Big Halloween Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple70

Pass the APMG-International ISO/IEC 27001 ISO-IEC-27001-Foundation Questions and answers with ExamsMirror

Practice at least 50% of the questions to maximize your chances of passing.
Exam ISO-IEC-27001-Foundation Premium Access

View all detail and faqs for the ISO-IEC-27001-Foundation exam


343 Students Passed

94% Average Score

92% Same Questions
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

Which statement describes Annex A of ISO/IEC 27001?

Options:

A.

Defines the criteria for accepting risks

B.

Provides a reference list of information security controls and their requirements

C.

Defines a mandatory list of controls that shall be implemented

D.

Provides measures to determine risk treatment effectiveness

Questions # 2:

What activity is done first when preparing for an initial certification audit?

Options:

A.

Agree the scope of the ISMS with the Certification Body auditor

B.

Provide documents to the Certification Body auditor for the Stage 1 audit

C.

Provide evidence that nonconformities from an internal audit have been actioned

D.

Provide records to the Certification Body auditor for the Stage 2 audit

Questions # 3:

Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC 27002 is true?

    ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC 27001 information security risk management process

    ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001

Options:

A.

Only 1 is true

B.

Only 2 is true

C.

Both 1 and 2 are true

D.

Neither 1 or 2 is true

Questions # 4:

Which statement describes a requirement of an internal audit programme?

Options:

A.

The programme must use third party auditors to ensure impartiality

B.

Previous audit results are disregarded to ensure objectivity

C.

The programme must consider the importance of the target processes

D.

All processes must be audited within a 3-year cycle

Questions # 5:

What is the definition of the term ‘integrity’ according to ISO/IEC 27000?

Options:

A.

The property of being accessible and usable

B.

The property that information is NOT made available inappropriately

C.

The property of accuracy and completeness

D.

The property of availability and confidentiality

Questions # 6:

Which ISMS documentation is part of the minimum scope of documented information required to be managed and controlled?

Options:

A.

Records of management decisions related to continual improvement

B.

Third party information security awareness materials

C.

The budget assigned to operate the ISMS and its related allocations

D.

A statement of correspondence between other ISO standards and the ISMS

Questions # 7:

Which audit activity related to ISO/IEC 27001 may be carried out by a practitioner?

Options:

A.

Conduct a surveillance audit of their own area of the organization

B.

Conduct an internal audit of the organization

C.

Conduct an audit of an Accredited Training Organization

D.

Conduct an audit of a Certification Body

Questions # 8:

Which item is required to be included in an information security policy?

Options:

A.

A commitment to satisfy applicable requirements related to information security

B.

A plan for the continual improvement of the information security management system

C.

A framework enabling concerns with the information security policy to be addressed

D.

A Statement of Applicability which defines the necessary controls to be implemented

Questions # 9:

Which item is required to be defined when planning the organization's risk assessment process?

Options:

A.

The parts of the ISMS scope which are excluded from the risk assessment

B.

How the effectiveness of the method will be measured

C.

The criteria for acceptable levels of risk

D.

There are NO specific information requirements

Questions # 10:

Who is required to ensure that staff are supported so that they can contribute to the information security management system?

Options:

A.

Top management of the organization

B.

Management responsible for each area of operation

C.

Auditors who audit each area of operation

D.

ISO/IEC 27001 practitioners within the organization

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
TOP CODES

TOP CODES

Top selling exam codes in the certification world, popular, in demand and updated to help you pass on the first try.