Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27002-Foundation Exam - Topic 1 Question 11 Discussion

Some employees of an organization find the data processing procedures complicated and have been struggling to follow them effectively. Which of the following threats is the organization facing in this case?
A) Data input error by employees
B) Hacking
C) Information theft

PECB ISO-IEC-27002-Foundation Exam - Topic 1 Question 11 Discussion

Actual exam question for PECB's ISO-IEC-27002-Foundation exam
Question #: 11
Topic #: 1
[All ISO-IEC-27002-Foundation Questions]

Some employees of an organization find the data processing procedures complicated and have been struggling to follow them effectively. Which of the following threats is the organization facing in this case?

Show Suggested Answer Hide Answer
Suggested Answer: A

The situation describes a people-related operational threat: data input error by employees. The root cause is not a malicious external attack or theft; it is that employees cannot reliably follow complicated processing procedures. ISO/IEC 27002 recognizes that people, competence, awareness, and documented procedures are essential to information security. When procedures are unclear, excessive, or difficult to follow, employees may enter incorrect data, omit fields, select wrong categories, mishandle classifications, misroute information, or unintentionally corrupt records. This primarily threatens integrity because the information may no longer be accurate or complete. Hacking would involve unauthorized technical intrusion, and information theft would involve intentional unauthorized taking or disclosure of information. Neither is stated in the scenario. ISO/IEC 27002 addresses this type of risk through information security awareness, education and training, documented operating procedures, clear responsibilities, and appropriate segregation of duties. Effective controls should make correct behavior practical and repeatable, not merely documented. Therefore, the verified answer is option A. Reference/Chapters: ISO/IEC 27002:2022, Control 6.3 Information security awareness, education and training; Control 5.37 Documented operating procedures; Control 5.3 Segregation of duties.


Contribute your Thoughts:

0/2000 characters
Nobuko
4 days ago
This reminds me of a practice question where we talked about user errors in data entry. A seems to fit here.
upvoted 0 times
...
Darci
9 days ago
I'm not entirely sure, but I feel like hacking and information theft are more about external threats rather than employee struggles.
upvoted 0 times
...
Vicky
14 days ago
I remember discussing how complicated procedures can lead to data input errors, so I think A might be the right choice.
upvoted 0 times
...

Save Cancel