Skip to content
CY-703 (B) · Cyber Security Policies & Standards/Important Questions

Cyber Security Policies & Standards (CY-703 (B)) - Important Questions

  1. Unit 514 Marks High Priority

    Explain Information Security standards (for example ISO/IEC 27001). Describe the key clauses, the certification process, and discuss how an organization implements these standards. Compare ISO/IEC 27001 with at least one other information security standard.

    Core topic from heatmap: Information Security Standards (ISO). Frequently asked in past papers; covers organizational implementation and comparison with other standards.

  2. Unit 214 Marks High Priority

    Describe the components of a National Cyber Security Policy. Explain how a corporate information security policy should align with and support the objectives of the national policy.

    Directly derived from heatmap and repeated past-paper pattern. Core national policy topic and corporate alignment.

  3. Unit 214 Marks High Priority

    Draw and explain the Digital Forensics Lifecycle. Discuss the major challenges in computer forensics and suggest mitigation approaches for each challenge.

    Repeated core question in past papers. Tests understanding of forensics process and practical challenges.

  4. Unit 110 Marks High Priority

    What is a Comprehensive Cyber Security Policy? Explain its objectives, scope and the key elements that must be included for a mid-sized enterprise.

    Core syllabus topic appearing frequently; assesses policy design for organizations.

  5. Unit 410 Marks High Priority

    Discuss privacy policy languages and methods for specifying privacy policies. Explain how privacy policies can be specified for the medical and financial domains with suitable examples.

    Privacy policies are repeatedly examined; includes technical languages and domain-specific specification (medical, financial).

  6. Unit 17 Marks High Priority

    Explain Cyber Crime, Cyber Terrorism and Cyber Espionage. Provide examples of each and discuss legal and organizational implications.

    Frequently asked conceptual topic covering different forms of cyber wrongdoing and their implications.

  7. Unit 57 Marks High Priority

    Explain the objectives and scope of the IT Act, 2000. Discuss its relevance to national cyber security policy and to an organization's cyber security framework.

    Statutory and policy question appearing frequently in exams; tests legal knowledge and policy relevance.

  8. Unit 410 Marks High Priority

    Explain Data Privacy Attacks with emphasis on data-linking and profiling. Describe techniques used in such attacks and outline mitigation strategies to protect personal data.

    Covers data privacy attacks and profiling; important for privacy and data protection units in syllabus.

  9. Unit 37 Marks High Priority

    Discuss organizational implications of web threats and social media risks. Describe typical attack vectors and propose security controls and policies to mitigate those risks.

    Organizational risk topic that recurs in exams; focuses on web and social media threats and mitigations.

  10. Unit 17 Marks Medium Priority

    Explain the CIA Triad (Confidentiality, Integrity, Availability). For each element of the triad, describe example controls used to ensure it in an organizational information system.

    Core foundational security concept repeatedly examined in past papers (listed in top repeated questions).

  11. Unit 57 Marks Medium Priority

    Explain Intellectual Property issues relevant to cyber security, including Patent, Copyright and Software Licensing. Discuss how IP considerations affect software development and information sharing in organizations.

    Intellectual property is part of syllabus and appears in past papers; examines legal and practical aspects for software and digital content.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in