Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CertiProf Certified ISO/IEC 27001:2022 Foundation I27001F Exam Questions

Page: 1 / 7 Total 40 questions

Want more questions? Get Premium Access.

Question 1

In the context of clause 6.1 actions to address risks and opportunities, what is defined as residual risk?

Correct Answer: C. Risk remaining after risk treatment
Explanation:

Residual risk is the risk that remains after risk treatment has been applied. In an ISMS, organizations assess risks, select treatment options, and implement controls or other measures to reduce risk to an acceptable level. Even after treatment, some level of risk may still remain, and that remaining portion is called residual risk. Therefore, option C is correct.


Question 2

According to the terms and definitions associated with ISO 27001, authenticity is defined as:

Correct Answer: B. The property that an entity is what it claims to be
Explanation:

In ISO information security terminology, authenticity means the property that an entity is what it claims to be. This concept is distinct from non-repudiation, which relates to the ability to prove that an event or action occurred and cannot later be denied. It is also distinct from integrity, which concerns accuracy and completeness. Therefore, option B is correct.


Question 3

In the context of clause 6.1 actions to address risks and opportunities, the weakness of an asset or control that can be exploited by a threat is known as:

Correct Answer: C. Vulnerability
Explanation:

A vulnerability is a weakness of an asset, control, or other element that can be exploited by one or more threats. In information security risk assessment, vulnerabilities are considered together with threats, likelihood, and impact in order to understand and evaluate risk. A threat is a potential cause of an unwanted incident, while impact refers to the consequence. Therefore, option C is correct.


Question 4

Within the ISMS, communicating the importance of effective information security management and of conforming to the ISMS requirements is a responsibility of:

Correct Answer: B. Top management
Explanation:

A specific leadership responsibility in ISO/IEC 27001:2022 is for top management to communicate the importance of effective information security management and of conforming to the ISMS requirements. This communication role is part of demonstrating leadership and commitment, helping create organizational awareness and support for the ISMS. Therefore, option B is correct.


Question 5

A document defining the scope of the Information Security Management System may:

Correct Answer: B. Consider the scope and boundaries from an organizational and technological perspective
Explanation:

ISO/IEC 27001:2022 requires the organization to determine the boundaries and applicability of the ISMS in order to establish its scope. When defining the scope, the organization must consider internal and external issues, interested parties, and interfaces and dependencies between activities performed by the organization and those performed by other organizations. The strongest and most accurate answer is B because it directly reflects the concept of scope and boundaries. Options A and C may be related in practice, but they are not the clearest expression of the formal requirement.


Question 6

Which statement describes a critical success factor for an Information Security Management System ISMS?

Correct Answer: B. Implementing an effective information security awareness, education, and training program
Explanation:

A successful ISMS depends heavily on awareness, competence, and engagement across the organization. ISO/IEC 27001:2022 emphasizes competence, awareness, communication, leadership, and operational discipline. An effective awareness, education, and training program helps ensure that people understand their information security responsibilities and contribute to the effectiveness of the ISMS. Hiring consultants or buying specific tools may help in some cases, but they are not critical success factors defined by the standard itself. Therefore, option B is the correct answer.