Pre-Summer Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: best70

ISO-IEC-27002-Foundation ISO/IEC 27002 Foundation Exam Questions and Answers

Questions 4

An organization has set up a fire alarm. What type of control is this?

Options:

A.

Corrective and managerial

B.

Detective and technical

C.

Preventive and legal

Buy Now
Questions 5

An organization uses an access control software that allows only authorized employees to access sensitive files. What type of control is this?

Options:

A.

Detective

B.

Corrective

C.

Preventive

Buy Now
Questions 6

Which of the following controls should the organization implement to ensure that its approach to managing information security continues to be suitable, adequate and effective?

Options:

A.

Control 5.4 Management responsibilities

B.

Control 5.35 Independent review of information security

C.

Control 5.24 Information security incident management planning and preparation

Buy Now
Questions 7

What is continual improvement?

Options:

A.

The process of increasing the effectiveness and efficiency of the organization to fulfill its policy and objectives

B.

A method of examining the nature of something or of determining its essential features and their relations

C.

The action taken to eliminate a detected nonconformity

Buy Now
Questions 8

Which statement below describes the principle of confidentiality?

Options:

A.

Property that information is not made available or disclosed to unauthorized individuals, entities, or processes

B.

Property of accuracy and completeness

C.

Property of being accessible and usable upon demand by an authorized entity

Buy Now
Questions 9

What should be considered, among others, when establishing a remote working policy?

Options:

A.

The threat of unauthorized access to information or resources from other persons in public places

B.

The positioning of information processing facilities handling sensitive data

C.

The maintenance of authorization process and record of all privileges allocated

Buy Now
Questions 10

Why should an organization integrate information security into project management?

Options:

A.

To ensure the effective application of ISO/IEC 27001 principles related to projects and deliverables

B.

To ensure information security audits on the project and deliverables are regularly conducted

C.

To ensure information security risks related to projects and deliverables are effectively addressed

Buy Now
Questions 11

What is risk assessment?

Options:

A.

The process of finding, recognizing, and describing risks

B.

The process to comprehend the nature of risk and to determine the level of risk

C.

The overall process of risk identification, risk analysis, and risk evaluation

Buy Now
Questions 12

What should an organization do if it detects a vulnerability that does not have a corresponding threat?

Options:

A.

Recognize the vulnerability

B.

Both A and C

C.

Monitor the vulnerability for changes

Buy Now
Exam Name: ISO/IEC 27002 Foundation Exam
Last Update: May 8, 2026
Questions: 40

PDF + Testing Engine

$134.99

Testing Engine

$99.99

PDF (Q&A)

$84.99