ISO 27000 Foundation Certification Exam — Questions and Answers
Question 1: What kind of action is necessary in light of the suggested residual risks?
- The ISMS implementation team shall re-assess them
- Residual risks can be ignored
- Risk owners shall approve their acceptance (Correct answer)
- Management shall transfer them to third parties
Correct answer: Risk owners shall approve their acceptance
After risk treatment, any remaining risks are considered residual risks. ISO 27001 requires that these residual risks be formally approved and accepted by the risk owners. This ensures accountability and acknowledges that some level of risk will always remain, and management has consciously decided to bear it.
Question 2: In ISO/IEC 27001, which party must formally approve the risk treatment plan and accept residual risks?
- Risk owners (Correct answer)
- Insurance providers
- External certification auditors
- The IT department head
Correct answer: Risk owners
Risk owners are responsible for approving the treatment plan for risks within their scope and formally accepting any residual risk.
Question 3: How should an organization handle metrics that consistently show 100% target achievement?
- Replace it with a financial cost-per-incident metric
- Increase the target or evaluate whether the metric still provides meaningful insight (Correct answer)
- Archive the metric and stop collecting it
- Report it as a success and take no further action
Correct answer: Increase the target or evaluate whether the metric still provides meaningful insight
Metrics that always show 100% may be set too loosely and should be challenged to ensure they still provide meaningful performance insight.
Question 4: A hacker sends a deceptive email pretending to be the CEO to trick an employee into transferring funds. This is an example of which attack type?
- Man-in-the-middle
- SQL injection
- Social engineering / phishing (Correct answer)
- Denial of Service
Correct answer: Social engineering / phishing
Phishing/social engineering attacks manipulate people into divulging information or performing actions by impersonating trusted entities.
Question 5: What is the primary purpose of ISO 27002 in relation to ISO 27001?
- It specifies requirements for cloud security
- It certifies organizations for ISMS compliance
- It defines the risk assessment methodology organizations must use
- It provides guidance on implementing the controls referenced in ISO 27001 Annex A (Correct answer)
Correct answer: It provides guidance on implementing the controls referenced in ISO 27001 Annex A
ISO 27002 is a code of practice that provides implementation guidance for the information security controls listed in ISO 27001 Annex A.
Question 6: What is the purpose of assigning information security roles and responsibilities in ISO 27001?
- To comply with software licensing rules
- To reduce the number of employees needed
- To create a security budget
- To ensure accountability and clarity in protecting information assets (Correct answer)
Correct answer: To ensure accountability and clarity in protecting information assets
Clearly defined roles and responsibilities ensure that every aspect of information security is owned, monitored, and actioned by specific individuals.
Question 7: Which statement about the relationship between threats and vulnerabilities is correct?
- A threat exploits a vulnerability to cause harm to an asset (Correct answer)
- Threats and vulnerabilities are interchangeable terms in ISO 27000
- A vulnerability causes harm without a threat present
- A threat is always internal; a vulnerability is always external
Correct answer: A threat exploits a vulnerability to cause harm to an asset
A threat acts as the agent that exploits an existing vulnerability to cause harm to an information asset.
Question 8: Which of the following best describes the concept of 'risk appetite' in ISO 27000?
- The amount and type of risk an organization is willing to pursue or retain (Correct answer)
- The budget allocated annually for information security controls
- The maximum financial loss an organization can sustain from a breach
- The list of risks that must always be avoided regardless of cost
Correct answer: The amount and type of risk an organization is willing to pursue or retain
Risk appetite is the amount and type of risk that an organization is willing to accept in pursuit of its objectives.
Question 9: A company decides to purchase a comprehensive cybersecurity insurance policy to cover potential financial losses from a data breach. Within the ISO 27000 framework for risk management, this action is an example of which risk treatment strategy?
- Risk acceptance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk avoidance
Correct answer: Risk transfer
Risk transfer, or risk sharing, involves moving the financial impact of a risk to a third party. Purchasing an insurance policy is a classic example of this, as the insurer agrees to bear some or all of the financial losses in exchange for premium payments.
Question 10: What document produced in the Plan phase specifies which risks will be treated and how?
- Information Security Policy
- Risk Treatment Plan (Correct answer)
- Statement of Applicability
- Business Continuity Plan
Correct answer: Risk Treatment Plan
The Risk Treatment Plan documents selected risk treatment options and the controls needed for each identified risk.
