Spring Sale - Special 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: 70dumps

I27001F Questions and Answers

Question # 6

According to ISO/IEC 27001:2022, is it necessary to formulate an information security risk treatment plan?

A.

It is only an observation to keep in mind when auditing the management system

B.

It is a requirement to be fulfilled

C.

It is a recommendation, but not a requirement

D.

None of the above

Full Access
Question # 7

According to the terms and definitions associated with ISO 27001, authenticity is defined as:

A.

The property of consistency in behaviour and intended results

B.

The property that an entity is what it claims to be

C.

The ability to prove that a claimed event has occurred or that a claimed action was performed by the entities that originated it

D.

None of the above

Full Access
Question # 8

During the operation of the ISMS, what is a requirement for information security objectives?

A.

Develop improvement plans using ISO/IEC 27002 to achieve the information security objectives

B.

Maintain documented information about the objectives

C.

Ensure that the objectives are consistent with the information security policy

D.

Establish objectives for relevant functions and levels

Full Access
Question # 9

Within the ISMS, communicating the importance of effective information security management and of conforming to the ISMS requirements is a responsibility of:

A.

The IT Security Manager

B.

Top management

C.

The IT Manager

D.

The quality management representative

Full Access
Question # 10

What are the phases of the PDCA cycle?

A.

Plan, Validate, Verify, Act

B.

Plan, Do, Check, Act

C.

Plan, Do, Verify, Assure

D.

Propose, Do, Validate, Act

Full Access
Question # 11

What does ISO/IEC 27001:2022 require for internal audits?

A.

A person designated by top management who can perform internal audits in all areas within the system scope

B.

Acquisition of a set of information security tools to document internal audits

C.

Conducting internal audits at planned intervals to provide information on whether the Information Security Management System conforms to the organization’s own requirements and to the requirements of ISO/IEC 27001:2022

D.

A consultancy to perform second-party internal audits accurately

Full Access
Question # 12

What relevant factor must be considered in internal audit programmes?

A.

Availability of the certification body auditors

B.

Ensuring that audits are carried out at least twice during the first year of ISMS implementation

C.

The importance of the processes concerned and the results of previous audits

D.

The number of third-party suppliers involved in the area to be audited

Full Access