Free PECB ISO/IEC 27001 Lead Implementer practice questions

10 free PECB ISO/IEC 27001 Lead Implementer practice questions with the correct answer and a full explanation for each, taken from the CertStash pack of 285 questions. Work through them, then open each answer to check your reasoning.

Question 1

Scenario 1: HealthGenic is a pediatric clinic that monitors the health and growth of individuals from infancy to early adulthood using a web-based medical software. The software is also used to schedule appointments, create customized medical reports, store patients’ data and medical history, and communicate with all the involved parties, including parents, other physicians, and the medical laboratory staff. Last month, HealthGenic experienced a number of service interruptions due to the increased number of users accessing the software. Another issue the company faced while using the software was the complicated user interface, which the untrained personnel found challenging to use. The top management of HealthGenic immediately informed the company that had developed the software about the issue. The software company fixed the issue; however, in the process of doing so, it modified some files that comprised sensitive information related to HealthGenic’s patients. The modifications that were made resulted in incomplete and incorrect medical reports and, more importantly, invaded the patients’ privacy. Based on the scenario above, answer the following question:Which of the following indicates that the confidentiality of information was compromised?

  1. Service interruptions due to the increased number of users
  2. Invasion of patients’ privacy
  3. Modification of patients’ medical reports
Show answer and explanation

Correct answer: B. Invasion of patients’ privacy

Confidentiality is the property that information is not made available or disclosed to unauthorized individuals or entities. The scenario states that the modifications invaded the patients' privacy, which means sensitive patient information was exposed to parties who had no right to see it. That exposure is the confidentiality breach.

Why the other options are wrong

  • A. Service interruptions stop authorized users from reaching the software, which is a loss of availability.
  • C. Modified medical reports that are incomplete and incorrect describe a loss of integrity, because the accuracy and completeness of the data was destroyed.

Question 2

Based on scenario 1, what is a potential impact of the loss of integrity of information in HealthGenic?

  1. Disruption of operations and performance degradation
  2. Incomplete and incorrect medical reports
  3. Service interruptions and complicated user interface
Show answer and explanation

Correct answer: B. Incomplete and incorrect medical reports

Integrity is the property of accuracy and completeness. When the software company modified the patient files, the resulting reports were incomplete and incorrect, so the data no longer reflected reality. Clinicians acting on wrong reports is precisely the impact of an integrity failure.

Why the other options are wrong

  • A. Disruption of operations and performance degradation is what happens when a system becomes unavailable, not when data becomes inaccurate.
  • C. Service interruptions are an availability impact and a complicated user interface is a usability weakness, so neither describes integrity.

Question 3

Intrinsic vulnerabilities, such as the _____________, are related to the characteristics of the asset. Refer to scenario 1.

  1. Software malfunction
  2. Service interruptions
  3. Complicated user interface
Show answer and explanation

Correct answer: C. Complicated user interface

An intrinsic vulnerability is a weakness that belongs to the asset itself, as opposed to an extrinsic one that comes from the environment around it. The asset here is the medical software, and the complicated user interface is a characteristic built into that software, so it is intrinsic.

Why the other options are wrong

  • A. A software malfunction is an event that occurs rather than a standing characteristic of the asset.
  • B. Service interruptions are a consequence that was suffered, so they are an impact rather than a vulnerability of the asset.

Question 4

Which situation described in scenario 1 represents a threat to HealthGenic?

  1. HealthGenic did not train its personnel to use the software
  2. The software company modified information related to HealthGenic’s patients
  3. HealthGenic used a web-based medical software for storing patients' confidential information
Show answer and explanation

Correct answer: B. The software company modified information related to HealthGenic’s patients

HealthGenic's patients A threat is a potential cause of an unwanted incident that may result in harm to a system or organization, and it can originate either inside or outside the organization. The software company modifying information belonging to HealthGenic's patients is an action by a third party that harmed the asset, which is exactly what a threat is.

Why the other options are wrong

  • A. Failing to train personnel is an absence of a control, so it is a vulnerability that a threat could exploit.
  • C. Choosing to use web-based software is a business decision that creates exposure, so it describes the context and the vulnerability rather than the threat itself.

Question 5

In scenario 1, HealthGenic experienced a number of service interruptions due to the loss of functionality of the software.

Which principle of information security has been affected in this case?

  1. Availability
  2. Confidentiality
  3. Integrity
Show answer and explanation

Correct answer: A. Availability

Availability is the property of being accessible and usable on demand by an authorized entity. Service interruptions caused by a loss of software functionality mean authorized users could not reach the system when they needed it, so availability was affected.

Why the other options are wrong

  • B. Confidentiality concerns disclosure to unauthorized parties, and nothing in this part of the scenario was disclosed.
  • C. Integrity concerns accuracy and completeness, and an interruption does not by itself alter any data.

