ISO-IEC-27001-Foundation Exam Questions & Answers
ISO/IEC 27001 (2022) Foundation Exam • APMG-International
100% money-back guarantee
Sample ISO-IEC-27001-Foundation Questions
Practice with real exam-style questions, each with the verified correct answer and explanation.
What activity is done first when preparing for an initial certification audit?
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27001:2022 standards and certification guidance:
Before a certification audit can begin, the scope of the ISMS must be clearly defined and agreed with the Certification Body. ISO/IEC 27001 Clause 4.3 requires: ''The scope shall be available as documented information.''
Certification Bodies require this scope statement to plan audit duration, resources, and coverage. Only after the scope is agreed does the Stage 1 audit begin, which reviews documented information and readiness. Stage 2 focuses on implementation and effectiveness. Evidence of corrective actions (C) is checked at Stage 2 if issues were identified earlier. Records provision (D) occurs during Stage 2, not first.
Thus, the first step in preparing for certification is A: Agreeing the scope of the ISMS with the Certification Body auditor.
Identify the missing word in the following sentence.
According to ISO/IEC 27000, the definition of risk [?] is a ''process to comprehend the nature of risk and to determine the level of risk.''
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27000 standards:
ISO/IEC 27000 defines:
Risk analysis: ''process to comprehend the nature of risk and to determine the level of risk'' (Clause 3.58).
Risk assessment: the overall process of risk identification, risk analysis, and risk evaluation.
Risk evaluation: compares results of risk analysis against risk criteria to determine priority.
Risk management: coordinated activities to direct and control an organization with regard to risk.
Therefore, the missing word in the given definition is ''analysis''.
This is important for ISMS implementation: organizations must understand the distinctions. Risk analysis is the core technical evaluation stage, while assessment is the broader process including evaluation, and management refers to the overall governance of risks.
Thus, the correct verified answer is B: Analysis.
Which statement is a factor that will influence the implementation of the information security management system?
ISO/IEC 27001 makes clear that the ISMS is intended to be tailored to the organization. The standard states: ''This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations regardless of type, size or nature.'' This means implementation is scaled based on each organization's risk, context, and needs, not a fixed one-size-fits-all set of activities or controls. Clause 6.1.3 further reinforces that control selection is flexible and risk-driven: ''Organizations can design controls as required or identify them from any source,'' and ''Annex A contains a list of possible information security controls... The information security controls listed in Annex A are not exhaustive and additional information security controls can be included if needed.'' Together, these extracts verify that the ISMS implementation is influenced by and scaled to the organization's needs and selected controls, not separated from management processes (A, D) nor mandated to include ''all controls'' (B).
In which clause would the requirements for internal audit be found?
The requirements for internal audit are explicitly placed in Clause 9.2 (Performance Evaluation) of ISO/IEC 27001:2022. The standard requires:
''The organization shall conduct internal audits at planned intervals to provide information on whether the information security management system... conforms to the organization's own requirements... and to the requirements of this document.'' (9.2.1)
''The organization shall plan, establish, implement and maintain an audit programme(s)...'' (9.2.2)
This clause clearly falls under Performance Evaluation (Clause 9), not Planning (Clause 6), Operation (Clause 8), or Improvement (Clause 10). Therefore, the correct answer is C.
Which activity is a required element of information security risk identification?
Clause 6.1.2 defines the mandatory elements of risk assessment. Under risk identification, the standard requires: ''identifies the information security risks: 1) apply the information security risk assessment process to identify risks...; and 2) identify the risk owners.'' By contrast, considering likelihood and determining levels of risk (options B and D) are part of risk analysis (6.1.2 d) ''assess the realistic likelihood...''; ''determine the levels of risk''), and prioritization for treatment (option C) is part of risk evaluation (6.1.2 e) ''prioritize the analysed risks for risk treatment''). Therefore, the specific activity that belongs to risk identification is to identify the risk owners. This sequencing is prescribed to ensure each risk has a designated owner responsible for decisions on treatment and acceptance downstream.
Get access to all 50 verified questions with detailed answers.
Unlock All ISO-IEC-27001-Foundation Questions