Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free APMG-International ISO-IEC-27001-Foundation Practice Exam with Questions & Answers

Questions 1

Identify the missing word(s) in the following sentence.

When planning the ISMS, the organization is specifically required to plan actions to address risks and opportunities and how to [ ? ] these actions.

Options:
A.

communicate

B.

apply competent resources to

C.

improve the effectiveness of

D.

evaluate the effectiveness of

APMG-International ISO-IEC-27001-Foundation Premium Access
Questions 2

Which activity is an operational planning and control requirement?

Options:
A.

Review the consequences of unintended changes

B.

Perform information security risk assessments at planned intervals

C.

Scheduling of second party audits

D.

Document information security objectives

Questions 3

Which statement describes the control for the Compliance with policies, rules and standards for information security within Annex A of ISO/IEC 27001?

Options:
A.

Regular review of compliance

B.

Regular review of contractual compliance

C.

Maintain contact with legal authorities

D.

Return assets to their legal owners

Questions 4

Which action is a required response to an identified residual risk?

Options:
A.

By default, it shall be controlled by information security awareness and training

B.

Top management shall delegate its treatment to risk owners

C.

It shall be reviewed by the risk owner to consider acceptance

D.

The organization shall change practices to avoid the risk occurring

Questions 5

To whom does the scope of the Terms and conditions of employment control apply?

Options:
A.

Employees only

B.

Contractors only

C.

Personnel and the organization

D.

All employees, contractors and third-party users

Questions 6

Which information is required to be included in the Statement of Applicability?

Options:
A.

The scope and boundaries of the ISMS

B.

The risk assessment approach of the organization

C.

The criteria against which risk will be evaluated

D.

The justification for including each information security control

Questions 7

Who determines the number of days required for a certification audit?

Options:
A.

The management representative from the organization to be audited

B.

The external auditor from the Certification Body who will undertake the audit

C.

The lead internal auditor from the organization to be audited

D.

Both the management representative and the external auditor together

Questions 8

Which item is required to be considered when defining the scope and boundaries of the information security management system?

Options:
A.

The dependencies between activities performed by the organization

B.

The level of quality to which the ISMS must adhere

C.

The lessons learned from the information security experiences of other organizations

D.

The regular activities necessary to maintain and improve the ISMS

Questions 9

Which trend in information security performance is required to be considered during a management review of the ISMS?

Options:
A.

Achievement of information security objectives

B.

Validity of information continuity controls

C.

Relevant external and internal requirements changes

D.

Decisions related to continual improvement opportunities

Questions 10

What is the definition of the term ‘integrity’ according to ISO/IEC 27000?

Options:
A.

The property of being accessible and usable

B.

The property that information is NOT made available inappropriately

C.

The property of accuracy and completeness

D.

The property of availability and confidentiality