Spring Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Questions 4

Which statement describes a requirement of an internal audit programme?

Options:

A.

The programme must use third party auditors to ensure impartiality

B.

Previous audit results are disregarded to ensure objectivity

C.

The programme must consider the importance of the target processes

D.

All processes must be audited within a 3-year cycle

Buy Now
Questions 5

Which item is required to be defined when planning the organization's risk assessment process?

Options:

A.

The parts of the ISMS scope which are excluded from the risk assessment

B.

How the effectiveness of the method will be measured

C.

The criteria for acceptable levels of risk

D.

There are NO specific information requirements

Buy Now
Questions 6

What is the definition of a threat according to ISO/IEC 27000?

Options:

A.

A potential cause of an unwanted incident which can result in harm to a system or organization

B.

A single or a series of unwanted or unexpected information security events

C.

A weakness of an asset or a control that can be exploited

D.

The risk remaining after risk treatment

Buy Now
Questions 7

Which statement describes the Classification of information control in Annex A of ISO/IEC 27001?

Options:

A.

Ensures that all information assets are labelled with their classification

B.

Ensures that information is classified based on confidentiality, integrity and availability

C.

Ensures that security perimeters are used to protect assets

D.

Ensures the rules to control physical and logical access apply to assets

Buy Now
Questions 8

Which activity is an operational planning and control requirement?

Options:

A.

Review the consequences of unintended changes

B.

Perform information security risk assessments at planned intervals

C.

Scheduling of second party audits

D.

Document information security objectives

Buy Now
Questions 9

What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?

Options:

A.

Information security event reporting

B.

Information security event management

C.

Response to information security events

D.

Reporting information security incidents

Buy Now
Questions 10

When are the information security policies required to be reviewed, according to the Policies for information security control?

Options:

A.

Every six months

B.

Annually

C.

According to a schedule defined by the Certification Body

D.

At planned intervals and if significant changes occur

Buy Now
Questions 11

Which statement is a factor that will influence the implementation of the information security management system?

Options:

A.

The ISMS will be separate from the organization's overall management structure

B.

The ISMS will encompass all controls specified within ISO/IEC 27001

C.

The ISMS will be scaled to the controls according to the needs of the organization

D.

The ISMS will be operated as an independent process within the organization

Buy Now
Questions 12

Who is required to ensure that staff are supported so that they can contribute to the information security management system?

Options:

A.

Top management of the organization

B.

Management responsible for each area of operation

C.

Auditors who audit each area of operation

D.

ISO/IEC 27001 practitioners within the organization

Buy Now
Questions 13

To whom does the scope of the Terms and conditions of employment control apply?

Options:

A.

Employees only

B.

Contractors only

C.

Personnel and the organization

D.

All employees, contractors and third-party users

Buy Now
Questions 14

What is a requirement for a corrective action made in response to a nonconformity?

Options:

A.

They are proportionate to the likelihood of the nonconformity recurring

B.

They are appropriate to the effects of the nonconformity

C.

They do NOT change the organization's information security policies

D.

They always eliminate the cause of the nonconformity

Buy Now
Questions 15

Which benefit is NOT relevant by implementing an ISMS for an organization?

Options:

A.

Information security compliance will increase stakeholder trust in the organization

B.

Information security staff will be qualified to ISO/IEC 27001 Foundation level

C.

Information security controls are tailored to suit the organization's specific circumstances

D.

Information security risks are assessed and the probability and/or impact reduced

Buy Now
Exam Name: ISO/IEC 27001 (2022) Foundation Exam
Last Update: May 21, 2026
Questions: 50

PDF + Testing Engine

$64.99  $185.69

Testing Engine

$49.99  $142.83
buy now ISO-IEC-27001-Foundation testing engine

PDF (Q&A)

$54.99  $157.11
buy now ISO-IEC-27001-Foundation pdf