Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70special

APMG-International ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Exam Practice Test

ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$37.5  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$33  $109.99
Question 1

What international standard provides guidance on the integration of ISO/IEC 27001 and the IT Service Management standard?

Options:

A.

ISO/IEC 27002

B.

ISO/IEC 27013

C.

ISO/IEC 20000-1

D.

None of the above

Question 2

When are the information security policies required to be reviewed, according to the Policies for information security control?

Options:

A.

Every six months

B.

Annually

C.

According to a schedule defined by the Certification Body

D.

At planned intervals and if significant changes occur

Question 3

What activity is done first when preparing for an initial certification audit?

Options:

A.

Agree the scope of the ISMS with the Certification Body auditor

B.

Provide documents to the Certification Body auditor for the Stage 1 audit

C.

Provide evidence that nonconformities from an internal audit have been actioned

D.

Provide records to the Certification Body auditor for the Stage 2 audit

Question 4

Which item is required to be defined when planning the organization's risk assessment process?

Options:

A.

The parts of the ISMS scope which are excluded from the risk assessment

B.

How the effectiveness of the method will be measured

C.

The criteria for acceptable levels of risk

D.

There are NO specific information requirements

Question 5

Which trend in information security performance is required to be considered during a management review of the ISMS?

Options:

A.

Achievement of information security objectives

B.

Validity of information continuity controls

C.

Relevant external and internal requirements changes

D.

Decisions related to continual improvement opportunities

Question 6

Identify the missing word in the following sentence.

According to ISO/IEC 27000, the definition of risk [?] is a “process to comprehend the nature of risk and to determine the level of risk.”

Options:

A.

Evaluation

B.

Analysis

C.

Assessment

D.

Management

Question 7

Which action is a required response to an identified residual risk?

Options:

A.

By default, it shall be controlled by information security awareness and training

B.

Top management shall delegate its treatment to risk owners

C.

It shall be reviewed by the risk owner to consider acceptance

D.

The organization shall change practices to avoid the risk occurring

Question 8

Which statement describes Annex A of ISO/IEC 27001?

Options:

A.

Defines the criteria for accepting risks

B.

Provides a reference list of information security controls and their requirements

C.

Defines a mandatory list of controls that shall be implemented

D.

Provides measures to determine risk treatment effectiveness

Question 9

Identify the missing word(s) in the following sentence.

“Information security, cybersecurity and privacy protection – [ ? ]” is the title of ISO/IEC 27005.

Options:

A.

Guidelines for information security management systems auditing

B.

Information security management systems – Requirements

C.

Guidance on managing information security risks

D.

Information security controls

Question 10

Which statement describes a purpose of monitoring, measurement, analysis and evaluation according to ISO/IEC 27001?

Options:

A.

To evaluate information security performance

B.

To ensure that employees and contractors are competent

C.

To monitor the use of information assets

D.

To track the use of outsourced processes

Question 11

What is required to be reported by the Information security event reporting control?

Options:

A.

Information disclosure

B.

Unauthorized access

C.

Asset disposal

D.

Observed or suspected events

Question 12

Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?

Options:

A.

Identify products which could be used in the organization to improve ISMS performance and effectiveness

B.

Ensure all personnel are trained to ISO/IEC 27001 Foundation level

C.

Ensure that the controls for compliance with legal and contractual requirements are implemented

D.

Hold up-to-date records on training, skills, experience and qualifications

Question 13

Which ISMS documentation is part of the minimum scope of documented information required to be managed and controlled?

Options:

A.

Records of management decisions related to continual improvement

B.

Third party information security awareness materials

C.

The budget assigned to operate the ISMS and its related allocations

D.

A statement of correspondence between other ISO standards and the ISMS

Question 14

In an audit, what is the definition of an observation?

Options:

A.

A non-fulfilment of a requirement of ISO/IEC 27001

B.

A conformity to the standard where there is an opportunity for improvement

C.

An issue excluded from the scope of the standard

D.

An issue raised by an interested party

Question 15

Which item is required to be included in an information security policy?

Options:

A.

A commitment to satisfy applicable requirements related to information security

B.

A plan for the continual improvement of the information security management system

C.

A framework enabling concerns with the information security policy to be addressed

D.

A Statement of Applicability which defines the necessary controls to be implemented