Question 11: Which scenario best illustrates the ISMS 'awareness' requirement under ISO 27001 Clause 7.3?
- All persons doing work under the organization's control understand the ISMS policy and their contribution to it (Correct answer)
- Awareness training is conducted only when a breach occurs
- Only the IT security team is briefed on the information security policy
- Vendors are responsible for their own staff awareness programs
Correct answer: All persons doing work under the organization's control understand the ISMS policy and their contribution to it
Clause 7.3 requires that all workers understand the policy, their role in achieving ISMS objectives, and the implications of non-conformity.
Question 12: Why is it mandatory for the scope of the ISMS to be maintained as documented information?
- To provide a clear basis for the information security risk assessment and to inform stakeholders. (Correct answer)
- To serve as the main input for the annual financial audit.
- To fulfill a legal requirement mandated by international trade agreements.
- To allow the marketing team to use it in promotional materials.
Correct answer: To provide a clear basis for the information security risk assessment and to inform stakeholders.
ISO/IEC 27001 Clause 4.3 explicitly states, 'The scope shall be available as documented information.' This documentation is crucial because it defines the boundaries for all subsequent ISMS activities, including risk assessment (Clause 6.1.2) and the creation of the Statement of Applicability. It also serves to clearly communicate the coverage of the ISMS to all stakeholders, including auditors, customers, and employees.
Question 13: What is the correct order of the first three phases in a typical information security incident response lifecycle?
- Detection and Identification → Containment → Eradication and Recovery (Correct answer)
- Eradication → Identification → Recovery
- Containment → Detection → Eradication
- Notification → Analysis → Containment
Correct answer: Detection and Identification → Containment → Eradication and Recovery
Incident response begins with detecting and identifying the incident, then containing its spread, and then eradicating the cause and recovering affected systems.
Question 14: In ISO 27000 terminology, which term refers to the combination of the probability of an event and its consequence?
- Risk (Correct answer)
- Threat
- Vulnerability
- Control
Correct answer: Risk
Risk is defined as the effect of uncertainty on objectives, typically expressed as the combination of likelihood and impact.
Question 15: Which of the following best describes 'risk transfer' as a risk treatment option?
- Accepting that the risk is within tolerance levels
- Moving risk responsibility to another party such as via insurance or outsourcing (Correct answer)
- Eliminating the asset that carries the risk
- Reducing the likelihood of a threat occurring
Correct answer: Moving risk responsibility to another party such as via insurance or outsourcing
Risk transfer involves shifting the financial or operational consequences of a risk to a third party, such as purchasing cyber insurance.
Question 16: In the PDCA model, what is the primary risk of skipping the 'Check' phase?
- The ISMS will become too expensive to operate
- Ineffective controls may go undetected, leaving the organization exposed (Correct answer)
- The risk treatment plan cannot be updated
- New employees will not receive security training
Correct answer: Ineffective controls may go undetected, leaving the organization exposed
Without Check phase activities, failed or ineffective controls are not identified, undermining the entire ISMS.
Question 17: According to ISO 27001, which of the following is the primary purpose of monitoring, measurement, analysis, and evaluation of the ISMS?
- To evaluate information security performance and the effectiveness of the ISMS. (Correct answer)
- To generate detailed reports exclusively for the annual external certification audit.
- To select and procure new security hardware and software based on performance data.
- To identify and discipline employees who do not comply with security policies.
Correct answer: To evaluate information security performance and the effectiveness of the ISMS.
ISO 27001 Clause 9.1 requires the organization to evaluate the information security performance and the effectiveness of the Information Security Management System (ISMS). This process provides the data needed for management reviews and continual improvement, ensuring the ISMS is achieving its intended outcomes.
Question 18: A multinational company defines its ISMS scope to cover only its US operations. Which obligation must it still consider?
- Implementing ISO 27001 in all regions immediately
- Interfaces with out-of-scope regions that could affect information security (Correct answer)
- It has no further obligations since the scope is limited
- Hiring separate security staff for each region
Correct answer: Interfaces with out-of-scope regions that could affect information security
Even with a limited scope, the organization must consider interfaces and dependencies with out-of-scope areas that could affect the ISMS's effectiveness.
Question 19: When implementing security controls, what does the term 'residual risk' mean?
