wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Certiprof ISO27001 Foundation - Exercise

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

According to ISO IEC 27001:2022 Clause 4.3, external and internal issues, interfaces and

dependencies must be considered to define the ISMS scope.

This statement is:

a)

True

b)

False

2.

According to ISO IEC 27001:2022, the information security risk assessment process requires

identifying risk owners and establishing and maintaining information security risk criteria.

This statement is:

a)

True

b)

False

3.

Which statement describes the benefits of an information security management system?

a)

An aid to management in structuring its approach to information security management.

b)

Enables organizations to properly manage disruptive incidents.

c)

Allows the organization to focus on containing the impact caused by information security incidents.

d)

An aid in the identification of nonconformities during audits.

4.

Appointing at least two internal auditors for the information security system is described as a

critical success factor of an information security management system (ISMS). This statement is:

a)

Trus

b)

False

5.

Implementing an effective information security awareness, training, and education program is

described as a critical success factor of an information security management system (ISMS).

This statement is:

a)

True

b)

False

6.

ISO IEC 27001:2022 requires information security objectives to be part of:

a)

Internal audits.

b)

ISMS reviews.

c)

The information security policy.

d)

The SoA.

7.

According to ISO IEC 27001:2022 in its clause 9.3 Management review, communicating the

importance of complying with the requirements of the ISMS is a top management responsibility

concerning the ISMS:

a)

True

b)

False

8.

According to ISO IEC 27001:2022 in clause 5.1 Leadership and Commitment, how should top

management provide evidence of their commitment to the ISMS?

a)

A) Promoting continuous improvement.

b)

B) Directing and supporting people to contribute to the effectiveness of the information security

management system.

c)

A & B are correct.

d)

None is requested by clause 5.1.

9.

According to ISO IEC 27001:2022 in clause 9.3, the objective of the top management review of

the ISMS is to ensure its suitability, adequacy, and continuing effectiveness.

a)

True

b)

False

10.

According to ISO IEC 27001:2022 the SoA must contain:

1. Evidence of senior management authorization of controls.

2. A list of the risks applicable to the organization.

3. The necessary controls with their justifications for inclusion and exclusion.

4. The information security policy.

a)

(A) Only 3.

b)

(B) 2 and 4.

c)

(C) Only 1.

d)

(D) All of correct

11.

According to ISO IEC 27001:2022 a Statement of Applicability should include a justification for

exclusion and inclusion of controls considered necessary.

a)

True

b)

False

12.

According to ISO IEC 27001:2022 the interfaces and dependencies between the activities

performed by the organization and those performed by other organizations must be considered in

determining the scope of the information security management system. This statement is:

a)

True

b)

False

13.

According to ISO IEC 27001:2022, supporting the drive for continuous improvement is

considered a responsibility of the IT manager in the organization. This statement is:

a)

True

b)

False

14.

Which of the following does not correspond to the phases of the PDCA cycle?

1. Plan

2. Do.

3. Assure.

4. Act.

a)

(A): 1

b)

(B): 2

c)

(C): 3

d)

(D): 4

15.

According to ISO IEC 27001:2022 clause 7.4 Communication, the activity within the ISMS of

communicating the importance of effective information security management and compliance with the

requirements of the ISMS is a responsibility of the IT manager.

(A): False.

(B): True.

a)

True

b)

False

16.

According to ISO IEC 27001:2022 Clause 5.2, the information security policy should:

a)

(A): Be available as documented information.

b)

(B): Be communicated within the organization.

c)

(C): Be available to interested parties, as appropriate.

d)

(D): All of the above.

17.

According to ISO IEC 27001:2022, regarding risk management, the organization shall:

a)

(A): Define and implement an information security risk assessment process.

b)

(B): Define and implement an information security risk treatment process.

c)

(C): Maintain documented information on information security risk assessment and risk treatment

processes.

d)

(D): All of the above.

18.

According to ISO IEC 27001:2022, regarding clause 7.5 documented information, the

organization shall ensure:

1. That it is available and ready for use, where and when needed.

2. That it is adequately protected (e.g., against loss of confidentiality, misuse, or loss of integrity).

3. To perform activities as applicable to ensure the preservation of legibility.

a)

(A): Only 1 is valid

b)

(B): 1 and 3 are valid.

c)

(C): None since clause 7.5 does not refer to documented information of an ISMS.

d)

(D): All are valid.

19.

According to ISO IEC 27001:2022, regarding clause 9.1 Monitoring, Measurement, Analysis

and Evaluation, the organization shall define:

1. What needs to be tracked and measured, including information security processes and controls.

2. The methods of monitoring, measurement, analysis, and evaluation, as applicable, to ensure valid results.

a)

(A): Only 1 is valid.

b)

(B): Only 2 is valid.

c)

(C): None since clause 9.1 does not refer to the Monitoring, Measurement, Analysis, and Evaluation of an

ISMS.

d)

(D): All are valid.

20.

According to ISO IEC 27001:2022, regarding clause 9.1 Internal audits, the organization shall:

1. Plan, establish, implement and maintain an audit program(s) that includes frequency, methods,

responsibilities, planning requirements, and reporting.

2. Audit programs should consider the importance of the processes involved and the results of previous

audits.

3. Conduct internal audits at planned intervals, to provide information about the information security

management system.

a)

(A): Only 1 is valid.

b)

(B): Only 2 is valid.

c)

(C): None since clause 9.1 does not refer to internal audits.

d)

(D): All are valid.

21.

