ISO/IEC 27040:2015 - Storage Security Foundation Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

An enterprise is developing its storage security framework, aiming to align with ISO/IEC 27040:2015. They have decided to implement a tiered storage approach, categorizing data based on its sensitivity and regulatory compliance requirements. Highly sensitive customer financial records will reside on a highly secured, encrypted storage tier with strict access controls, while less critical internal operational logs will be placed on a more accessible, less protected tier. What is the fundamental security principle guiding this data segregation strategy within the context of ISO/IEC 27040:2015?

Applying security controls commensurate with the risk and value of the data asset.
Ensuring all data is subject to the highest level of encryption regardless of classification.
Prioritizing storage availability over data confidentiality for all data types.
Implementing a single, uniform security policy across all storage media.

About the ISO/IEC 27040:2015 - Storage Security Foundation Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27040:2015 - Storage Security Foundation exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.