Online Questions - Valid Practice ISO-IEC-27001-Foundation Exam Dumps Test Questions [Q13-Q32]

Share

Online Questions - Valid Practice ISO-IEC-27001-Foundation Exam Dumps Test Questions

100% Real ISO-IEC-27001-Foundation dumps  - Brilliant ISO-IEC-27001-Foundation Exam Questions PDF

NEW QUESTION # 13
What is required to be reported by the Information security event reporting control?

  • A. Information disclosure
  • B. Asset disposal
  • C. Unauthorized access
  • D. Observed or suspected events

Answer: D

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A, control 6.8 (Information security event reporting) specifies:
"Information security events should be reported through appropriate management channels as quickly as possible. The organization should require all employees and contractors to note and report any observed or suspected information security events." This wording confirms that the required reporting covers"observed or suspected events."Specific event types like information disclosure (A) or unauthorized access (B) are examples but not the broad requirement.
Asset disposal (C) is addressed separately under equipment lifecycle controls (Annex A.7.14).
Therefore, the verified correct answer isD: Observed or suspected events.


NEW QUESTION # 14
In which clause would the requirements for internal audit be found?

  • A. Performance Evaluation
  • B. Planning
  • C. Improvement
  • D. Operation

Answer: A

Explanation:
The requirements for internal audit are explicitly placed inClause 9.2 (Performance Evaluation)of ISO/IEC
27001:2022. The standard requires:
* "The organization shall conduct internal audits at planned intervals to provide information on whether the information security management system... conforms to the organization's own requirements... and to the requirements of this document." (9.2.1)
* "The organization shall plan, establish, implement and maintain an audit programme(s)..." (9.2.2) This clause clearly falls underPerformance Evaluation (Clause 9), not Planning (Clause 6), Operation (Clause 8), or Improvement (Clause 10). Therefore, the correct answer isC.


NEW QUESTION # 15
Which statement describes a requirement for information security objectives?

  • A. They shall be consistent with the information security policy
  • B. They shall be contractually transferred to third parties
  • C. They shall be reviewed at least annually
  • D. They shall all be measurable

Answer: A

Explanation:
Clause 6.2 (Information security objectives) requires that objectives:
* "be consistent with the information security policy"
* "be measurable (if practicable)"
* "take into account applicable information security requirements"
* "be monitored, communicated, and updated as appropriate."
From this, option A is correct since consistency with policy is an explicit requirement. Option B is incorrect because the standard allows objectives to be measurable "if practicable" (not mandatory for all). Option C is incorrect-objectives are not transferred contractually to third parties, though third-party agreements may include security requirements. Option D is incorrect because the standard requires regular review "as appropriate," not a fixed annual cycle.
Thus, the verified requirement isA: They shall be consistent with the information security policy.


NEW QUESTION # 16
Which statement is a factor that will influence the implementation of the information security management system?

  • A. The ISMS will encompass all controls specified within ISO/IEC 27001
  • B. The ISMS will be separate from the organization's overall management structure
  • C. The ISMS will be scaled to the controls according to the needs of the organization
  • D. The ISMS will be operated as an independent process within the organization

Answer: C

Explanation:
ISO/IEC 27001 makes clear that the ISMS is intended to be tailored to the organization. The standard states: " This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations regardless of type, size or nature." This means implementation is scaled based on each organization's risk, context, and needs, not a fixed one-size-fits-all set of activities or controls. Clause 6.1.3 further reinforces that control selection is flexible and risk-driven: " Organizations can design controls as required or identify them from any source," and "Annex A contains a list of possible information security controls... The information security controls listed in Annex A are not exhaustive and additional information security controls can be included if needed." Together, these extracts verify that the ISMS implementation is influenced by and scaled to the organization's needs and selected controls, not separated from management processes (A, D) nor mandated to include "all controls" (B).


NEW QUESTION # 17
Which information is required to be included in the Statement of Applicability?

  • A. The justification for including each information security control
  • B. The risk assessment approach of the organization
  • C. The scope and boundaries of the ISMS
  • D. The criteria against which risk will be evaluated

Answer: A

Explanation:
Clause 6.1.3 (d) requires that the organization"produce a Statement of Applicability that contains the necessary controls (see Annex A), and justification for inclusions, whether they are implemented or not, and the justification for exclusions." This is the defining requirement of the SoA: it documents which Annex A controls are relevant, which are implemented, and the justification for inclusion/exclusion. While the ISMS scope (A) is documented in Clause 4.3, and risk evaluation criteria (C) are defined in Clause 6.1.2, these do not belong in the SoA. The SoA does not describe the full risk assessment approach (B); that is part of the risk assessment methodology.
Therefore, the mandatory requirement for the SoA isjustification for including (or excluding) each information security control.