ISO/IEC 27002:2022 provides mandatory requirements for a risk management approach, while

ISO/IEC 27001:2022 contains mandatory requirements for an ISMS. This statement is:

a)

True

b)

False

22.

ISO/IEC 27001:2022 contains mandatory requirements, while ISO/IEC 27002:2022 provides

guidance on information security controls. This statement is:

a)

True

b)

False

23.

According to ISO IEC 27001:2022, regarding clause 8.3 Treatment of Information Security

Risks, the organization shall:

1. Implement the information security risk management plan.

2. Retain documented information on the results of the treatment of information security risks.

a)

(A): Only 1 is valid.

b)

(B): Only 2 is valid.

c)

(C): None, since clause 8.3 does not refer to the Information Security risk treatment plan.

d)

(D): All are valid.

24.

According to ISO/IEC 27001:2022 in its clause 9.3, The internal audit team is required to

review the ISMS to ensure its suitability, adequacy and effectiveness. This statement is:

a)

True

b)

False

25.

According to ISO/IEC 27001:2022, the organization shall establish, maintain and continually

improve an information security management system. This statement is:

a)

True

b)

False

26.

According to ISO/IEC 27001:2022 regarding clause 7.5 Documented Information, the

organization shall ensure, as appropriate:

1. Identification and description (e.g., title, date, author or reference number).

2. Format (e.g., language, software version, graphics) and its media (e.g., paper, electronic).

3 The review and approval regarding suitability and adequacy.

a)

(A): Only 1 is valid.

b)

(B): Only 2 is valid.

c)

(C): None since clause 7.5 does not refer to the treatment of documented information of an ISMS.

d)

(D): All are valid.

27.

 ISO/IEC 27001:2022 regarding clause 6.1 actions to address risks and opportunities, states

that mitigate, assume, share and eliminate are:

a)

(A): Risk treatment options.

b)

(B): The classification of controls in Appendix A.

c)

(C): Risk classification for the SOA.

d)

(D): All are valid.

28.

Durability, Integrity and Confidentiality are the three main aspects of information security. This

statement is:

a)

True

b)

False

29.

In ISO IEC 27001:2022, which clause states that the organization shall conduct internal audits

at planned intervals, to provide information about the information security management system:

a)

(A): Clause 9.1

b)

(D): None of the above.

c)

(C): Clause 9.3

d)

(B): Clause 9.2

30.

In ISO IEC 27001:2022, which clause states that the organization shall determine the

necessary competence of persons who perform, under its control, work that affects its information

security performance:

a)

(A): Clause 7.1

b)

(B): Clause 7.2

c)

(C): Clause 7.3

d)

(D): Clause 7.4

31.

In ISO IEC 27001:2022, which clause states that the organization must identify the risks

associated with the loss of confidentiality, integrity and availability of information:

a)

(A): Clause 6.1

b)

(B): Clause 6.2

c)

(C): Clause 6.3

d)

(D): Clause 6.4

32.

In ISO IEC 27001:2022, the definition of _________________ is the property that an entity is

what it claims to be.

a)

(A): Authenticity.

b)

(B): Verification.

c)

(C): Authorization.

d)

(D): Validation.

33.

In ISO IEC 27001:2022, ____________________ is defined as a systematic, independent and

documented process for obtaining audit evidence and evaluating it objectively to determine the extent to

which audit criteria are met.

a)

(A): Audit.

b)

(B): Senior Management Review.

c)

(C): Information security policy.

d)

(D): ISO IEC 27001:2022 Standard.

34.

The _____________________ standard has been designed to "provide requirements for

establishing, implementing, maintaining and continually improving an information security management

system".

a)

(A): 31000:2018

b)

(B): 19011:2018

c)

(C): 27002:2022

d)

(D): 27001:2022

35.

In ISO IEC 27001:2022 in clause 4.3, during the determination of the Scope of the Information

Security Management System the _________ and the ____________ should be considered.

a)

(A): The external and internal dependencies mentioned in section 4.1 and the risks mentioned in section

4.2.

b)

(B): Stakeholders and risks surrounding the organization.

c)

(C): Stakeholders and requirements.

.

d)

(D): The external and internal issues mentioned in section 4.1 and the requirements mentioned in section

4.2

36.

According to ISO IEC 27001:2022, ________________ is defined as the risk remaining after risk

treatment.

a)

(A): Secondary risk.

b)

(B): Security incident.

c)

(C): Vulnerability.

d)

(D): Residual Risk

37.

According to ISO IEC 27001:2022, ________________ during its ________________ should include

considerations on:

Changes in external and internal issues that are relevant to the ISMS.

The status of actions since previous management reviews.

Opportunities for continuous improvement.

a)

(A): Senior Management during its internal audit.

b)

(B): Auditors during their internal audit.

c)

(C): Top Management during its ISMS review.

d)

(D): Auditors during their ISMS review.

38.

In ISO IEC 27001:2022, which clause states that the organization shall determine the need for

internal and external communications relevant to the information security management system.

a)

(A): Clause 7.1

b)

(B): Clause 7.2

c)

(C): Clause 7.3

d)

(D): Clause 7.4

39.

In ISO IEC 27001:2022, which clause states that people working under the control of the

organization should be aware of the information security policy.

a)

(A): Clause 7.1

b)

(B): Clause 7.2

c)

(C): Clause 7.3

d)

(D): Clause 7.4

40.

In ISO IEC 27001:2022, which clause states that when a nonconformity occurs, the

organization shall react to the nonconformity, and deal with the consequences.

a)

(A): Clause 10.1

b)

(B): Clause 10.2

c)

(C): Clause 9.2

d)

(D): Clause 9.3