Limited-Time Offer: Enjoy 50% Savings! - Ends In 0d 00h 00m 00s Coupon code: 50OFF
Free Exam Questions

ISO-IEC-27001-Foundation Exam Questions & Answers

ISO/IEC 27001 (2022) Foundation Exam  •  APMG-International

50 Questions 120 min Updated Sep 2026 99% Pass Rate
Get Full Access

100% money-back guarantee

Sample ISO-IEC-27001-Foundation Questions

Practice with real exam-style questions, each with the verified correct answer and explanation.

Q1 MultipleChoice

What activity is done first when preparing for an initial certification audit?

Correct Answer: A
Explanation:

Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27001:2022 standards and certification guidance:

Before a certification audit can begin, the scope of the ISMS must be clearly defined and agreed with the Certification Body. ISO/IEC 27001 Clause 4.3 requires: ''The scope shall be available as documented information.''

Certification Bodies require this scope statement to plan audit duration, resources, and coverage. Only after the scope is agreed does the Stage 1 audit begin, which reviews documented information and readiness. Stage 2 focuses on implementation and effectiveness. Evidence of corrective actions (C) is checked at Stage 2 if issues were identified earlier. Records provision (D) occurs during Stage 2, not first.

Thus, the first step in preparing for certification is A: Agreeing the scope of the ISMS with the Certification Body auditor.

Q2 MultipleChoice

Identify the missing word in the following sentence.

According to ISO/IEC 27000, the definition of risk [?] is a ''process to comprehend the nature of risk and to determine the level of risk.''

Correct Answer: B
Explanation:

Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27000 standards:

ISO/IEC 27000 defines:

Risk analysis: ''process to comprehend the nature of risk and to determine the level of risk'' (Clause 3.58).

Risk assessment: the overall process of risk identification, risk analysis, and risk evaluation.

Risk evaluation: compares results of risk analysis against risk criteria to determine priority.

Risk management: coordinated activities to direct and control an organization with regard to risk.

Therefore, the missing word in the given definition is ''analysis''.

This is important for ISMS implementation: organizations must understand the distinctions. Risk analysis is the core technical evaluation stage, while assessment is the broader process including evaluation, and management refers to the overall governance of risks.

Thus, the correct verified answer is B: Analysis.

Q3 MultipleChoice

Which statement is a factor that will influence the implementation of the information security management system?

Correct Answer: C
Explanation:

ISO/IEC 27001 makes clear that the ISMS is intended to be tailored to the organization. The standard states: ''This document also includes requirements for the assessment and treatment of information security risks tailored to the needs of the organization. The requirements set out in this document are generic and are intended to be applicable to all organizations regardless of type, size or nature.'' This means implementation is scaled based on each organization's risk, context, and needs, not a fixed one-size-fits-all set of activities or controls. Clause 6.1.3 further reinforces that control selection is flexible and risk-driven: ''Organizations can design controls as required or identify them from any source,'' and ''Annex A contains a list of possible information security controls... The information security controls listed in Annex A are not exhaustive and additional information security controls can be included if needed.'' Together, these extracts verify that the ISMS implementation is influenced by and scaled to the organization's needs and selected controls, not separated from management processes (A, D) nor mandated to include ''all controls'' (B).

Q4 MultipleChoice

In which clause would the requirements for internal audit be found?

Correct Answer: C
Explanation:

The requirements for internal audit are explicitly placed in Clause 9.2 (Performance Evaluation) of ISO/IEC 27001:2022. The standard requires:

''The organization shall conduct internal audits at planned intervals to provide information on whether the information security management system... conforms to the organization's own requirements... and to the requirements of this document.'' (9.2.1)

''The organization shall plan, establish, implement and maintain an audit programme(s)...'' (9.2.2)

This clause clearly falls under Performance Evaluation (Clause 9), not Planning (Clause 6), Operation (Clause 8), or Improvement (Clause 10). Therefore, the correct answer is C.

Q5 MultipleChoice

Which activity is a required element of information security risk identification?

Correct Answer: A
Explanation:

Clause 6.1.2 defines the mandatory elements of risk assessment. Under risk identification, the standard requires: ''identifies the information security risks: 1) apply the information security risk assessment process to identify risks...; and 2) identify the risk owners.'' By contrast, considering likelihood and determining levels of risk (options B and D) are part of risk analysis (6.1.2 d) ''assess the realistic likelihood...''; ''determine the levels of risk''), and prioritization for treatment (option C) is part of risk evaluation (6.1.2 e) ''prioritize the analysed risks for risk treatment''). Therefore, the specific activity that belongs to risk identification is to identify the risk owners. This sequencing is prescribed to ensure each risk has a designated owner responsible for decisions on treatment and acceptance downstream.

Get access to all 50 verified questions with detailed answers.

Unlock All ISO-IEC-27001-Foundation Questions

Frequently Asked Questions

The ISO/IEC 27001 Foundation certification is an entry-level credential offered by APMG-International that validates knowledge of information security management systems (ISMS) based on the ISO/IEC 27001:2022 standard. It demonstrates understanding of the fundamental principles, requirements, and implementation of ISMS within organizations.

There are no formal prerequisites for taking the ISO/IEC 27001 Foundation exam. However, it is recommended that candidates have basic knowledge of information security concepts and understand their organization's security practices before attempting the certification.

The ISO/IEC 27001 Foundation exam typically consists of 40 multiple-choice questions and must be completed within 60 minutes. Candidates need to achieve a minimum score of 65% (26 out of 40 questions) to pass the exam.

The exam covers key topics including ISMS fundamentals, the Plan-Do-Check-Act (PDCA) cycle, risk management processes, control objectives and controls from Annex A, compliance requirements, and organizational implementation of ISO/IEC 27001:2022 standards. It focuses on understanding rather than in-depth technical expertise.

Candidates can prepare through official APMG-International training courses, self-study using the ISO/IEC 27001:2022 standard documentation, study guides, practice exams, and online learning platforms. It is recommended to dedicate 20-30 hours of study time and review sample questions to become familiar with the exam format.
Exam Details
  • Exam CodeISO-IEC-27001-Foundation
  • VendorAPMG-International
  • Total Questions50
  • Duration120 min
  • LanguageEnglish
  • Last UpdatedSep 1, 2026
4.9/5

Pass ISO-IEC-27001-Foundation First Time

Get all 50 exam questions with verified answers and 90-day free updates.

Buy Now & Pass
  • PDF + Practice Test Bundle
  • 90-Day Free Updates
  • 100% Money-Back Guarantee
  • Instant Download
  • 24/7 Customer Support
99% Pass Rate Trusted by 50,000+ IT professionals