
Pass Your APMG-International ISO-IEC-27001-Foundation Exam with Correct 72 Questions and Answers
Latest [Aug 02, 2026] 2026 Realistic Verified ISO-IEC-27001-Foundation Dumps
APMG-International ISO-IEC-27001-Foundation Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
NEW QUESTION # 23
What is the primary purpose of an Information Security Management System (ISMS)?
- A. To prevent cyberattacks completely
- B. To protect information through a systematic risk management process
- C. To comply only with legal requirements
- D. To eliminate all information security risks
Answer: B
Explanation:
An ISMS provides a structured framework for managing information security risks. ISO/IEC 27001 focuses on protecting confidentiality, integrity, and availability through continual improvement and risk-based decision-making, rather than eliminating all risks or guaranteeing complete protection.
NEW QUESTION # 24
What activity is done first when preparing for an initial certification audit?
- A. Provide documents to the Certification Body auditor for the Stage 1 audit
- B. Agree the scope of the ISMS with the Certification Body auditor
- C. Provide records to the Certification Body auditor for the Stage 2 audit
- D. Provide evidence that nonconformities from an internal audit have been actioned
Answer: B
Explanation:
Before a certification audit can begin, the scope of the ISMS must be clearly defined and agreed with the Certification Body. ISO/IEC 27001 Clause 4.3 requires: "The scope shall be available as documented information."
NEW QUESTION # 25
Which of the following is required to be considered when selecting appropriate information security risk treatment options?
- A. Criteria for accepting identified risks
- B. Criteria for performing risk assessments
- C. Only risk controls in ISO/IEC 27002
- D. Only risk controls in Annex A of ISO/IEC 27001
Answer: A
Explanation:
Clause 6.1.3 (c) requires organizations to:
"compare the controls determined in 6.1.3 b) with those in Annex A and verify that no necessary control has been omitted; and prepare a Statement of Applicability." It also requires organizations to select risk treatment options considering "the organization's risk acceptance criteria."
NEW QUESTION # 26
Which statement describes a requirement for information security objectives?
- A. They shall be contractually transferred to third parties
- B. They shall be reviewed at least annually
- C. They shall be consistent with the information security policy
- D. They shall all be measurable
Answer: C
Explanation:
Clause 6.2 (Information security objectives) requires that objectives:
* "be consistent with the information security policy"
* "be measurable (if practicable)"
* "take into account applicable information security requirements"
* "be monitored, communicated, and updated as appropriate."
From this, option A is correct since consistency with policy is an explicit requirement. Option B is incorrect because the standard allows objectives to be measurable "if practicable" (not mandatory for all). Option C is incorrect-objectives are not transferred contractually to third parties, though third-party agreements may include security requirements. Option D is incorrect because the standard requires regular review "as appropriate," not a fixed annual cycle.
Thus, the verified requirement isA: They shall be consistent with the information security policy.
NEW QUESTION # 27
What is the definition of a threat according to ISO/IEC 27000?
- A. A weakness of an asset or a control that can be exploited
- B. A single or a series of unwanted or unexpected information security events
- C. The risk remaining after risk treatment
- D. A potential cause of an unwanted incident which can result in harm to a system or organization
Answer: D
Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27000 standards:
According to ISO/IEC 27000:2018, Clause 3.74, athreatis defined as:
"Potential cause of an unwanted incident, which can result in harm to a system or organization." This definition directly matches option A.
* Option B refers to an "information security incident" (ISO/IEC 27000:2018, Clause 3.32).
* Option C describes a "vulnerability" (ISO/IEC 27000:2018, Clause 3.67).
* Option D refers to "residual risk" (ISO/IEC 27000:2018, Clause 3.61).
The standard emphasizes that threats exploit vulnerabilities, causing incidents that can harm information confidentiality, integrity, and availability. Correctly identifying threats is critical for risk assessment (Clause
6.1.2). Thus, the correct definition per ISO/IEC 27000 isA.
NEW QUESTION # 28
Which attribute is NOT a required focus of continual ISMS improvement?
- A. Importance
- B. Effectiveness
- C. Adequacy
- D. Suitability
Answer: A
Explanation:
Clause 10.2 (Continual Improvement) specifies that the organization must"continually improve the suitability, adequacy and effectiveness of the information security management system." This makes it clear that three attributes are explicitly required to be addressed:
* Suitability: ensuring the ISMS continues to meet organizational needs in changing contexts.
