nerdexam
(ISC)2

CCSP · Question #838

Which of the following best describes the purpose and scope of ISO/IEC 27034-1?

The correct answer is D. Provides an overview of application security that introduces definitive concepts, principles, and. The question asks to identify the primary focus and scope of the ISO/IEC 27034-1 standard.

Submitted by rania.sa· Apr 18, 2026Cloud Application Security

Question

Which of the following best describes the purpose and scope of ISO/IEC 27034-1?

Options

  • ADescribes international privacy standards for cloud computing
  • BServes as a newer replacement for NIST 800-52 r4
  • CProvides on overview of network and infrastructure security designed to secure cloud
  • DProvides an overview of application security that introduces definitive concepts, principles, and

How the community answered

(60 responses)
  • A
    3% (2)
  • B
    2% (1)
  • D
    95% (57)

Why each option

The question asks to identify the primary focus and scope of the ISO/IEC 27034-1 standard.

ADescribes international privacy standards for cloud computing

ISO/IEC 27034-1 does not primarily describe international privacy standards for cloud computing; other standards like ISO/IEC 27017 or 27018 address those areas.

BServes as a newer replacement for NIST 800-52 r4

ISO/IEC 27034-1 is an international standard focused on application security, unrelated to NIST 800-52 r4 which is a NIST publication on guidance for cloud computing security.

CProvides on overview of network and infrastructure security designed to secure cloud

While application security is part of overall IT security, ISO/IEC 27034-1 does not primarily provide an overview of network and infrastructure security; its scope is specifically application security.

DProvides an overview of application security that introduces definitive concepts, principles, andCorrect

D is correct because ISO/IEC 27034-1 specifically focuses on application security, providing an overview of concepts, principles, and processes for integrating security into the application lifecycle. It aims to ensure information security throughout the software development process.

Concept tested: ISO/IEC 27034-1 application security overview

Source: https://www.iso.org/standard/45170.html

Topics

#ISO/IEC 27034-1#Application Security#Security Standards

Community Discussion

No community discussion yet for this question.

Full CCSP Practice