Here are all the actual test exam dumps for IT exams. Most people prepare for the actual exams with our test dumps to pass their exams. So it's critical to choose and actual test pdf to succeed.

Exam ISO-IEC-27001-Lead-Implementer Topic 5 Question 162 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Implementer exam
Question #: 162
Topic #: 5
Scenario 1: NobleFind is an online retailer specializing in high-end, custom-design furniture. The company offers a wide range of handcrafted pieces tailored to meet the needs of residential and commercial clients.
NobleFind also provides expert design consultation services. Despite NobleFind's efforts to keep its online shop platform secure, the company faced persistent issues, including a recent data breach. These ongoing challenges disrupted normal operations and underscored the need for enhanced security measures. The designated IT team quickly responded to resolve the problem. To address these issues, NobleFind decided to implement an Information Security Management System (ISMS) based on ISO/IEC 27001 to improve security, protect customer data, and ensure the stability of its services.
In addition to its commitment to information security, NobleFind focuses on maintaining the accuracy and completeness of its product data. This is ensured by carefully managing version control, checking information regularly, enforcing strict access policies, and implementing backup procedures. Moreover, product details and customer designs are accessible only to authorized individuals, with security measures such as multi- factor authentication and data access policies.
NobleFind has implemented an incident investigation process within its ISMS, as part of its comprehensive approach to information security. Additionally, it has established record retention policies to ensure that online information about each product and client information remains readily accessible and usable on demand for authorized entities. NobleFind established an information security policy offering clear guidelines for safeguarding historical data. It also insisted that personnel sign confidentiality agreements and were committed to recruiting only qualified individuals. Additionally, NobleFind implemented measures for monitoring the resources used by its systems, reviewing user access rights, and conducting a thorough analysis of audit logs to swiftly identify and address any security anomalies.
With its ISMS in place, NobleFind maintains and safeguards documented information, encompassing a wide range of data, records, and specifications. This documented information is vital to its operations, ensuring the security and integrity of customer data, historical records, and financial information.
Based on the scenario above, answer the following question.
Which information security principle was impacted during the service interruption that NobleFind experienced?

Suggested Answer: C Vote an answer

The principle that was impacted during the service interruption at NobleFind is Availability.
According to ISO/IEC 27001:2022, information security is built upon three core principles, known as the CIA Triad:
Confidentiality: Ensuring that information is accessible only to those authorized to have access.
Integrity: Safeguarding the accuracy and completeness of information and processing methods.
Availability: Ensuring that authorized users have access to information and associated assets when required.
A service interruption directly affects the availability of information and services. This is explicitly supported by ISO/IEC 27001:2022 in Annex A, control A.8.14 "Redundancy of information processing facilities," which emphasizes the need to ensure that information and assets are available when needed. Moreover, Clause 6.1.2(c)1 of ISO/IEC 27001:2022 highlights the necessity to identify risks associated with the loss of confidentiality, integrity, and availability within the scope of the ISMS. A disruption in the normal operation, such as the service interruption faced by NobleFind, constitutes a breach of the availability principle.
Reference Extracts:
"apply the information security risk assessment process to identify risks associated with the loss of confidentiality, integrity and availability for information within the scope of the information security management system..."- ISO/IEC 27001:2022, Clause 6.1.2 (c)1.
"availability: property of being accessible and usable upon demand by an authorized entity"- ISO/IEC
27000:2018, 3.7 (as referenced in ISO/IEC 27001:2022, Section 3 Terms and definitions).
"A disruption is an incident... that causes an unplanned negative deviation from the expected delivery of products and services according to an organization's objectives."- ISO/IEC 27002:2022, 3.1.9 Disruption.
A service interruption that affects customer access or company operations is thus a classic example of an availability incident.
References:
ISO/IEC 27001:2022, Clause 6.1.2(c)1
ISO/IEC 27001:2022, Section 3 Terms and Definitions
ISO/IEC 27002:2022, 3.1.9 Disruption
ISO/IEC 27000:2018 (vocabulary referenced by ISO/IEC 27001:2022)

by Elvira at Jul 23, 2026, 12:57 PM

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Nick name: Submit Cancel
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.