Weekend Sale Limited Time Flat 70% Discount offer - Ends in 0d 00h 00m 00s - Coupon code: 70spcl

APMG-International ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Exam Practice Test

Page: 1 / 5
Total 50 questions

ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Question 1

What is a requirement for a corrective action made in response to a nonconformity?

Options:

A.

They are proportionate to the likelihood of the nonconformity recurring

B.

They are appropriate to the effects of the nonconformity

C.

They do NOT change the organization's information security policies

D.

They always eliminate the cause of the nonconformity

Question 2

Which statement describes the Classification of information control in Annex A of ISO/IEC 27001?

Options:

A.

Ensures that all information assets are labelled with their classification

B.

Ensures that information is classified based on confidentiality, integrity and availability

C.

Ensures that security perimeters are used to protect assets

D.

Ensures the rules to control physical and logical access apply to assets

Question 3

Which statement describes a requirement for information security objectives?

Options:

A.

They shall be consistent with the information security policy

B.

They shall all be measurable

C.

They shall be contractually transferred to third parties

D.

They shall be reviewed at least annually

Question 4

Which ISMS documentation is part of the minimum scope of documented information required to be managed and controlled?

Options:

A.

Records of management decisions related to continual improvement

B.

Third party information security awareness materials

C.

The budget assigned to operate the ISMS and its related allocations

D.

A statement of correspondence between other ISO standards and the ISMS

Question 5

Which aspect of ISO/IEC 27001 requires that contractors know about the organization’s information security policies?

Options:

A.

Nonconformity and corrective action

B.

Competence

C.

Communication

D.

Awareness

Question 6

Which factor is required to be determined when understanding the organization and its context?

Options:

A.

Internal issues affecting the purpose of the ISMS

B.

The information security objectives relevant to the ISMS

C.

The processes that will be required to operate the ISMS

D.

The ISO/IEC 27001 clauses which apply to the management system

Question 7

Identify the missing word in the following sentence.

The organization shall determine the [ ? ] of interested parties relevant to information security.

Options:

A.

requirements

B.

number

C.

structure

D.

influence

Question 8

Which is a control title within Annex A of ISO/IEC 27001?

Options:

A.

Information security in supplier relationships

B.

Responsibilities and procedures

C.

Protection of documents

D.

Change control

Question 9

Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC 27002 is true?

    ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC 27001 information security risk management process

    ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001

Options:

A.

Only 1 is true

B.

Only 2 is true

C.

Both 1 and 2 are true

D.

Neither 1 or 2 is true

Question 10

Which benefit is NOT relevant by implementing an ISMS for an organization?

Options:

A.

Information security compliance will increase stakeholder trust in the organization

B.

Information security staff will be qualified to ISO/IEC 27001 Foundation level

C.

Information security controls are tailored to suit the organization's specific circumstances

D.

Information security risks are assessed and the probability and/or impact reduced

Question 11

Which International Standard can be used to implement an integrated management system with ISO/IEC 27001?

Options:

A.

ISO/IEC 27003

B.

ISO/IEC 27013

C.

ISO 9001

D.

None of the above

Question 12

When are the information security policies required to be reviewed, according to the Policies for information security control?

Options:

A.

Every six months

B.

Annually

C.

According to a schedule defined by the Certification Body

D.

At planned intervals and if significant changes occur

Question 13

What is the definition of the term ‘integrity’ according to ISO/IEC 27000?

Options:

A.

The property of being accessible and usable

B.

The property that information is NOT made available inappropriately

C.

The property of accuracy and completeness

D.

The property of availability and confidentiality

Question 14

To whom are the information security policies required to be communicated, according to the control in Annex A of ISO/IEC 27001?

Options:

A.

Top management

B.

Only staff with accountability for ISMS operation

C.

Employees within the scope of the ISMS

D.

Relevant personnel and relevant interested parties

Question 15

Which item is required to be considered when defining the scope and boundaries of the information security management system?

Options:

A.

The dependencies between activities performed by the organization

B.

The level of quality to which the ISMS must adhere

C.

The lessons learned from the information security experiences of other organizations

D.

The regular activities necessary to maintain and improve the ISMS

Page: 1 / 5
Total 50 questions