NEW QUESTION # 18
Which item is required to be defined when planning the organization's risk assessment process?

  • A. The criteria for acceptable levels of risk
  • B. The parts of the ISMS scope which are excluded from the risk assessment
  • C. How the effectiveness of the method will be measured
  • D. There are NO specific information requirements

Answer: A

Explanation:
Clause 6.1.2 (Information security risk assessment) requires organizations to "define and apply an information security risk assessment process that... establishes and maintains information security risk criteria, including criteria for accepting risk." This means that acceptable levels of risk (risk acceptance criteria) must be explicitly defined. These criteria ensure consistent decision-making when evaluating whether identified risks need further treatment or can be tolerated.
Option A is incorrect because exclusions relate to the ISMS scope (Clause 4.3), not risk assessment planning.
Option B is not a requirement; effectiveness of risk assessment methods is not required to be measured, though methods must be applied consistently. Option D is false-the standard clearly specifies required elements for risk assessment.
Thus, the correct answer isC: The criteria for acceptable levels of risk.


NEW QUESTION # 19
Which activity is an operational planning and control requirement?

  • A. Scheduling of second party audits
  • B. Review the consequences of unintended changes
  • C. Document information security objectives
  • D. Perform information security risk assessments at planned intervals

Answer: B

Explanation:
Clause 8.1 (Operational planning and control) requires organizations to:
"Ensure that changes are controlled. The organization shall review the consequences of unintended changes, taking action to mitigate any adverse effects, as necessary." This requirement ensures that operational processes are planned, controlled, and adjusted where unexpected changes occur. Risk assessments (B) are covered in Clause 6.1.2 (Planning), not operations. Scheduling second-party audits (C) is not an ISMS requirement but part of supplier/customer arrangements. Documenting objectives (D) belongs to Clause 6.2 (Planning).
Thus, the required operational planning and control activity is A: Review the consequences of unintended changes.


NEW QUESTION # 20
What is the name of the control clause used to control information security breaches within Annex A of ISO
/IEC 27001?

  • A. Information security event reporting
  • B. Response to information security events
  • C. Information security event management
  • D. Reporting information security incidents

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A in ISO/IEC 27001 refers directly to ISO/IEC 27002 for control guidance. In ISO/IEC 27002:2022, Clause 6.8 is titled:
"Information security event reporting - Information security events should be reported through appropriate management channels as quickly as possible." This control ensures breaches, incidents, or suspected issues are reported for action. The other options (B, C, D) are not the exact titles in Annex A. The official title isInformation security event reporting, confirming


NEW QUESTION # 21
Which attribute is NOT a required focus of continual ISMS improvement?

  • A. Importance
  • B. Suitability
  • C. Effectiveness
  • D. Adequacy

Answer: A

Explanation:
Clause 10.2 (Continual Improvement) specifies that the organization must"continually improve the suitability, adequacy and effectiveness of the information security management system." This makes it clear that three attributes are explicitly required to be addressed:
* Suitability: ensuring the ISMS continues to meet organizational needs in changing contexts.
* Adequacy: ensuring the ISMS covers the necessary scope and provides sufficient control coverage.
* Effectiveness: ensuring the ISMS achieves intended outcomes in protecting information security.
The word"importance"is not part of the continual improvement requirement. Importance is implicit in prioritization of risks and actions, but it is not a required continual improvement attribute in ISO/IEC 27001.
Therefore, optionD: Importanceis the correct choice as it is not specified.
This distinction reinforces that continual improvement is not about subjective importance, but about systematic enhancement of the ISMS'ssuitability, adequacy, and effectiveness.


NEW QUESTION # 22
Who determines the number of days required for a certification audit?

  • A. The external auditor from the Certification Body who will undertake the audit
  • B. The management representative from the organization to be audited
  • C. Both the management representative and the external auditor together
  • D. The lead internal auditor from the organization to be audited

Answer: A

Explanation:
Certification audits are carried out byCertification Bodies (CBs), not the organization itself. ISO/IEC 27001 requires external certification audits to be independent, impartial, and objective. According to ISO/IEC 27006 (Requirements for bodies providing audit and certification of ISMS), the Certification Body determines the audit duration and number of audit daysbased on factors such as organizational size, complexity, scope, and risk environment. This ensures consistency across organizations and prevents manipulation by the auditee. ISO/IEC 27001 Clause 9.2 and 9.3 addressinternal audit and management review, but the determination of certification audit days is outside the organization's control; it rests solely with the accredited Certification Body auditors. Thus, answer: Bis correct, as the CB's external auditor formally calculates and assigns the audit time.


