Skip to content
CY-703 (B) · Cyber Security Policies & Standards/Important Questions

Cyber Security Policies & Standards (CY-703 (B)) - Important Questions

  1. Unit 57 Marks Medium Priority

    Explain the CIA Triad and discuss controls used to ensure confidentiality, integrity and availability.

    Core conceptual question frequently asked to test fundamentals of confidentiality, integrity and availability.

  2. Unit 510 Marks Medium Priority

    Draw and explain the Digital Forensics Lifecycle and discuss challenges in computer forensics.

    Standard examination question on forensic process and practical challenges in computer forensics.

  3. Unit 510 Marks High Priority

    Explain the objectives and scope of the IT Act, 2000 and its relevance to cyber security policy.

    Core statutory question from Unit 5; directly tests understanding of the IT Act and its policy relevance.

  4. Unit 514 Marks Medium Priority

    Describe the components of a National Cyber Security Policy and how a corporate information security policy should align with it.

    Policy-design question that links national strategy to corporate policy; seen repeatedly in past papers.

  5. Unit 514 Marks High Priority

    Explain Information Security Standards: Describe ISO/IEC 27001 and ISO/IEC 27002 — their scope, structure, key clauses(controls) and the role of Statement of Applicability in an ISMS.

    High-frequency technical standards question covering the core ISO/IEC 27000 series and ISMS concepts.

  6. Unit 510 Marks High Priority

    Discuss the implementation steps for ISO/IEC 27001 certification, including risk assessment, preparation of Statement of Applicability, control implementation and continual improvement (Plan-Do-Check-Act).

    Practical question on certification lifecycle and implementation steps for ISO/IEC 27001 often expected in exams.

  7. Unit 510 Marks Medium Priority

    Intellectual Property Issues: Explain the differences between patent, copyright and software license. Discuss common software licensing models (proprietary, GPL, LGPL, MIT) and enforcement challenges.

    Core Intellectual Property topic in Unit 5 testing distinctions and licensing models relevant to software.

  8. Unit 514 Marks High Priority

    Discuss key provisions and cybercrime offences under the IT Act, 2000 with mention of relevant sections (for example, sections dealing with unauthorised access, data theft, tampering, and privacy breaches).

    Detailed statutory question expected in exams to test knowledge of specific cyber offences and relevant sections.

  9. Unit 57 Marks Medium Priority

    Discuss privacy policy languages and how privacy policies can be specified for medical and financial domains.

    Domain-specific privacy policy question taken from analytics; tests specification and application of privacy policies.

  10. Unit 57 Marks High Priority

    Discuss the role of standards bodies (ISO, IEC, IEEE, NIST) in cyber security and compare ISO/IEC 27000 series with NIST SP 800-series in terms of scope and use by organisations.

    Standards comparison question to test breadth of knowledge about international standards bodies and major frameworks.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in