Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free ISO/IEC 27001 (2022) Foundation Exam Practice Questions

Exams4sure Dumps

Exam style questions across every ISO-IEC-27001-Foundation domain

Last Update 1 day ago
Total Questions : 50

Start with our free ISO-IEC-27001-Foundation practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real ISO/IEC 27001 exam. Each ISO-IEC-27001-Foundation exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your APMG-International weak domains, see where you're losing marks, and build a focused study plan in minutes.

ISO-IEC-27001-Foundation PDF

ISO-IEC-27001-Foundation PDF (Printable)
$46.5
$154.99

ISO-IEC-27001-Foundation Testing Engine

ISO-IEC-27001-Foundation PDF (Printable)
$51
$169.99

ISO-IEC-27001-Foundation PDF + Testing Engine

ISO-IEC-27001-Foundation PDF (Printable)
$63.9
$212.99
Question # 1

Identify the missing word(s) in the following control relating to the Policies for information security control.

“Information security policy and topic-specific policies should be defined, approved by management, [ ? ] and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.”

Options:

A.  

published

B.  

established and maintained

C.  

published, communicated to

D.  

communicated to

Discussion 0
Question # 2

Which statement describes a purpose of monitoring, measurement, analysis and evaluation according to ISO/IEC 27001?

Options:

A.  

To evaluate information security performance

B.  

To ensure that employees and contractors are competent

C.  

To monitor the use of information assets

D.  

To track the use of outsourced processes

Discussion 0
Question # 3

Identify the missing words in the following sentence.

The organization shall establish, implement, maintain and [ ? ] an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.

Options:

A.  

report on

B.  

continually improve

C.  

communicate the importance of

D.  

enforce standards for

Discussion 0
Question # 4

Identify the missing word in the following sentence.

The organization shall determine the [ ? ] of interested parties relevant to information security.

Options:

A.  

requirements

B.  

number

C.  

structure

D.  

influence

Discussion 0
Question # 5

Which statement describes a requirement of an internal audit programme?

Options:

A.  

The programme must use third party auditors to ensure impartiality

B.  

Previous audit results are disregarded to ensure objectivity

C.  

The programme must consider the importance of the target processes

D.  

All processes must be audited within a 3-year cycle

Discussion 0
Question # 6

Which aspect of ISO/IEC 27001 requires that contractors know about the organization’s information security policies?

Options:

A.  

Nonconformity and corrective action

B.  

Competence

C.  

Communication

D.  

Awareness

Discussion 0
Question # 7

What is required to be reported by the Information security event reporting control?

Options:

A.  

Information disclosure

B.  

Unauthorized access

C.  

Asset disposal

D.  

Observed or suspected events

Discussion 0
Question # 8

What is the definition of the term ‘integrity’ according to ISO/IEC 27000?

Options:

A.  

The property of being accessible and usable

B.  

The property that information is NOT made available inappropriately

C.  

The property of accuracy and completeness

D.  

The property of availability and confidentiality

Discussion 0
Question # 9

In an audit, what is the definition of an observation?

Options:

A.  

A non-fulfilment of a requirement of ISO/IEC 27001

B.  

A conformity to the standard where there is an opportunity for improvement

C.  

An issue excluded from the scope of the standard

D.  

An issue raised by an interested party

Discussion 0
Question # 10

Which output is a required result from risk analysis?

Options:

A.  

Risk acceptance criteria

B.  

Determined levels of risk

C.  

Risk treatment control options

D.  

Prioritized risks for treatment

Discussion 0

Free Exams Sample Questions