Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27002-Foundation Exam - Topic 3 Question 8 Discussion

What is the purpose of Control 8.20 Network security of ISO/IEC 27002?
A) To protect information in networks and its supporting information processing facilities from compromise via the network
B) To ensure security in the use of network services
C) To split the network in security boundaries

PECB ISO-IEC-27002-Foundation Exam - Topic 3 Question 8 Discussion

Actual exam question for PECB's ISO-IEC-27002-Foundation exam
Question #: 8
Topic #: 3
[All ISO-IEC-27002-Foundation Questions]

What is the purpose of Control 8.20 Network security of ISO/IEC 27002?

Show Suggested Answer Hide Answer
Suggested Answer: A

The purpose of Control 8.20, Network security, is to protect information in networks and supporting information processing facilities from compromise through the network. This includes protecting data in transit, network devices, network services, communication paths, routing, management interfaces, and connected systems. Network compromise can lead to unauthorized access, interception, malware propagation, denial of service, lateral movement, data exfiltration, or manipulation of traffic. Option B relates more closely to Control 8.21, Security of network services, which addresses security mechanisms, service levels, and management requirements for network services. Option C relates to Control 8.22, Segregation of networks, which specifically concerns splitting networks into security boundaries or domains. Control 8.20 is broader: it establishes the general objective of securing networks against compromise. ISO/IEC 27002 expects organizations to manage and control networks according to risk, including architecture, monitoring, authentication, encryption where needed, device hardening, and protection of network management functions. The correct answer is therefore option A. Reference/Chapters: ISO/IEC 27002:2022, Control 8.20 Network security; Control 8.21 Security of network services; Control 8.22 Segregation of networks.


Contribute your Thoughts:

0/2000 characters
I studied this recently, and I believe the main purpose is to protect information from compromise, but I might be mixing it up with another control.
upvoted 0 times
...
Marget
5 days ago
I feel like splitting the network into security boundaries is important too, but I can't recall if that's specifically what Control 8.20 covers.
upvoted 0 times
...
Glory
10 days ago
I remember a practice question that asked about network security controls, and I think ensuring security in network services was a key point there.
upvoted 0 times
...
Cassie
15 days ago
I think Control 8.20 is mainly about protecting information in networks, but I'm not entirely sure if that's the only focus.
upvoted 0 times
...

Save Cancel