- Risk that has been fully eliminated by controls
- Risk that was never identified during assessment
- Risk remaining after treatment measures have been applied (Correct answer)
- Risk transferred entirely to a third party
Correct answer: Risk remaining after treatment measures have been applied
Residual risk is the level of risk that persists after controls are implemented and cannot be fully eliminated.
Question 20: An organization operating in both healthcare and retail decides to certify only its healthcare division under ISO 27001. This is an example of:
- Defining ISMS scope by business unit or division (Correct answer)
- Mandatory industry-specific scoping
- Applying controls selectively without justification
- Non-compliance with ISO 27001 requirements
Correct answer: Defining ISMS scope by business unit or division
Scoping the ISMS to a specific business division is a legitimate and common approach, provided the scope boundaries and any exclusions are properly documented.
Question 21: A multinational corporation has an established ISMS certified to ISO/IEC 27001. To comply with evolving global data privacy regulations, the company wants to enhance its ISMS to specifically manage and protect Personally Identifiable Information (PII). Which ISO 27000 family standard provides a framework for a Privacy Information Management System (PIMS) as an extension to an ISMS?
- ISO/IEC 27017
- ISO/IEC 27701 (Correct answer)
- ISO/IEC 27005
- ISO/IEC 27032
Correct answer: ISO/IEC 27701
ISO/IEC 27701 is designed as a privacy extension to ISO/IEC 27001 and ISO/IEC 27002. It specifies requirements and provides guidance for establishing, implementing, and maintaining a Privacy Information Management System (PIMS), helping organizations manage PII and comply with privacy regulations. ISO/IEC 27017 is for cloud security, 27032 for cybersecurity, and 27005 for risk management.
Question 22: A company's ISMS management review reveals that its risk appetite has changed due to a merger. Which management review output addresses this?
- Decisions on continual improvement opportunities
- Actions to address nonconformities
- Decisions related to any need for changes to the ISMS (Correct answer)
- Decisions on resource needs
Correct answer: Decisions related to any need for changes to the ISMS
ISO 27001 Clause 9.3 includes 'any need for changes to the ISMS' as a required output when strategic context changes like a merger occur.
Question 23: As part of an ISO 27001 implementation, the Chief Executive Officer (CEO) of an organization publicly endorses the new information security policy and ensures that sufficient budget and personnel are allocated for the ISMS project. Which specific leadership responsibility from ISO 27001 is the CEO primarily demonstrating?
- Conducting the detailed information security risk assessment.
- Ensuring the integration of ISMS requirements into the organization’s processes and providing necessary resources. (Correct answer)
- Performing the daily backup and recovery operations.
- Writing the specific procedures for access control.
Correct answer: Ensuring the integration of ISMS requirements into the organization’s processes and providing necessary resources.
ISO 27001 Clause 5.1 ('Leadership and commitment') requires top management to demonstrate their commitment. This includes ensuring the information security policy and objectives are established, ensuring the integration of ISMS requirements into the organization's processes, and ensuring that the resources needed for the ISMS are available. The CEO's actions directly align with these high-level responsibilities. The other options are operational tasks typically delegated to security or IT teams.
Question 24: Which task must be completed while analyzing risks?
- Determine the likelihood of the occurrence of the risks (Correct answer)
- Accept all evaluated risks
- Identify the risks associated with loss of confidentiality
- Select appropriate controls
Correct answer: Determine the likelihood of the occurrence of the risks
Risk analysis, as a key part of the risk assessment process (Clause 6.1.2), involves identifying risks, determining their likelihood of occurrence, and evaluating their potential consequences. Determining the likelihood helps the organization understand the probability of a risk materializing, which is essential for prioritizing and selecting appropriate treatment options.
Question 25: An organization's internal audit of its ISMS was conducted by the IT systems administrators, who audited the server configurations and network access controls they had personally implemented. Which fundamental principle of ISO 27001's internal audit requirements has been violated?
- The need for objectivity and impartiality in the audit process. (Correct answer)
- The requirement for competence of the auditors.
- The requirement to audit at planned intervals.
- The need to maintain documented information of audit results.
Correct answer: The need for objectivity and impartiality in the audit process.
ISO 27001 Clause 9.2 requires that auditors be selected to ensure objectivity and impartiality of the audit process. Auditors cannot audit their own work, as it creates a conflict of interest and undermines the integrity and objectivity of the audit findings.
