Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: cramtick70

ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Questions 4

Which action is a required response to an identified residual risk?

Options:

A.

By default, it shall be controlled by information security awareness and training

B.

Top management shall delegate its treatment to risk owners

C.

It shall be reviewed by the risk owner to consider acceptance

D.

The organization shall change practices to avoid the risk occurring

Buy Now
Questions 5

Which statement describes a requirement of an internal audit programme?

Options:

A.

The programme must use third party auditors to ensure impartiality

B.

Previous audit results are disregarded to ensure objectivity

C.

The programme must consider the importance of the target processes

D.

All processes must be audited within a 3-year cycle

Buy Now
Questions 6

What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?

Options:

A.

Information security event reporting

B.

Information security event management

C.

Response to information security events

D.

Reporting information security incidents

Buy Now
Questions 7

Identify the missing word in the following sentence.

The organization shall determine the [ ? ] of interested parties relevant to information security.

Options:

A.

requirements

B.

number

C.

structure

D.

influence

Buy Now
Questions 8

Identify the missing word(s) in the following sentence.

When planning the ISMS, the organization is specifically required to plan actions to address risks and opportunities and how to [ ? ] these actions.

Options:

A.

communicate

B.

apply competent resources to

C.

improve the effectiveness of

D.

evaluate the effectiveness of

Buy Now
Questions 9

What international standard provides guidance on the integration of ISO/IEC 27001 and the IT Service Management standard?

Options:

A.

ISO/IEC 27002

B.

ISO/IEC 27013

C.

ISO/IEC 20000-1

D.

None of the above

Buy Now
Questions 10

What activity is done first when preparing for an initial certification audit?

Options:

A.

Agree the scope of the ISMS with the Certification Body auditor

B.

Provide documents to the Certification Body auditor for the Stage 1 audit

C.

Provide evidence that nonconformities from an internal audit have been actioned

D.

Provide records to the Certification Body auditor for the Stage 2 audit

Buy Now
Questions 11

Which ISMS documentation is part of the minimum scope of documented information required to be managed and controlled?

Options:

A.

Records of management decisions related to continual improvement

B.

Third party information security awareness materials

C.

The budget assigned to operate the ISMS and its related allocations

D.

A statement of correspondence between other ISO standards and the ISMS

Buy Now
Questions 12

Which benefit is NOT relevant by implementing an ISMS for an organization?

Options:

A.

Information security compliance will increase stakeholder trust in the organization

B.

Information security staff will be qualified to ISO/IEC 27001 Foundation level

C.

Information security controls are tailored to suit the organization's specific circumstances

D.

Information security risks are assessed and the probability and/or impact reduced

Buy Now
Questions 13

Identify the missing word in the following sentence.

According to ISO/IEC 27000, the definition of risk [?] is a “process to comprehend the nature of risk and to determine the level of risk.”

Options:

A.

Evaluation

B.

Analysis

C.

Assessment

D.

Management

Buy Now
Questions 14

To whom are the information security policies required to be communicated, according to the control in Annex A of ISO/IEC 27001?

Options:

A.

Top management

B.

Only staff with accountability for ISMS operation

C.

Employees within the scope of the ISMS

D.

Relevant personnel and relevant interested parties

Buy Now
Questions 15

Which item is required to be included in an information security policy?

Options:

A.

A commitment to satisfy applicable requirements related to information security

B.

A plan for the continual improvement of the information security management system

C.

A framework enabling concerns with the information security policy to be addressed

D.

A Statement of Applicability which defines the necessary controls to be implemented

Buy Now
Exam Name: ISO/IEC 27001 (2022) Foundation Exam
Last Update: Oct 5, 2025
Questions: 50
ISO-IEC-27001-Foundation pdf

ISO-IEC-27001-Foundation PDF

$25.5  $84.99
ISO-IEC-27001-Foundation Engine

ISO-IEC-27001-Foundation Testing Engine

$30  $99.99
ISO-IEC-27001-Foundation PDF + Engine

ISO-IEC-27001-Foundation PDF + Testing Engine

$40.5  $134.99