Weekend Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Questions 4

Which aspect of ISO/IEC 27001 requires that contractors know about the organization’s information security policies?

Options:

A.

Nonconformity and corrective action

B.

Competence

C.

Communication

D.

Awareness

Buy Now
Questions 5

What is the definition of the term ‘integrity’ according to ISO/IEC 27000?

Options:

A.

The property of being accessible and usable

B.

The property that information is NOT made available inappropriately

C.

The property of accuracy and completeness

D.

The property of availability and confidentiality

Buy Now
Questions 6

What is the definition of a threat according to ISO/IEC 27000?

Options:

A.

A potential cause of an unwanted incident which can result in harm to a system or organization

B.

A single or a series of unwanted or unexpected information security events

C.

A weakness of an asset or a control that can be exploited

D.

The risk remaining after risk treatment

Buy Now
Questions 7

Which of the following is required to be considered when selecting appropriate information security risk treatment options?

Options:

A.

Criteria for accepting identified risks

B.

Criteria for performing risk assessments

C.

Only risk controls in Annex A of ISO/IEC 27001

D.

Only risk controls in ISO/IEC 27002

Buy Now
Questions 8

Which of the following statements about the differences between an internal audit and a certification audit is true?

An internal audit is conducted at planned intervals and a certification audit is conducted annually

An internal audit is known as a 1st party audit and a certification audit is known as a 3rd party audit

Options:

A.

Only 1 is true

B.

Only 2 is true

C.

Both 1 and 2 are true

D.

Neither 1 or 2 is true

Buy Now
Questions 9

Which factor is required to be determined when understanding the organization and its context?

Options:

A.

Internal issues affecting the purpose of the ISMS

B.

The information security objectives relevant to the ISMS

C.

The processes that will be required to operate the ISMS

D.

The ISO/IEC 27001 clauses which apply to the management system

Buy Now
Questions 10

Identify the missing word(s) in the following sentence.

“Information security, cybersecurity and privacy protection – [ ? ]” is the title of ISO/IEC 27005.

Options:

A.

Guidelines for information security management systems auditing

B.

Information security management systems – Requirements

C.

Guidance on managing information security risks

D.

Information security controls

Buy Now
Questions 11

Which statement describes a requirement of an internal audit programme?

Options:

A.

The programme must use third party auditors to ensure impartiality

B.

Previous audit results are disregarded to ensure objectivity

C.

The programme must consider the importance of the target processes

D.

All processes must be audited within a 3-year cycle

Buy Now
Questions 12

Who determines the number of days required for a certification audit?

Options:

A.

The management representative from the organization to be audited

B.

The external auditor from the Certification Body who will undertake the audit

C.

The lead internal auditor from the organization to be audited

D.

Both the management representative and the external auditor together

Buy Now
Questions 13

Which statement is a factor that will influence the implementation of the information security management system?

Options:

A.

The ISMS will be separate from the organization's overall management structure

B.

The ISMS will encompass all controls specified within ISO/IEC 27001

C.

The ISMS will be scaled to the controls according to the needs of the organization

D.

The ISMS will be operated as an independent process within the organization

Buy Now
Questions 14

Which item is required to be included in an information security policy?

Options:

A.

A commitment to satisfy applicable requirements related to information security

B.

A plan for the continual improvement of the information security management system

C.

A framework enabling concerns with the information security policy to be addressed

D.

A Statement of Applicability which defines the necessary controls to be implemented

Buy Now
Questions 15

Which trend in information security performance is required to be considered during a management review of the ISMS?

Options:

A.

Achievement of information security objectives

B.

Validity of information continuity controls

C.

Relevant external and internal requirements changes

D.

Decisions related to continual improvement opportunities

Buy Now
Exam Name: ISO/IEC 27001 (2022) Foundation Exam
Last Update: Oct 3, 2025
Questions: 50

PDF + Testing Engine

$63.52  $181.49

Testing Engine

$50.57  $144.49
buy now ISO-IEC-27001-Foundation testing engine

PDF (Q&A)

$43.57  $124.49
buy now ISO-IEC-27001-Foundation pdf