Question 26: An organization is establishing its ISMS according to ISO 27001 and is determining its 'interested parties' as required by Clause 4.2. Which of the following would be the LEAST likely to be considered a relevant interested party with requirements pertinent to the ISMS?
- The company's shareholders who are concerned about business continuity.
- A major customer who requires security assurances in their service contract.
- A government regulatory body that enforces data protection laws.
- A competitor company operating in the same market. (Correct answer)
Correct answer: A competitor company operating in the same market.
Interested parties are individuals or organizations that can affect, be affected by, or perceive themselves to be affected by the organization's ISMS. Regulators, customers, and shareholders have direct requirements and expectations for the organization's information security. While a competitor is part of the business environment, they do not typically have direct, legitimate requirements *for* the organization's ISMS that need to be addressed within its framework.
Question 27: Which of the following controls is primarily categorized under the 'Physical controls' theme (A.7) in ISO/IEC 27001:2022 Annex A?
- Securing offices, rooms, and facilities (Correct answer)
- Management of technical vulnerabilities
- Information security for use of cloud services
- Information security awareness, education, and training
Correct answer: Securing offices, rooms, and facilities
Securing offices, rooms, and facilities (A.7.3) is a core component of the 'Physical controls' theme. This theme is concerned with preventing unauthorized physical access, damage, and interference to the organization's premises and the information within them.
Question 28: Under ISO 27001, what must happen if a significant change occurs in the organization?
- No action is required until the next scheduled audit
- The ISMS certification is immediately revoked
- The ISMS scope and risk assessment must be reviewed and updated (Correct answer)
- Only the IT department needs to be notified
Correct answer: The ISMS scope and risk assessment must be reviewed and updated
ISO 27001 requires organizations to review their ISMS, including scope and risk assessment, whenever significant changes occur.
Question 29: Which of the following best describes a 'corrective action' under ISO 27001 Clause 10.1?
- A compensating control that mitigates residual risk
- A management directive to increase the security budget
- An action taken to eliminate the cause of a detected nonconformity (Correct answer)
- A preventive measure taken before any nonconformity occurs
Correct answer: An action taken to eliminate the cause of a detected nonconformity
A corrective action addresses the root cause of an identified nonconformity to prevent its recurrence, not just its immediate symptom.
Question 30: Which statement about ISMS audit independence is correct according to ISO 27001?
- Auditors may audit their own work if they are certified
- Auditors must be independent of the activities they audit (Correct answer)
- Only external auditors can be considered independent
- Independence is optional if the organization is small
Correct answer: Auditors must be independent of the activities they audit
ISO 27001 Clause 9.2 requires that auditors are selected to ensure objectivity and impartiality, meaning they cannot audit their own work.
Question 31: Which of the following is an administrative (managerial) information security control?
- Data encryption at rest
- Security awareness training programs (Correct answer)
- Biometric door locks
- Intrusion detection systems
Correct answer: Security awareness training programs
Administrative controls are policies, procedures, and training programs that govern people's behavior and organizational processes.
Question 32: An organization's server room lacks a fire suppression system. According to the vocabulary of ISO 27000, this deficiency is best described as a(n):
- Impact
- Risk
- Vulnerability (Correct answer)
- Threat
Correct answer: Vulnerability
A vulnerability is defined as a 'weakness of an asset or control that can be exploited by one or more threats'. The absence of a fire suppression system is a weakness in the physical protection of the server room asset, which could be exploited by a threat (i.e., a fire).
Question 33: In the ISMS operational context, what does 'operational planning and control' primarily require?
- Hiring a dedicated CISO for every department
- Planning, implementing, and controlling processes needed to meet security requirements (Correct answer)
- Outsourcing all IT operations to a managed service provider
- Conducting annual penetration tests only
Correct answer: Planning, implementing, and controlling processes needed to meet security requirements
ISO 27001 Clause 8 requires organizations to plan, implement, control, and review processes that address information security requirements.
Question 34: Which ISO 27001 clause specifically requires the organization to determine the scope of the ISMS?
- Clause 8 – Operation
- Clause 5 – Leadership
- Clause 6 – Planning
- Clause 4 – Context of the organization (Correct answer)
Correct answer: Clause 4 – Context of the organization
Clause 4.3 of ISO 27001 explicitly requires the organization to determine the boundaries and applicability of the ISMS to establish its scope.
