Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: clap70

ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Questions 4

Which statement describes the Classification of information control in Annex A of ISO/IEC 27001?

Options:

A.

Ensures that all information assets are labelled with their classification

B.

Ensures that information is classified based on confidentiality, integrity and availability

C.

Ensures that security perimeters are used to protect assets

D.

Ensures the rules to control physical and logical access apply to assets

Buy Now
Questions 5

Identify the missing word in the following sentence.

According to ISO/IEC 27000, the definition of risk [?] is a “process to comprehend the nature of risk and to determine the level of risk.”

Options:

A.

Evaluation

B.

Analysis

C.

Assessment

D.

Management

Buy Now
Questions 6

Which item is required to be considered when defining the scope and boundaries of the information security management system?

Options:

A.

The dependencies between activities performed by the organization

B.

The level of quality to which the ISMS must adhere

C.

The lessons learned from the information security experiences of other organizations

D.

The regular activities necessary to maintain and improve the ISMS

Buy Now
Questions 7

Which item is required to be defined when planning the organization's risk assessment process?

Options:

A.

The parts of the ISMS scope which are excluded from the risk assessment

B.

How the effectiveness of the method will be measured

C.

The criteria for acceptable levels of risk

D.

There are NO specific information requirements

Buy Now
Questions 8

Who is required to ensure that staff are supported so that they can contribute to the information security management system?

Options:

A.

Top management of the organization

B.

Management responsible for each area of operation

C.

Auditors who audit each area of operation

D.

ISO/IEC 27001 practitioners within the organization

Buy Now
Questions 9

When are the information security policies required to be reviewed, according to the Policies for information security control?

Options:

A.

Every six months

B.

Annually

C.

According to a schedule defined by the Certification Body

D.

At planned intervals and if significant changes occur

Buy Now
Questions 10

Which aspect of ISO/IEC 27001 requires that contractors know about the organization’s information security policies?

Options:

A.

Nonconformity and corrective action

B.

Competence

C.

Communication

D.

Awareness

Buy Now
Questions 11

Which factor is required to be determined when understanding the organization and its context?

Options:

A.

Internal issues affecting the purpose of the ISMS

B.

The information security objectives relevant to the ISMS

C.

The processes that will be required to operate the ISMS

D.

The ISO/IEC 27001 clauses which apply to the management system

Buy Now
Questions 12

In which clause would the requirements for internal audit be found?

Options:

A.

Planning

B.

Operation

C.

Performance Evaluation

D.

Improvement

Buy Now
Questions 13

Which action is a required response to an identified residual risk?

Options:

A.

By default, it shall be controlled by information security awareness and training

B.

Top management shall delegate its treatment to risk owners

C.

It shall be reviewed by the risk owner to consider acceptance

D.

The organization shall change practices to avoid the risk occurring

Buy Now
Questions 14

Which trend in information security performance is required to be considered during a management review of the ISMS?

Options:

A.

Achievement of information security objectives

B.

Validity of information continuity controls

C.

Relevant external and internal requirements changes

D.

Decisions related to continual improvement opportunities

Buy Now
Questions 15

Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC 27002 is true?

    ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC 27001 information security risk management process

    ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001

Options:

A.

Only 1 is true

B.

Only 2 is true

C.

Both 1 and 2 are true

D.

Neither 1 or 2 is true

Buy Now
Exam Name: ISO/IEC 27001 (2022) Foundation Exam
Last Update: Oct 4, 2025
Questions: 50
ISO-IEC-27001-Foundation pdf

ISO-IEC-27001-Foundation PDF

$25.5  $84.99
ISO-IEC-27001-Foundation Engine

ISO-IEC-27001-Foundation Testing Engine

$30  $99.99
ISO-IEC-27001-Foundation PDF + Engine

ISO-IEC-27001-Foundation PDF + Testing Engine

$40.5  $134.99