Weekend Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

APMG-International ISO-IEC-27001-Foundation - ISO/IEC 27001 (2022) Foundation Exam

Which statement describes a purpose of monitoring, measurement, analysis and evaluation according to ISO/IEC 27001?

A.

To evaluate information security performance

B.

To ensure that employees and contractors are competent

C.

To monitor the use of information assets

D.

To track the use of outsourced processes

Which is a control title within Annex A of ISO/IEC 27001?

A.

Information security in supplier relationships

B.

Responsibilities and procedures

C.

Protection of documents

D.

Change control

What is the name of the control clause used to control information security breaches within Annex A of ISO/IEC 27001?

A.

Information security event reporting

B.

Information security event management

C.

Response to information security events

D.

Reporting information security incidents

Which information is required to be included in the Statement of Applicability?

A.

The scope and boundaries of the ISMS

B.

The risk assessment approach of the organization

C.

The criteria against which risk will be evaluated

D.

The justification for including each information security control

Which action must top management take to provide evidence of its commitment to the establishment, operation and improvement of the ISMS?

A.

Communicating feedback from interested parties to the organization

B.

Ensuring information security objectives are established

C.

Producing a risk assessment report

D.

Implementing the actions from internal audits

Which action is a required response to an identified residual risk?

A.

By default, it shall be controlled by information security awareness and training

B.

Top management shall delegate its treatment to risk owners

C.

It shall be reviewed by the risk owner to consider acceptance

D.

The organization shall change practices to avoid the risk occurring

Which item is required to be included in an information security policy?

A.

A commitment to satisfy applicable requirements related to information security

B.

A plan for the continual improvement of the information security management system

C.

A framework enabling concerns with the information security policy to be addressed

D.

A Statement of Applicability which defines the necessary controls to be implemented

Which aspect of ISO/IEC 27001 requires that contractors know about the organization’s information security policies?

A.

Nonconformity and corrective action

B.

Competence

C.

Communication

D.

Awareness

Which statement describes the Classification of information control in Annex A of ISO/IEC 27001?

A.

Ensures that all information assets are labelled with their classification

B.

Ensures that information is classified based on confidentiality, integrity and availability

C.

Ensures that security perimeters are used to protect assets

D.

Ensures the rules to control physical and logical access apply to assets

Which of the following statements about the differences between an internal audit and a certification audit is true?

An internal audit is conducted at planned intervals and a certification audit is conducted annually

An internal audit is known as a 1st party audit and a certification audit is known as a 3rd party audit

A.

Only 1 is true

B.

Only 2 is true

C.

Both 1 and 2 are true

D.

Neither 1 or 2 is true