Weekend Sale - 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: dm70dm

ISO-IEC-27001-Foundation ISO/IEC 27001 (2022) Foundation Exam Questions and Answers

Questions 4

Which is a control title within Annex A of ISO/IEC 27001?

Options:

A.

Information security in supplier relationships

B.

Responsibilities and procedures

C.

Protection of documents

D.

Change control

Buy Now
Questions 5

Which trend in information security performance is required to be considered during a management review of the ISMS?

Options:

A.

Achievement of information security objectives

B.

Validity of information continuity controls

C.

Relevant external and internal requirements changes

D.

Decisions related to continual improvement opportunities

Buy Now
Questions 6

Which statement describes the control for the Compliance with policies, rules and standards for information security within Annex A of ISO/IEC 27001?

Options:

A.

Regular review of compliance

B.

Regular review of contractual compliance

C.

Maintain contact with legal authorities

D.

Return assets to their legal owners

Buy Now
Questions 7

Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC 27002 is true?

    ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC 27001 information security risk management process

    ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001

Options:

A.

Only 1 is true

B.

Only 2 is true

C.

Both 1 and 2 are true

D.

Neither 1 or 2 is true

Buy Now
Questions 8

Which of the following is required to be considered when selecting appropriate information security risk treatment options?

Options:

A.

Criteria for accepting identified risks

B.

Criteria for performing risk assessments

C.

Only risk controls in Annex A of ISO/IEC 27001

D.

Only risk controls in ISO/IEC 27002

Buy Now
Questions 9

In which clause would the requirements for internal audit be found?

Options:

A.

Planning

B.

Operation

C.

Performance Evaluation

D.

Improvement

Buy Now
Questions 10

Which activity is an operational planning and control requirement?

Options:

A.

Review the consequences of unintended changes

B.

Perform information security risk assessments at planned intervals

C.

Scheduling of second party audits

D.

Document information security objectives

Buy Now
Questions 11

Which activity is a required element of information security risk identification?

Options:

A.

Determine the risk owners

B.

Consider the likelihood of the occurrence

C.

Prioritize the risk for treatment

D.

Determine the level of risk

Buy Now
Questions 12

Which statement about the conduct of audits is true?

Options:

A.

Third party audits are conducted by a customer of the organization

B.

The certificate issued after a successful re-certification audit in typical schemes lasts for one year

C.

One of the focus areas for a surveillance audit is the output from internal audits and management reviews

D.

During Stage 1 of a certification audit, evidence is collected by observing activities

Buy Now
Questions 13

Identify the missing word in the following sentence.

According to ISO/IEC 27000, the definition of risk [?] is a “process to comprehend the nature of risk and to determine the level of risk.”

Options:

A.

Evaluation

B.

Analysis

C.

Assessment

D.

Management

Buy Now
Questions 14

What activity is done first when preparing for an initial certification audit?

Options:

A.

Agree the scope of the ISMS with the Certification Body auditor

B.

Provide documents to the Certification Body auditor for the Stage 1 audit

C.

Provide evidence that nonconformities from an internal audit have been actioned

D.

Provide records to the Certification Body auditor for the Stage 2 audit

Buy Now
Questions 15

Which information is required to be included in the Statement of Applicability?

Options:

A.

The scope and boundaries of the ISMS

B.

The risk assessment approach of the organization

C.

The criteria against which risk will be evaluated

D.

The justification for including each information security control

Buy Now
Exam Name: ISO/IEC 27001 (2022) Foundation Exam
Last Update: Oct 5, 2025
Questions: 50

PDF + Testing Engine

$49.5  $164.99

Testing Engine

$37.5  $124.99
buy now ISO-IEC-27001-Foundation testing engine

PDF (Q&A)

$31.5  $104.99
buy now ISO-IEC-27001-Foundation pdf
dumpsmate guaranteed to pass
24/7 Customer Support

DumpsMate's team of experts is always available to respond your queries on exam preparation. Get professional answers on any topic of the certification syllabus. Our experts will thoroughly satisfy you.

Site Secure

mcafee secure

TESTED 05 Oct 2025