NEW QUESTION # 23
Which item is required to be included in an information security policy?

  • A. A commitment to satisfy applicable requirements related to information security
  • B. A framework enabling concerns with the information security policy to be addressed
  • C. A Statement of Applicability which defines the necessary controls to be implemented
  • D. A plan for the continual improvement of the information security management system

Answer: A

Explanation:
Clause 5.2 (Information security policy) requires that the policy:
* "includes information security objectives (or provides a framework for setting them)"
* "includes a commitment to satisfy applicable requirements related to information security"
* "includes a commitment to continual improvement of the ISMS."
Among the listed options, the exact mandatory requirement is"a commitment to satisfy applicable requirements related to information security". Option B partially reflects Clause 5.2 (commitment to continual improvement), but the wording given in the standard prioritizes the satisfaction of applicable requirements (e.g., legal, regulatory, contractual). Option C is not a policy requirement. Option D (Statement of Applicability) is a separate mandatory document (Clause 6.1.3) and not part of the policy itself.
Thus, the correct answer isA.


NEW QUESTION # 24
Which of the following statements about the differences between an internal audit and a certification audit is true?
An internal audit is conducted at planned intervals and a certification audit is conducted annually An internal audit is known as a 1st party audit and a certification audit is known as a 3rd party audit

  • A. Only 1 is true
  • B. Only 2 is true
  • C. Neither 1 or 2 is true
  • D. Both 1 and 2 are true

Answer: B

Explanation:
ISO/IEC 27001 Clause 9.2 requires internal audits to be conducted at planned intervals, but it does not specify an annual frequency. Certification audits, under ISO/IEC 17021 rules, typically occur on a 3-year cycle with annual surveillance, not strictly "annually." This makes statement 1 inaccurate.
Audit types are defined in ISO/IEC 19011:
First-party audits: conducted internally by or on behalf of the organization (internal audits).
Third-party audits: conducted by independent external certification bodies.
Thus, statement 2 is correct. Therefore, the accurate choice is B: Only 2 is true.


NEW QUESTION # 25
Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?

  • A. Ensure that the controls for compliance with legal and contractual requirements are implemented
  • B. Hold up-to-date records on training, skills, experience and qualifications
  • C. Identify products which could be used in the organization to improve ISMS performance and effectiveness
  • D. Ensure all personnel are trained to ISO/IEC 27001 Foundation level

Answer: B

Explanation:
Clause 7.2 (Competence) requires the organization to:
* "determine the necessary competence of person(s) doing work under its control that affects its information security performance;"
* "ensure that these persons are competent on the basis of appropriate education, training, or experience;"
* "retain appropriate documented information as evidence of competence." This makesholding up-to-date records on training, skills, experience, and qualifications(D) the correct answer. Option A is irrelevant to competence. Option B is incorrect since ISO does not require Foundation- level training - competence is context-based. Option C is related to compliance but does not ensure individual competence.
Thus, the verified correct answer isD.


NEW QUESTION # 26
Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC 27002 is true?
* ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC 27001 information security risk management process
* ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001

  • A. Only 1 is true
  • B. Neither 1 or 2 is true
  • C. Only 2 is true
  • D. Both 1 and 2 are true

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27001 & 27002:2022 standards:
ISO/IEC 27001 Annex A lists reference controls. ISO/IEC 27002 providesdetailed guidance on the implementation of those controls, including purpose, guidance, and examples. Clause 6.1.3 of ISO/IEC
27001 makes the link explicit: controls from Annex A are referenced, but ISO/IEC 27002 explains how to implement them.
However, ISO/IEC 27002 doesnotprovide a process for risk management-that is covered by ISO/IEC
27005. Risk management requirements are in ISO/IEC 27001 (Clauses 6.1.2 and 6.1.3).
Therefore, statement 1 is true, but statement 2 is false. Correct answer:A.


NEW QUESTION # 27
What is a requirement for a corrective action made in response to a nonconformity?

