Pre-Summer Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

CertiProf I27001F Certified ISO/IEC 27001:2022 Foundation Exam Practice Test

Demo: 12 questions
Total 40 questions

Certified ISO/IEC 27001:2022 Foundation Questions and Answers

Question 1

Within the ISMS, ensuring the integration of information security management system requirements into the organization’s processes is a responsibility of:

Options:

A.

The quality management representative

B.

The IT Security Manager

C.

The Operations Manager

D.

Top management

Question 2

What does ISO/IEC 27001:2022 require for the control of documented information?

Options:

A.

Control documented information so that it is available and suitable for use, where and when it is needed

B.

Acquire a technological tool to control documented information effectively

C.

Have an internal auditor validate that documented information control is performed externally

D.

Hire a consultancy to determine how documented information should be controlled in order to achieve certification

Question 3

Identify the missing words in the following sentence.

The organization shall establish, ________, maintain, and continually improve an information security management system.

Options:

A.

implement

B.

administer

C.

monitor

D.

exploit

Question 4

Which of the following activities are responsibilities of top management?

Options:

A.

Ensuring compliance with the information security policy

B.

Assigning the resources necessary to maintain the system

C.

Supporting the drive for continual improvement

D.

All of the above

Question 5

What does ISO/IEC 27001:2022 require for information security risk treatment?

Options:

A.

A consultancy to accurately perform information security risk treatment

B.

Performing an information security risk treatment process to select appropriate risk treatment options, taking into account the results of the risk assessment

C.

A person designated by top management with expertise to perform information security risk treatment

D.

Acquiring a set of information security tools to automate risk treatment

Question 6

What does ISO/IEC 27001:2022 require in order for top management to demonstrate leadership and commitment with respect to the Information Security Management System?

Options:

A.

Ensuring that the information security policy and information security objectives are established and are compatible with the strategic direction of the organization

B.

Hiring a consultancy to determine the best way to do it

C.

Appointing a volunteer to be responsible for the Information Security Management System

D.

Nothing is required

Question 7

According to the terms and definitions associated with ISO 27001, authenticity is defined as:

Options:

A.

The property of consistency in behaviour and intended results

B.

The property that an entity is what it claims to be

C.

The ability to prove that a claimed event has occurred or that a claimed action was performed by the entities that originated it

D.

None of the above

Question 8

Which of the following options should be included in the ISMS policy?

Options:

A.

The name of the intrusion detection system

B.

The company history and the motivation for implementing the ISMS

C.

The information security objectives

D.

The results of previous audits

Question 9

What does ISO/IEC 27001:2022 require for information security risk assessment?

Options:

A.

A person designated by top management

B.

A consultancy to perform the information security risk assessment professionally

C.

Acquisition of a set of information security tools to automate the assessment using artificial intelligence

D.

Applying an information security risk assessment process that establishes and maintains information security risk criteria

Question 10

According to ISO/IEC 27001:2022, is it necessary to formulate an information security risk treatment plan?

Options:

A.

It is only an observation to keep in mind when auditing the management system

B.

It is a requirement to be fulfilled

C.

It is a recommendation, but not a requirement

D.

None of the above

Question 11

What does ISO/IEC 27001:2022 require in order to evaluate information security performance and the effectiveness of the Information Security Management System?

Options:

A.

Information security tools to evaluate information security performance and system effectiveness

B.

A consultancy to accurately perform the evaluation of information security performance and validate the effectiveness of the management system

C.

The organization must determine what needs to be monitored and measured, including information security processes and controls

D.

A person designated by top management with expertise to evaluate information security performance and system effectiveness

Question 12

Annex A of ISO/IEC 27001:2022 consists of:

Options:

A.

Elements necessary for a good design and implementation of the ISMS

B.

A comprehensive list of controls grouped by themes

C.

Guidelines for risk management

D.

None of the above

Demo: 12 questions
Total 40 questions