Question 35: Which scenario demonstrates an inappropriate ISMS scope exclusion?
- Excluding a legacy system already decommissioned
- Excluding a cafeteria management system with no access to sensitive data
- Excluding a physical gym facility used only by staff
- Excluding an e-commerce platform that processes customer payment information (Correct answer)
Correct answer: Excluding an e-commerce platform that processes customer payment information
Excluding an e-commerce platform that processes payment data is inappropriate because it handles sensitive information that falls under the organization's security obligations.
Question 36: Which ISO standard provides specific guidance on information security governance at the enterprise level?
- ISO 27017
- ISO 27014 (Correct answer)
- ISO 27003
- ISO 27005
Correct answer: ISO 27014
ISO 27014 provides guidance on the governance of information security, addressing the roles of the governing body and executive management.
Question 37: What is the relationship between a 'threat' and a 'vulnerability' in ISO 27000 risk terminology?
- A vulnerability creates a threat automatically
- A threat exploits a vulnerability to cause harm to an asset (Correct answer)
- They are interchangeable terms for the same concept
- Threats apply only to physical assets; vulnerabilities apply to logical ones
Correct answer: A threat exploits a vulnerability to cause harm to an asset
A threat source exploits a vulnerability in a system or process to cause an adverse impact on information assets.
Question 38: How does the concept of 'interfaces and dependencies' affect ISMS scope decisions?
- It ensures that relationships with out-of-scope entities are considered so security gaps are not created at boundaries (Correct answer)
- It determines the number of ISO controls to implement
- It applies only to cloud service dependencies
- It mandates that all third parties be brought within the ISMS scope
Correct answer: It ensures that relationships with out-of-scope entities are considered so security gaps are not created at boundaries
Identifying interfaces and dependencies helps the organization understand how out-of-scope activities can create security risks at the boundaries of the ISMS.
Question 39: An attacker sends a deceptive email to trick an employee into revealing login credentials. Which threat category does this represent?
- Physical security breach
- Technical vulnerability exploitation
- Denial of service
- Social engineering (Correct answer)
Correct answer: Social engineering
Phishing and deceptive emails fall under social engineering, where attackers manipulate people rather than systems.
Question 40: What is the purpose of maintaining an 'asset inventory' during ISMS operation?
- To track employee performance related to asset usage
- To satisfy financial accounting requirements under GAAP
- To calculate the replacement cost of hardware for insurance purposes only
- To identify assets within scope so appropriate controls can be applied (Correct answer)
Correct answer: To identify assets within scope so appropriate controls can be applied
An asset inventory identifies what information assets exist within scope, enabling the organization to assign ownership and apply appropriate protections.
Question 41: A weakness in a system's security procedures, design, implementation, or internal controls that could be exploited by a threat source is known as a:
- Consequence
- Vulnerability (Correct answer)
- Risk
- Threat
Correct answer: Vulnerability
ISO/IEC 27000 defines a 'vulnerability' as a weakness of an asset or control that can be exploited by one or more threats. A threat is a potential cause of an incident, and a risk is the effect of uncertainty on objectives, often expressed as a combination of the consequences of an event and the associated likelihood of occurrence.
Question 42: Which activity DOES NOT fall under a certifying body's mandates and obligations?
- Internal and lead auditor training
- Advise how to fill the gaps found during a readiness assessment (Correct answer)
- Check and approve the scope of the ISMS
- Use external auditors to carry out formal assessment against ISO/IEC 27001
Correct answer: Advise how to fill the gaps found during a readiness assessment
A certifying body's role is to conduct independent audits and assess an organization's conformity to the standard, maintaining impartiality. Providing specific advice on how to fill gaps or implement controls would be considered consulting, which creates a conflict of interest for a certifying body. They identify nonconformities but do not prescribe solutions.
Question 43: An organization scores each risk by multiplying a likelihood score (1–5) by an impact score (1–5). This approach is an example of which assessment method?
- Fully quantitative assessment
- Delphi technique
- Purely qualitative assessment
- Semi-quantitative assessment (Correct answer)
Correct answer: Semi-quantitative assessment
Semi-quantitative assessment uses numerical scales (like 1–5) that are ordinal rather than true monetary values, combining elements of both qualitative and quantitative approaches.
