Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

ISO/IEC 27001 (2022) Foundation Exam

Last Update 19 hours ago Total Questions : 50

The ISO/IEC 27001 (2022) Foundation Exam content is now fully updated, with all current exam questions added 19 hours ago. Deciding to include ISO-IEC-27001-Foundation practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our ISO-IEC-27001-Foundation exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these ISO-IEC-27001-Foundation sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any ISO/IEC 27001 (2022) Foundation Exam practice test comfortably within the allotted time.

Question # 1

Which factor is required to be determined when understanding the organization and its context?

A.

Internal issues affecting the purpose of the ISMS

B.

The information security objectives relevant to the ISMS

C.

The processes that will be required to operate the ISMS

D.

The ISO/IEC 27001 clauses which apply to the management system

Question # 2

Which statement describes a requirement for information security objectives?

A.

They shall be consistent with the information security policy

B.

They shall all be measurable

C.

They shall be contractually transferred to third parties

D.

They shall be reviewed at least annually

Question # 3

What international standard provides guidance on the integration of ISO/IEC 27001 and the IT Service Management standard?

A.

ISO/IEC 27002

B.

ISO/IEC 27013

C.

ISO/IEC 20000-1

D.

None of the above

Question # 4

Which item is required to be defined when planning the organization's risk assessment process?

A.

The parts of the ISMS scope which are excluded from the risk assessment

B.

How the effectiveness of the method will be measured

C.

The criteria for acceptable levels of risk

D.

There are NO specific information requirements

Question # 5

Which statement about the conduct of audits is true?

A.

Third party audits are conducted by a customer of the organization

B.

The certificate issued after a successful re-certification audit in typical schemes lasts for one year

C.

One of the focus areas for a surveillance audit is the output from internal audits and management reviews

D.

During Stage 1 of a certification audit, evidence is collected by observing activities

Question # 6

What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?

A.

Information security event reporting

B.

Information security event management

C.

Response to information security events

D.

Reporting information security incidents

Question # 7

Identify the missing word(s) in the following sentence.

“Information security, cybersecurity and privacy protection – [ ? ]” is the title of ISO/IEC 27005.

A.

Guidelines for information security management systems auditing

B.

Information security management systems – Requirements

C.

Guidance on managing information security risks

D.

Information security controls

Question # 8

When are the information security policies required to be reviewed, according to the Policies for information security control?

A.

Every six months

B.

Annually

C.

According to a schedule defined by the Certification Body

D.

At planned intervals and if significant changes occur

Question # 9

Which of the following is required to be considered when selecting appropriate information security risk treatment options?

A.

Criteria for accepting identified risks

B.

Criteria for performing risk assessments

C.

Only risk controls in Annex A of ISO/IEC 27001

D.

Only risk controls in ISO/IEC 27002

Question # 10

What is required to be reported by the Information security event reporting control?

A.

Information disclosure

B.

Unauthorized access

C.

Asset disposal

D.

Observed or suspected events

Go to page: