered when using cryptography?

  • A. Security checkpoints in projects
  • B. Restricting and filtering systems connection to the network
  • C. The roles and responsibilities for the key management

正解:C

解説:
When using cryptography, organizations should consider roles and responsibilities for key management.
Cryptographic controls are only effective when keys are properly generated, stored, distributed, rotated, backed up, revoked, destroyed, and protected from unauthorized access. Weak key management can defeat strong algorithms because compromise of the key can expose encrypted information or allow unauthorized signing, decryption, or impersonation. ISO/IEC 27002 Control 8.24, Use of cryptography, guides organizations to define rules for effective cryptographic use, including protection of confidentiality, authenticity, integrity, and non-repudiation where relevant. Key management responsibilities must be assigned clearly so that ownership, custody, approval, recovery, and emergency access are controlled. Option B relates to project security management, not cryptographic implementation specifically. Option C relates to network security and filtering, not cryptographic key governance. Cryptography requires policy decisions about algorithms, key lengths, certificate management, lifecycle handling, legal restrictions, and separation of duties. The exam's correct answer is therefore option A because key management is a central technical and governance constraint of cryptographic protection. References/Chapters: ISO/IEC 27002:2022, Control 8.24 Use of cryptography; Control 5.15 Access control; Control 5.17 Authentication information.


質問 # 32
An organization uses an access control software that allows only authorized employees to access sensitive files. What type of control is this?

  • A. Corrective
  • B. Detective
  • C. Preventive

正解:C

解説:
Access control software that allows only authorized employees to access sensitive files is a preventive control.
Its purpose is to stop unauthorized access before it occurs by enforcing approved access rules. In ISO/IEC
27002, access control is implemented through policies, identity management, authentication, authorization, access rights review, privileged access control, and restrictions on information access. This type of software can prevent unauthorized disclosure, unauthorized modification, misuse of sensitive data, and violation of privacy or contractual obligations. It is not primarily detective because it does not merely discover an event after it has happened. It is not corrective because it does not restore damaged information or reverse the impact of an incident. Its security value is in blocking access attempts that do not meet authorization criteria.
The principle behind the control is least privilege: users should receive only the access necessary for their role and responsibilities. For sensitive files, this is especially important because confidentiality, integrity, and accountability depend on correct authorization. References/Chapters: ISO/IEC 27002:2022, Control 5.15 Access control; Control 5.16 Identity management; Control 5.18 Access rights; Control 8.3 Information access restriction.


質問 # 33
......

あなたをお手軽に合格させるISO-IEC-27002-Foundation試験正確なPDF問題:https://www.passtest.jp/PECB/ISO-IEC-27002-Foundation-shiken.html