Weekend Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

ISO-IEC-27001-Foundation Questions and Answers

Question # 6

What is the definition of the term ‘integrity’ according to ISO/IEC 27000?

A.

The property of being accessible and usable

B.

The property that information is NOT made available inappropriately

C.

The property of accuracy and completeness

D.

The property of availability and confidentiality

Full Access
Question # 7

Which attribute is NOT a required focus of continual ISMS improvement?

A.

Adequacy

B.

Effectiveness

C.

Suitability

D.

Importance

Full Access
Question # 8

Which statement describes the control for the Compliance with policies, rules and standards for information security within Annex A of ISO/IEC 27001?

A.

Regular review of compliance

B.

Regular review of contractual compliance

C.

Maintain contact with legal authorities

D.

Return assets to their legal owners

Full Access
Question # 9

Identify the missing words in the following sentence.

The organization shall establish, implement, maintain and [ ? ] an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.

A.

report on

B.

continually improve

C.

communicate the importance of

D.

enforce standards for

Full Access
Question # 10

What is required to be reported by the Information security event reporting control?

A.

Information disclosure

B.

Unauthorized access

C.

Asset disposal

D.

Observed or suspected events

Full Access
Question # 11

Which of the following is required to be considered when selecting appropriate information security risk treatment options?

A.

Criteria for accepting identified risks

B.

Criteria for performing risk assessments

C.

Only risk controls in Annex A of ISO/IEC 27001

D.

Only risk controls in ISO/IEC 27002

Full Access
Question # 12

Which action is a required response to an identified residual risk?

A.

By default, it shall be controlled by information security awareness and training

B.

Top management shall delegate its treatment to risk owners

C.

It shall be reviewed by the risk owner to consider acceptance

D.

The organization shall change practices to avoid the risk occurring

Full Access
Question # 13

Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?

A.

Identify products which could be used in the organization to improve ISMS performance and effectiveness

B.

Ensure all personnel are trained to ISO/IEC 27001 Foundation level

C.

Ensure that the controls for compliance with legal and contractual requirements are implemented

D.

Hold up-to-date records on training, skills, experience and qualifications

Full Access
Question # 14

What international standard provides guidance on the integration of ISO/IEC 27001 and the IT Service Management standard?

A.

ISO/IEC 27002

B.

ISO/IEC 27013

C.

ISO/IEC 20000-1

D.

None of the above

Full Access
Question # 15

Identify the missing word in the following sentence.

The organization shall determine the [ ? ] of interested parties relevant to information security.

A.

requirements

B.

number

C.

structure

D.

influence

Full Access