wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Certiprof ISO 27001 Foundation - Simulation

Total questions: 40

Worksheet time: 20mins

Name
Class
Date
1.

Clause 6.1 (Actions to Address Risks and Opportunities) has some common strategies among the risk treatment options, which one(s) of the following are valid:

a)

A. Transfer.

b)

B. Mitigate.

c)
  • C. Assume.

d)
  • D. All of the above.

2.

The activity within the ISMS of approving and securing the necessary resources for the ISMS is a responsibility of:

a)

A. The IT Security Manager.

b)

B. The IT Manager.

c)
  • C. The person responsible for the QMS.

d)
  • D. The top management.

3.

The activity within the ISMS of ensuring the integration of information security management system requirements into the organization's processes is the responsibility of:

a)

A. The top management.

b)

B. The IT Security Manager.

c)
  • C. The person responsible for the QMS.

d)
  • D. The Operations Manager.

4.

What control is required for documented information?

a)

Each document is classified as an asset.

b)
  1. Records must be retained for three years.

c)
  1. Documents are protected from loss of integrity.

d)
  1. Only the owner of the document can update the document.

5.

Which of the following activities correspond to top management responsibilities?

a)
  • Ensure compliance with the information security policy.

b)
  • Allocate resources necessary to maintain the system.

c)
  • Supporting the drive for continuous improvement.

d)

All of the above.

6.

The information security policy must be known by:

a)
  • IT Security Manager.

b)
  • Everyone.

c)
  1. QMS manager.

d)
  1. IT Manager.

7.

The activity within the ISMS of communicating the importance of effective information security management and compliance with ISMS requirements is a responsibility of:

a)

The top management.

b)

The IT Security Manager.

c)
  • The person responsible for the QMS.

d)
  • The IT Manager.

8.

Who is required to perform the review of the ISMS to ensure its suitability, adequacy and effectiveness?

a)

Top management.

b)

The external company performing the certification audit.

c)
  • The process owners.

d)
  • The internal audit team.

9.

Identify the missing words in the following sentence.

The organization shall establish, ........................……. security management system.

a)

Operate, review.

b)

Manage, check.

c)

Implement, maintain.and continually improve an information

d)

Monitor, measure.

10.

What should be taken into account in determining the scope of the information security management system?

a)
  • The results of the gap analysis.

b)
  • Legal, regulatory, contractual requirements.

c)
  • The objectives of the organization.

d)

All of the above.

11.

What aspects should be considered to determine the scope of the ISMS?

a)

External and internal issues.

b)

Assets and resources.

c)
  1. Risks and opportunities.

  2. Threats and

d)
  1. vulnerabilities.

12.

In ISO/EC 27001, what does the information security risk assessment process refer to?

a)
  1. Identify risk owners.

b)
  1. Identify security risks.

c)
  • Establish and maintain information security risk criteria.

d)
  • All of the above.

13.

Which of the following benefits are not fully maximized by implementing an ISMS?

a)

Provide consistent management and operation of information security throughout the organization.

b)
  • Increasing the confidence of interested parties in the organization.

c)
  • Eliminate all information security vulnerabilities in the organization.

d)
  • Reducing the probability of information security incidents.

14.

Which of the following should be included in the ISMS policy?

a)

The deadline for the implementation of the ISMS.

b)
  1. The certificate of previous audits.

c)
  1. The result of a gap analysis.

d)
  1. A commitment to continual improvement of the ISMS.

15.

What does ISO 27001 require for information security risk assessment?

a)
  • A. Implement an information security risk assessment process that establishes and maintains information security risk criteria.

b)
  • To acquire a set of information security tools that allow the assessment to be done automatically using artificial intelligence.

c)
  • A manager appointed by top management.

d)

A consultancy to perform information security risk assessment in a professional manner.

16.

What details should be contained in a Statement of Applicability?

a)

A. Justification for exclusion of controls.

b)

B. Justification for inclusion of controls.

c)

• C. Necessary controls.

d)

D. All of the above.

17.

What does the ISO 27001 standard require for the treatment of information security risks?

a)
  • Perform an information security risk treatment process to select appropriate information security risk treatment options taking into account the results of the risk assessment.

b)
  • A consultancy to carry out precisely the treatment of information security risks.

c)
  • A manager appointed by the top management to carry out the information security risk treatment under his expertise.

d)

To acquire a set of information security tools to automate the treatment of risks.

18.

Which statement describes the critical success factors of an information security management system (ISMS)?

a)

Conduct a second party audit.

b)

Hire an information security coordinator.

c)

Implementing a measurement system used to evaluate information security management performance that can provide suggestions for improvement.

d)

Appoint at least two internal auditors for the information security system.

19.

What does ISO 27001 require for the control of documented information?

a)
  • A responsible person designated by the top management to carry out the control of documented information under his expertise.

b)
  • Acquire a set of information security tools to control documented information effectively.

c)
  • A consultancy to accurately perform the control of documented information.

d)

Adequate protection, e.g., against loss of confidentiality, misuse, or loss of integrity.

20.

According to ISO/EC 27001 it is necessary to ensure that the information security management system can achieve its intended results.

a)

It is only an observation to take into account when auditing the management system.

b)
  • It is a requirement to be fulfilled.

c)
  • It is a recommendation, but not a requirement.

d)
  • D. None of the above.

21.

What does ISO 27001 require to assess information security performance and the effectiveness of the information security management system?

a)

A consultancy to accurately perform the information security performance assessment and validate the effectiveness of the management system.

b)

Information security tools to assess information security performance and system effectiveness.

c)

A manager appointed by top management to perform the evaluation of the information security performance and the effectiveness of the management system.

d)

Determination by the organization of what needs to be monitored and what needs to be measured, including information security processes and controls.