Question 44: How often does ISO/IEC 27001 require organizations to perform information security risk assessments?
- Every five years as mandated by the standard
- At planned intervals and when significant changes occur (Correct answer)
- Only once during ISMS implementation
- Only after a security incident has been recorded
Correct answer: At planned intervals and when significant changes occur
ISO/IEC 27001 requires risk assessments at planned intervals and whenever significant changes arise that may affect information security.
Question 45: What must an organization determine when deciding what to monitor and measure in its ISMS?
- Which employees are responsible for each control
- What methods will be used and when results will be analyzed (Correct answer)
- The budget allocated to each information security control
- Which external auditors will review the measurements
Correct answer: What methods will be used and when results will be analyzed
ISO 27001 Clause 9.1 requires organizations to determine what to monitor and measure, the methods to use, and when results will be analyzed and evaluated.
Question 46: What is the main output of the risk treatment process within an operational ISMS?
- An updated organizational chart showing security roles
- A final list of all organizational assets
- A risk treatment plan and updated Statement of Applicability (Correct answer)
- A report submitted directly to regulators
Correct answer: A risk treatment plan and updated Statement of Applicability
Risk treatment produces a risk treatment plan detailing selected controls and updates the SoA to reflect implementation decisions.
Question 47: In ISO 27000, what is meant by 'residual risk'?
- Risk that remains after controls have been applied (Correct answer)
- Risk that is deemed acceptable by top management
- Risk that is transferred to a third party
- Risk identified during the initial assessment phase
Correct answer: Risk that remains after controls have been applied
Residual risk is the remaining level of risk after risk treatment controls have been implemented.
Question 48: An organization wants to outsource its data backup process. How should the ISMS address this?
- Remove the backup asset from the asset register
- Apply controls to externally provided processes and retain responsibility (Correct answer)
- Transfer all legal liability to the outsourcing vendor
- Exclude backups from the ISMS scope since they are outsourced
Correct answer: Apply controls to externally provided processes and retain responsibility
ISO 27001 requires that externally provided processes still be controlled and managed within the ISMS; responsibility cannot be fully delegated.
Question 49: What distinguishes a 'vulnerability' from a 'threat' in information security risk terminology?
- There is no distinction — the terms are interchangeable in ISO 27000
- A threat is a potential cause of harm; a vulnerability is a weakness that can be exploited by a threat (Correct answer)
- A vulnerability causes impact; a threat reduces likelihood
- A vulnerability is an external actor; a threat is an internal weakness
Correct answer: A threat is a potential cause of harm; a vulnerability is a weakness that can be exploited by a threat
ISO 27000 defines a threat as a potential cause of an unwanted incident, while a vulnerability is a weakness that may be exploited by one or more threats.
Question 50: In the context of an ISO 27001 ISMS, what is the primary responsibility of a 'Risk Owner'?
- To conduct the annual audit of the risk management process.
- To technically implement the security controls for all identified risks.
- To manage the day-to-day operation of the information assets associated with a risk.
- To approve the risk treatment plan and accept the residual risk for a specific risk. (Correct answer)
Correct answer: To approve the risk treatment plan and accept the residual risk for a specific risk.
The Risk Owner is the individual accountable for a specific risk. Their key responsibilities include approving the chosen risk treatment plan and formally accepting the level of risk that remains after controls are applied (residual risk). While they oversee the risk, they may not be the one technically implementing controls (IT Manager) or managing the asset day-to-day (Asset Owner).
Question 51: What is the primary role of a Computer Security Incident Response Team (CSIRT)?
- To audit compliance with ISO 27001 certification requirements
- To conduct regular penetration tests on organizational systems
- To develop and maintain the organization's information security policies
- To coordinate and manage the organization's response to information security incidents (Correct answer)
Correct answer: To coordinate and manage the organization's response to information security incidents
A CSIRT is specifically established to coordinate and execute responses to information security incidents, ensuring a structured and effective handling process.
Question 52: In ISO 27001, what is the relationship between ISMS scope and the Statement of Applicability (SoA)?
- The scope is derived from the SoA after risk assessment
- The SoA defines which assets are in scope
- The SoA lists which Annex A controls apply based on the defined scope (Correct answer)
- The SoA replaces the scope document entirely
Correct answer: The SoA lists which Annex A controls apply based on the defined scope
The Statement of Applicability documents which controls from ISO 27001 Annex A are applicable within the defined ISMS scope and justifies any exclusions.
