Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70percent

PECB ISO-IEC-27002-Foundation ISO/IEC 27002 Foundation Exam Exam Practice Test

ISO/IEC 27002 Foundation Exam Questions and Answers

Question 1

What should the management of the organization do to ensure that all personnel are aware of and fulfill their information security responsibilities?

Options:

A.

Require all personnel to apply information security in accordance with the established information security policy, topic-specific policies and procedures of the organization

B.

Require all personnel to establish and approve information security policies, topic-specific policies and procedures of the organization

C.

Require all personnel to read the guidelines of ISO/IEC 27002

Question 2

What is continual improvement?

Options:

A.

The process of increasing the effectiveness and efficiency of the organization to fulfill its policy and objectives

B.

A method of examining the nature of something or of determining its essential features and their relations

C.

The action taken to eliminate a detected nonconformity

Question 3

Which of the following controls should the organization implement to ensure that its approach to managing information security continues to be suitable, adequate and effective?

Options:

A.

Control 5.4 Management responsibilities

B.

Control 5.35 Independent review of information security

C.

Control 5.24 Information security incident management planning and preparation

Question 4

What does ISO/IEC 27002 provide?

Options:

A.

Guidance for the implementation of information security controls

B.

Requirements for the implementation of information security controls

C.

Guidance for the management of information security risks

Question 5

Why should an organization integrate information security into project management?

Options:

A.

To ensure the effective application of ISO/IEC 27001 principles related to projects and deliverables

B.

To ensure information security audits on the project and deliverables are regularly conducted

C.

To ensure information security risks related to projects and deliverables are effectively addressed

Question 6

What is the purpose of Control 8.20 Network security of ISO/IEC 27002?

Options:

A.

To protect information in networks and its supporting information processing facilities from compromise via the network

B.

To ensure security in the use of network services

C.

To split the network in security boundaries

Question 7

An organization has set up a fire alarm. What type of control is this?

Options:

A.

Corrective and managerial

B.

Detective and technical

C.

Preventive and legal

Question 8

Which information security principle is compromised by accidental changes in information?

Options:

A.

Availability

B.

Integrity

C.

Confidentiality

Question 9

Which control of ISO/IEC 27002 helps organizations ensure that employees and contractors are suitable for their roles?

Options:

A.

Control 6.1 Screening

B.

Control 6.4 Disciplinary process

C.

Control 6.7 Remote working

Question 10

Some employees of an organization find the data processing procedures complicated and have been struggling to follow them effectively. Which of the following threats is the organization facing in this case?

Options:

A.

Data input error by employees

B.

Hacking

C.

Information theft

Question 11

What should an organization do if it detects a vulnerability that does not have a corresponding threat?

Options:

A.

Recognize the vulnerability

B.

Both A and C

C.

Monitor the vulnerability for changes

Question 12

Which control of ISO/IEC 27002 aims to ensure the correct and secure operation of information processing facilities?

Options:

A.

Control 7.2 Physical entry

B.

Control 5.37 Documented operating procedures

C.

Control 5.35 Independent review of information security