Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free APMG-International ISO/IEC 27001 (2022) Foundation Exam ISO-IEC-27001-Foundation Exam Questions

Page: 1 / 9 Total 50 questions

Want more questions? Get Premium Access.

Question 1

Which output is a required result from risk analysis?

Correct Answer: B. Determined levels of risk
Explanation:

Clause 6.1.2 (d) states that during risk analysis, the organization shall:

''assess the potential consequences that would result if the risks identified... were to materialize;''

''assess the realistic likelihood of the occurrence of the risks identified;''

''determine the levels of risk.''

This makes it clear that the required output of risk analysis is the determined levels of risk. Risk acceptance criteria (A) are set earlier in 6.1.2(a), treatment control options (C) belong to 6.1.3, and prioritization (D) is part of risk evaluation (6.1.2 e). Therefore, the verified correct output is B: Determined levels of risk.


Question 2

When are the information security policies required to be reviewed, according to the Policies for information security control?

Correct Answer: D. At planned intervals and if significant changes occur
Explanation:

Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:

Annex A.5.1 (Policies for information security) specifies:

''Information security policy and topic-specific policies should be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur.''

This clearly identifies the review frequency requirement: planned intervals and whenever there are significant changes. Options A and B (six-monthly or annually) are not prescribed by ISO --- timing is left to the organization. Option C is also wrong, since Certification Bodies do not dictate policy review schedules.

Therefore, the verified correct answer is D.


Question 3

Which action is a required response to an identified residual risk?

Correct Answer: C. It shall be reviewed by the risk owner to consider acceptance
Explanation:

Clause 6.1.3 (e) specifies:

''The organization shall obtain risk owners' approval of the information security risk treatment plan and acceptance of the residual information security risks.''

This confirms that residual risks --- those remaining after risk treatment --- must be reviewed and formally accepted by the designated risk owner. Option A is incorrect; awareness training is not a default control for all residual risks. Option B misrepresents leadership responsibility; top management ensures processes exist, but risk owners formally approve residual risk. Option D (avoiding risk) is a treatment option, not the mandated requirement for residual risks.

Thus, the required response is C: Review and acceptance by the risk owner.


Question 4

Which activity is a required element of information security risk identification?

Correct Answer: A. Determine the risk owners
Explanation:

Clause 6.1.2 defines the mandatory elements of risk assessment. Under risk identification, the standard requires: ''identifies the information security risks: 1) apply the information security risk assessment process to identify risks...; and 2) identify the risk owners.'' By contrast, considering likelihood and determining levels of risk (options B and D) are part of risk analysis (6.1.2 d) ''assess the realistic likelihood...''; ''determine the levels of risk''), and prioritization for treatment (option C) is part of risk evaluation (6.1.2 e) ''prioritize the analysed risks for risk treatment''). Therefore, the specific activity that belongs to risk identification is to identify the risk owners. This sequencing is prescribed to ensure each risk has a designated owner responsible for decisions on treatment and acceptance downstream.


Question 5

Who is required to ensure that staff are supported so that they can contribute to the information security management system?

Correct Answer: A. Top management of the organization
Explanation:

Clause 5.1 (Leadership and Commitment) requires that:

''Top management shall demonstrate leadership and commitment with respect to the information security management system by... ensuring that the resources needed for the ISMS are available... and supporting persons to contribute to the effectiveness of the ISMS.''

This makes it explicit that top management has the responsibility to ensure personnel are supported so they can contribute to the ISMS. Option B (line management) may provide local support, but ultimate accountability rests with top management. Auditors (C) only evaluate compliance, not provide support. Practitioners (D) help implement, but they don't bear formal responsibility under the standard.

Thus, the verified answer is A: Top management of the organization.


Question 6

In an audit, what is the definition of an observation?

Correct Answer: B. A conformity to the standard where there is an opportunity for improvement
Explanation:

ISO/IEC 27001 mandates internal audits (Clause 9.2) and continual improvement (Clause 10.1) but does not define the specific audit term ''observation.'' However, the audit framework in 9.2 requires an audit programme and impartial auditors, and management review inputs include ''feedback on the information security performance including trends in... audit results'' and ''opportunities for continual improvement.'' The companion implementation guidance (ISO/IEC 27002) reinforces the concept of opportunities for improvement in the review of policies: ''The reviews should include assessing opportunities for improvement and the need for changes to the approach to information security...'' In practical ISO audit usage (aligned with ISO 19011 guidance referenced in the Study Guide), an observation is a recorded conformity where improvement is advisable---commonly termed an Opportunity for Improvement (OFI). The Study Guide's internal audit section emphasizes running an audit programme to identify ''potential areas of weakness or non-compliance,'' supporting the notion of recording improvement opportunities alongside nonconformities. Therefore, within ISO/IEC 27001 audit practice, the best-fit definition is B: a conformity where there is an opportunity for improvement.