22.

How should top management provide evidence of its commitment to the ISMS?

a)
  • By defining a risk assessment approach.

b)
  • Conducting an annual internal audit of the information security management system.

c)
  1. Communicating the importance of complying with the ISMS requirements.

d)
  1. By approving the information security management system once it has been established.

23.

The activity within the ISMS of ensuring that the information security policy and objectives are established and are consistent with the strategic direction of the organization is the responsibility of:

a)
  • The IT manager.

b)
  • The top management.

c)

The ISMS implementation consultant.

d)

The ISMS manager.

24.

Which relevant factor should be considered in internal audit programs?

a)
  • Number of third-party suppliers involved in the area to be audited.

b)
  • Ensure that audits are conducted at least twice during the first year of implementation of the information security management system.

c)
  • Availability of the certification body's auditors.

d)

Audit programs should take into account the importance of the processes involved and the results of previous audits.

25.

Which statement describes the difference between ISO/IEC 27001 and ISO/IEC 27002?

a)
  • A. ISO/IEC 27002 provides guidance on measurement and ISO/IEC 27001 provides guidance on information security controls.

b)
  • B. ISO/EC 27002 contains mandatory requirements, while ISO/IEC 27001 provides guidance on information security controls.

c)
  • C. ISO/EC 27001 contains mandatory requirements, while ISO/IEC 27002 provides guidance on information security controls.

d)
  • D. ISO/EC 27002 provides mandatory requirements for a risk management approach, ISO/IEC 27001 contains mandatory requirements for an ISMS.

26.

Annex A of the ISO/IEC 27001:2022 consists of:

a)

• A. Elements necessary for good ISMS design and implementation.

b)

B. A comprehensive list of controls grouped into domains.

c)

• C. Guidelines for risk management.

d)

D. None of the above.

27.

What control is required for documented information?

a)

Each document is classified as an asset.

b)
  1. Records must be retained for three years.

c)
  1. Documents are protected from loss of integrity.

d)
  1. Only the owner of the document can update the document.

28.

Which of the following should be included in the ISMS policy?

a)
  • A. The name of the intrusion detection system.

b)
  • B. The information security objectives.

c)
  • C. The results of previous audits.

d)

D. The history of the company with the motivation for implementing the ISMS.

29.

What does ISO 27001 require about the information security policy?

a)

The information security policy must be available as documented information.

b)
  1. It must be available to interested parties.

c)
  1. Be appropriate and communicated within the organization.

d)
  1. All of the above.

30.

Which of the following benefits are not fully maximized by implementing an ISMS?

a)

To prevent information security incidents altogether.

b)
  1. Satisfy social needs and expectations.

c)
  1. Increasing confidence in the organization by interested parties.

d)
  1. Promoting good information security practices.

31.

During the operation of the ISMS, what is the requirement for information security objectives?

a)

• A. Maintain documented information on objectives.

b)

B. Ensure that the objectives are consistent with the information security policy.

c)

• C. Develop improvement plans using ISO 27002 that enable information security objectives to be met.

d)

D. Establish objectives for relevant functions and levels.

32.

What does ISO 27001 require to establish the information security policy?

a)
  • A. To acquire software containing policies that fit the management system to be implemented.

b)
  • B. A consultancy to determine the best way.

c)
  • C. Include a commitment by top management to continually improve the information security management system.

d)

D. An initial audit to know the current status of the quality management system.

33.

The management review shall include consideration of:

a)
  • A. Changes in external and internal issues that are relevant to the ISMS.

b)
  • B. The status of actions since previous management reviews.

c)
  • C. Opportunities for continual improvement.

d)

D. All of the above.

34.

Which of the following activities correspond to top management responsibilities?

a)
  • A. Motivate employees to contribute to the effectiveness of the ISMS.

b)
  • B. Approve and secure the necessary resources for the ISMS.

c)
  • Establish the appropriate conditions for the involvement of employees in the achievement of the organization's information security objectives.

d)
  • D. All of the above.

35.

What are the three main aspects of information security?

a)
  • Durability, auditability, confidentiality.

b)
  1. Confidentiality, integrity, availability.

c)
  • B. Confidentiality, recoverability, integrity.

d)
  1. Non-repudiation, Authenticity, Accountability.

36.

According to the terms and definitions associated with ISO 27001, Effectiveness is defined as:

a)
  • A. Property relating to consistency in behavior and desired results.

b)
  • Extent to which planned activities are carried out and planned results are achieved

c)
  • C. Ability to corroborate that the claim that a certain event occurred or a certain action was performed by the originating entities is true.

d)
  • D. None of the above.

37.

Focusing on clause 4.3 (Determination of the scope of the Information Security Management System), what should the organization consider when determining the scope of the ISMS?

a)

A. The external and internal issues referred to in clause 4.1.

b)

B. The requirements referred to in section 4.2.

c)
  • C. The interfaces and dependencies between the activities performed by the organization and those performed by other organizations.

d)
  • D. All of the above.

38.

What does ISO 27001 require for scoping the information security management system?

a)
  • A. Acquire a set of security tools.

b)
  • B. Consider organizational boundaries, information systems boundaries and physical

c)
  • C. Processes, Technology, People.

d)
  • D. All of the above.

39.

According to ISO IEC 27001:2022, supporting the drive for continuous improvement is

considered a responsibility of the IT manager in the organization. This statement is:

a)

True

b)

False

40.

According to ISO/IEC 27001:2022 in its clause 9.3, The internal audit team is required to

review the ISMS to ensure its suitability, adequacy and effectiveness. This statement is:

a)

True

b)

False