Question 6

Scenario 2: Beauty is a cosmetics company that has recently switched to an -ommerce model, leaving the traditional retail. The top management has decided to build their own custom platform in-house and outsource the payment process to an external provider operating online payments systems that support online money transfers. Due to this transformation of the business model, a number of security controls were implemented based on the identified threats and vulnerabilities associated to critical assets. To protect customers’ information. Beauty’s employees had to sign a confidentiality agreement. In addition, the company reviewed all user access rights so that only authorized personnel can have access to sensitive files and drafted a new segregation of duties chart. However, the transition was difficult for the IT team, who had to deal with a security incident not long after transitioning to the e-commerce model. After investigating the incident, the team concluded that due to the out-of-date ant-alware software, an attacker gained access to their files and exposed customers’ information, including their names and home addresses. The IT team decided to stop using the old anti-malware software and install a new one which would automatically remove malicious code in case of similar incidents. The new software was installed in every workstation within the company. After installing the new software, the team updated it with the latest malware definitions and enabled the automatic update feature to keep it up to date at all times. Additionally, they established an authentication process that requires a user identification and password when accessing sensitive information. In addition, Beauty conducted a number of information security awareness sessions for the IT team and other employees that have access to confidential information in order to raise awareness on the importance of system and network security. Based on the scenario above, answer the following question:After investigating the incident. Beauty decided to install a new anti-malware software.

What type of security control has been implemented in this case?

  1. Preventive
  2. Detective
  3. Corrective
Show answer and explanation

Correct answer: C. Corrective

Controls are classified by when they act relative to an incident. Beauty installed the new anti-malware only after investigating an incident that had already happened, and its stated function is to remove malicious code once it is present. Acting after the event to limit and repair the damage makes it a corrective control.

Why the other options are wrong

  • A. A preventive control is put in place to stop an incident before it happens, whereas this was a response to one that already occurred.
  • B. A detective control identifies that an incident is occurring, but this software goes further and removes the malicious code.

Question 7

Which statement below suggests that Beauty has implemented a managerial control that helps avoid the occurrence of incidents? Refer to scenario 2.

  1. Beauty’s employees signed a confidentiality agreement
  2. Beauty conducted a number of information security awareness sessions for the IT team and other employees that have access to confidential information
  3. Beauty updated the segregation of duties chart
Show answer and explanation

Correct answer: B. Beauty conducted a number of information security awareness sessions for the IT team and other employees that have access to confidential information

Managerial controls, sometimes called administrative controls, are those exercised through the management of people and processes, and they include training, awareness, management reviews and internal audits. The awareness sessions Beauty ran for its staff are a management action intended to stop incidents occurring, so they are the managerial preventive control described.

Why the other options are wrong

  • A. A confidentiality agreement is enforced through contract law, so it is classified as a legal control.
  • C. The scenario states that a new segregation of duties chart was drafted after the access rights review, not updated, so this statement does not match what Beauty did.

Question 8

According to scenario 2, Beauty has reviewed all user access rights.

What type of control is this?

  1. Detective and administrative
  2. Corrective and managerial
  3. Legal and technical
Show answer and explanation

Correct answer: A. Detective and administrative

A review of user access rights looks back over the rights that already exist in order to find and identify ones that should not be there, which is the definition of a detective control. It is carried out through management process and personnel rather than through technology, so it is also an administrative control.

Why the other options are wrong

  • B. A corrective control repairs damage or restores a system after an incident, while this review only identifies inappropriate rights and does not fix anything itself.
  • C. A legal control derives its force from law or contract, and a technical control is enforced by technology, but a management review of rights is neither.

Question 9

Based on scenario 2. Beauty should have implemented (1) ______________________ to detect (2) ______________________.

  1. (1) An access control software, (2) patches
  2. (1) Network intrusions, (2) technical vulnerabilities
  3. (1) An intrusion detection system, (2) intrusions on networks
Show answer and explanation

Correct answer: C. (1) An intrusion detection system, (2) intrusions on networks

The sentence has to hold together as a control and the thing that control detects. An intrusion detection system exists precisely to monitor a network and identify intrusions on it, so it is the only pairing where the second half is genuinely what the first half detects.

Why the other options are wrong

  • A. Access control software restricts who may reach a resource, and it does not detect patches. Patches are applied rather than detected.
  • B. Network intrusions are an event rather than a control, so the first blank would contain the thing being detected instead of the mechanism doing the detecting.

Question 10

Based on scenario 2, which information security principle is the IT team aiming to ensure by establishing a user authentication process that requires user identification and password when accessing sensitive information?

  1. Integrity
  2. Confidentiality
  3. Availability
Show answer and explanation

Correct answer: B. Confidentiality

Requiring a user identification and a password before sensitive information can be reached ensures that only people who can prove who they are may see that information. Restricting disclosure to authorized users is the definition of confidentiality.

Why the other options are wrong

  • A. Integrity concerns keeping data accurate and complete, which authentication does not by itself achieve.
  • C. Availability concerns access on demand, and adding an authentication step restricts access rather than assuring it.

That was 10 of 285.

The full PECB ISO/IEC 27001 Lead Implementer pack has all 285 questions, each with the answer, the explanation and why the other options are wrong, plus a questions-only copy for timed runs. US$39, paid once, with free monthly updates and a pass-or-your-money-back guarantee.

Get the full pack