  • A. They always eliminate the cause of the nonconformity
  • B. They are appropriate to the effects of the nonconformity
  • C. They are proportionate to the likelihood of the nonconformity recurring
  • D. They do NOT change the organization's information security policies

Answer: B

Explanation:
Clause 10.1 (Nonconformity and corrective action) specifies:
"The organization shall react to the nonconformity and, as applicable: take action to control and correct it; deal with the consequences; evaluate the need for action to eliminate the cause(s)...
Corrective actions shall be appropriate to the effects of the nonconformities encountered." This confirms optionB. Option A is inaccurate-ISO requires actions appropriate toeffects, not probability alone. Option C is false-policies may need updating to correct nonconformities. Option D is incorrect, as not every cause can always be eliminated; residual issues may exist.
Thus, the verified requirement isB.


NEW QUESTION # 28
Identify the missing word(s) in the following sentence.
"Information security, cybersecurity and privacy protection - [ ? ]" is the title of ISO/IEC 27005.

  • A. Information security controls
  • B. Guidelines for information security management systems auditing
  • C. Guidance on managing information security risks
  • D. Information security management systems - Requirements

Answer: C

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27005 standards:
ISO/IEC 27005:2022 is titled:
"Information security, cybersecurity and privacy protection - Guidance on managing information security risks." This standard provides structured methodologies for identifying, analyzing, evaluating, and treating risks, in alignment with ISO/IEC 27001's risk management requirements (Clause 6.1.2 and 6.1.3). It supports organizations in implementing the risk management process that underpins an ISMS. Options A and B are titles of other ISO standards (ISO/IEC 27007 for auditing, ISO/IEC 27001 for requirements). Option D refers to ISO/IEC 27002 (controls).
Thus, the correct answer isC: Guidance on managing information security risks.


NEW QUESTION # 29
When are the information security policies required to be reviewed, according to the Policies for information security control?

  • A. At planned intervals and if significant changes occur
  • B. Annually
  • C. According to a schedule defined by the Certification Body
  • D. Every six months

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.5.1 (Policies for information security) specifies:
"Information security policy and topic-specific policies should be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur." This clearly identifies the review frequency requirement: planned intervalsandwhenever there are significant changes. Options A and B (six-monthly or annually) are not prescribed by ISO - timing is left to the organization. Option C is also wrong, since Certification Bodies do not dictate policy review schedules.
Therefore, the verified correct answer isD.


NEW QUESTION # 30
What activity is done first when preparing for an initial certification audit?

  • A. Provide records to the Certification Body auditor for the Stage 2 audit
  • B. Agree the scope of the ISMS with the Certification Body auditor
  • C. Provide evidence that nonconformities from an internal audit have been actioned
  • D. Provide documents to the Certification Body auditor for the Stage 1 audit

Answer: B

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27001:2022 standards and certification guidance:
Before a certification audit can begin, thescope of the ISMSmust be clearly defined and agreed with the Certification Body. ISO/IEC 27001 Clause 4.3 requires: "The scope shall be available as documented information." Certification Bodies require this scope statement to plan audit duration, resources, and coverage. Only after the scope is agreed does the Stage 1 audit begin, which reviews documented information and readiness. Stage
2 focuses on implementation and effectiveness. Evidence of corrective actions (C) is checked at Stage 2 if issues were identified earlier. Records provision (D) occurs during Stage 2, not first.
Thus, the first step in preparing for certification isA: Agreeing the scope of the ISMS with the Certification Body auditor.


NEW QUESTION # 31
Which is a control title within Annex A of ISO/IEC 27001?

  • A. Change control
  • B. Protection of documents
  • C. Responsibilities and procedures
  • D. Information security in supplier relationships

Answer: D

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
In ISO/IEC 27002:2022, which provides control guidance for Annex A of ISO/IEC 27001, Clause 5.19 is titled:"Information security in supplier relationships." This control requires organizations to ensure that information security is addressed in supplier agreements and relationships. It is part of theOrganizational Controls theme. The other options are not control titles in Annex A:
* "Responsibilities and procedures" (B) was used in older standards like ISO/IEC 27001:2005 but no longer exists.
* "Protection of documents" (C) relates to document control but is not a specific Annex A control.
* "Change control" (D) is relevant to ITIL/ITSM but not listed as a control title in Annex A.
Therefore, the correct Annex A control title isA: Information security in supplier relationships.


NEW QUESTION # 32
......

ISO-IEC-27001-Foundation Exam PDF [2026] Tests Free Updated Today with Correct 52 Questions: https://www.examcost.com/ISO-IEC-27001-Foundation-practice-exam.html

APMG-International ISO-IEC-27001-Foundation Exam Preparation Guide and PDF Download: https://drive.google.com/open?id=1XjAJbRBkxmtA62TtcJ7iLpdhXyjTCTwT