Question 53: When an organization identifies a risk but determines that the cost of treatment exceeds the potential loss, it may decide to:
- Avoid the risk by eliminating the related activity
- Transfer the risk to a business partner
- Retain the risk and monitor it (Correct answer)
- Share the risk with a third-party insurer
Correct answer: Retain the risk and monitor it
Risk retention is appropriate when treatment costs exceed the potential impact, and the organization consciously accepts the risk.
Question 54: Which process ensures that the ISMS risk treatment remains effective as the organization's environment changes over time?
- Risk monitoring and review (Correct answer)
- Risk identification
- Risk communication
- Risk acceptance
Correct answer: Risk monitoring and review
Risk monitoring and review is an ongoing process that verifies whether risk treatment measures remain effective and whether new risks have emerged.
Question 55: During ISMS implementation, who holds ultimate accountability for accepting residual risk?
- The IT security analyst
- The external auditor
- The third-party consultant
- Top management or designated risk owners (Correct answer)
Correct answer: Top management or designated risk owners
Risk owners, approved by top management, are accountable for accepting residual risk after treatment options have been applied.
Question 56: Which standard in the ISO 27000 family provides the overview, fundamental principles, and vocabulary for an ISMS?
- ISO/IEC 27002
- ISO/IEC 27005
- ISO/IEC 27001
- ISO/IEC 27000 (Correct answer)
Correct answer: ISO/IEC 27000
ISO/IEC 27000 is the foundational standard in the series. It provides an overview of information security management systems and specifies the essential vocabulary (terms and definitions) used across the entire ISO 27000 family of standards.
Question 57: Which of the following controls is a primary example of a Technological Control as defined in the ISO 27001:2022 Annex A themes?
- Management of privileged access rights (Correct answer)
- Information security policy and procedures
- Information security awareness, education, and training
- Securing offices, rooms, and facilities
Correct answer: Management of privileged access rights
The management of privileged access rights is a Technological Control. This theme includes controls implemented through technology, such as access control systems, encryption, network security, and secure coding. The other options fall under People (training), Physical (securing offices), and Organizational (policies) controls respectively.
Question 58: Why is it important that the PDCA cycle in an ISMS is iterative rather than a one-time process?
- Because ISO 27001 requires certification to be renewed annually
- Because regulatory requirements never change
- Because the threat landscape, business context, and technology change continuously (Correct answer)
- Because PDCA is only applicable during the initial ISMS setup
Correct answer: Because the threat landscape, business context, and technology change continuously
Threats, vulnerabilities, and business requirements evolve constantly, making ongoing iteration of the PDCA cycle essential.
Question 59: What role does the Statement of Applicability (SoA) play in the PDCA cycle?
- It is produced in the Do phase to document implemented controls
- It is a Check phase report on control effectiveness
- It is an Act phase document for continual improvement plans
- It is a Plan phase output that links Annex A controls to the risk treatment decisions (Correct answer)
Correct answer: It is a Plan phase output that links Annex A controls to the risk treatment decisions
The SoA is created during the Plan phase to document which Annex A controls are applicable, included, or excluded and why.
Question 60: An organization reviews its ISMS scope annually and expands it to include a newly acquired subsidiary. What does this reflect?
- A violation of ISO 27001 scope stability requirements
- An unnecessary increase in certification costs
- A failure to define scope correctly at the outset
- Continual improvement and adaptation of the ISMS to changing organizational context (Correct answer)
Correct answer: Continual improvement and adaptation of the ISMS to changing organizational context
Updating the ISMS scope in response to organizational changes reflects the continual improvement principle central to ISO 27001.
Question 61: A financial services firm's ISMS scope statement reads: 'All systems supporting retail banking operations at the New York headquarters.' What type of boundary does this represent?
- Vendor and supply chain boundary
- Functional and physical boundary (Correct answer)
- Network topology boundary only
- Temporal and personnel boundary
Correct answer: Functional and physical boundary
The scope statement defines both a functional boundary (retail banking operations) and a physical boundary (New York headquarters).
ISO 27000 Foundation Certification Exam
The ISO 27000 Foundation Certification Exam exam validates essential knowledge and skills required for certification or licensure in this field.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds