Weekend Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Questions 4

Which benefit is NOT relevant by implementing an ISMS for an organization?

Options:

A.

Information security compliance will increase stakeholder trust in the organization

B.

Information security staff will be qualified to ISO/IEC 27001 Foundation level

C.

Information security controls are tailored to suit the organization's specific circumstances

D.

Information security risks are assessed and the probability and/or impact reduced

Buy Now
Questions 5

Which statement describes the control for the Compliance with policies, rules and standards for information security within Annex A of ISO/IEC 27001?

Options:

A.

Regular review of compliance

B.

Regular review of contractual compliance

C.

Maintain contact with legal authorities

D.

Return assets to their legal owners

Buy Now
Questions 6

Which statement about the conduct of audits is true?

Options:

A.

Third party audits are conducted by a customer of the organization

B.

The certificate issued after a successful re-certification audit in typical schemes lasts for one year

C.

One of the focus areas for a surveillance audit is the output from internal audits and management reviews

D.

During Stage 1 of a certification audit, evidence is collected by observing activities

Buy Now
Questions 7

Which statement describes Annex A of ISO/IEC 27001?

Options:

A.

Defines the criteria for accepting risks

B.

Provides a reference list of information security controls and their requirements

C.

Defines a mandatory list of controls that shall be implemented

D.

Provides measures to determine risk treatment effectiveness

Buy Now
Questions 8

What is the definition of the term ‘integrity’ according to ISO/IEC 27000?

Options:

A.

The property of being accessible and usable

B.

The property that information is NOT made available inappropriately

C.

The property of accuracy and completeness

D.

The property of availability and confidentiality

Buy Now
Questions 9

Which factor is required to be determined when understanding the organization and its context?

Options:

A.

Internal issues affecting the purpose of the ISMS

B.

The information security objectives relevant to the ISMS

C.

The processes that will be required to operate the ISMS

D.

The ISO/IEC 27001 clauses which apply to the management system

Buy Now
Questions 10

What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?

Options:

A.

Information security event reporting

B.

Information security event management

C.

Response to information security events

D.

Reporting information security incidents

Buy Now
Questions 11

Which trend in information security performance is required to be considered during a management review of the ISMS?

Options:

A.

Achievement of information security objectives

B.

Validity of information continuity controls

C.

Relevant external and internal requirements changes

D.

Decisions related to continual improvement opportunities

Buy Now
Questions 12

Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?

Options:

A.

Identify products which could be used in the organization to improve ISMS performance and effectiveness

B.

Ensure all personnel are trained to ISO/IEC 27001 Foundation level

C.

Ensure that the controls for compliance with legal and contractual requirements are implemented

D.

Hold up-to-date records on training, skills, experience and qualifications

Buy Now
Questions 13

Identify the missing word in the following sentence.

The organization shall determine the [ ? ] of interested parties relevant to information security.

Options:

A.

requirements

B.

number

C.

structure

D.

influence

Buy Now
Questions 14

Identify the missing word(s) in the following sentence.

“Information security, cybersecurity and privacy protection – [ ? ]” is the title of ISO/IEC 27005.

Options:

A.

Guidelines for information security management systems auditing

B.

Information security management systems – Requirements

C.

Guidance on managing information security risks

D.

Information security controls

Buy Now
Questions 15

Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC 27002 is true?

    ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC 27001 information security risk management process

    ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001

Options:

A.

Only 1 is true

B.

Only 2 is true

C.

Both 1 and 2 are true

D.

Neither 1 or 2 is true

Buy Now
Exam Name: ISO/IEC 27001 (2022) Foundation Exam
Last Update: Oct 5, 2025
Questions: 50

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99