* Adequacy: ensuring the ISMS covers the necessary scope and provides sufficient control coverage.
* Effectiveness: ensuring the ISMS achieves intended outcomes in protecting information security.
The word"importance"is not part of the continual improvement requirement. Importance is implicit in prioritization of risks and actions, but it is not a required continual improvement attribute in ISO/IEC 27001.
Therefore, optionD: Importanceis the correct choice as it is not specified.
This distinction reinforces that continual improvement is not about subjective importance, but about systematic enhancement of the ISMS'ssuitability, adequacy, and effectiveness.
NEW QUESTION # 29
What is the definition of a threat according to ISO/IEC 27000?
- A. A weakness of an asset or a control that can be exploited
- B. A single or a series of unwanted or unexpected information security events
- C. The risk remaining after risk treatment
- D. A potential cause of an unwanted incident which can result in harm to a system or organization
Answer: D
Explanation:
According to ISO/IEC 27000:2018, Clause 3.74, a threat is defined as:
"Potential cause of an unwanted incident, which can result in harm to a system or organization."
NEW QUESTION # 30
Which statement describes Annex A of ISO/IEC 27001?
- A. Defines a mandatory list of controls that shall be implemented
- B. Defines the criteria for accepting risks
- C. Provides measures to determine risk treatment effectiveness
- D. Provides a reference list of information security controls and their requirements
Answer: D
Explanation:
Annex A of ISO/IEC 27001:2022 is titled:
"Reference control objectives and controls." It provides areference list of information security controls, structured into 4 themes: organizational, people, physical, and technological.
The standard explicitly states in Clause 6.1.3: "Organizations can design controls as required or identify them from any source. Annex A contains a list of possible information security controls." This means controls in Annex A are not mandatory (eliminating option C). Risk acceptance criteria (A) are defined in Clause 6.1.2, not Annex A. Annex A also does not provide measures for treatment effectiveness (D).
Thus, Annex A is best described as areference list of information security controls. Correct answer:B.
NEW QUESTION # 31
What international standard provides guidance on the integration of ISO/IEC 27001 and the IT Service Management standard?
- A. ISO/IEC 27013
- B. None of the above
- C. ISO/IEC 27002
- D. ISO/IEC 20000-1
Answer: A
Explanation:
ISO/IEC 27013 is titled:
"Information technology -- Security techniques -- Guidance on the integrated implementation of ISO/IEC 27001 and ISO/IEC 20000-1." This standard provides organizations with specific advice on how to integrate an Information Security Management System (ISMS) with an IT Service Management System (ITSMS). ISO/IEC
20000-1 is the IT Service Management requirements standard, but integration guidance is provided in 27013.
NEW QUESTION # 32
Identify the missing word(s) in the following sentence.
"Information security, cybersecurity and privacy protection ?[ ? ]" is the title of ISO/IEC 27005.
- A. Guidance on managing information security risks
- B. Guidelines for information security management systems auditing
- C. Information security controls
- D. Information security management systems ?Requirements
Answer: A
Explanation:
ISO/IEC 27005:2022 is titled:
"Information security, cybersecurity and privacy protection -- Guidance on managing information security risks." This standard provides structured methodologies for identifying, analyzing, evaluating, and treating risks, in alignment with ISO/IEC 27001's risk management requirements (Clause 6.1.2 and 6.1.3). It supports organizations in implementing the risk management process that underpins an ISMS.
NEW QUESTION # 33
What is the definition of the term 'integrity' according to ISO/IEC 27000?
- A. The property of accuracy and completeness
- B. The property of availability and confidentiality
- C. The property of being accessible and usable
- D. The property that information is NOT made available inappropriately
Answer: A
Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27000 standards:
According to ISO/IEC 27000:2018, Clause 3.35:
"Integrity is the property of accuracy and completeness."
This is one of the three core principles of information security (CIA triad):
* Confidentiality: ensuring information is not made available to unauthorized persons (related to option B).
* Integrity: ensuring data is accurate, complete, and unaltered except by authorized means.
* Availability: ensuring information is accessible and usable when required (related to option A).
Option D incorrectly mixes availability and confidentiality. The precise ISO definition isaccuracy and completeness, which matches option C.
Thus, the correct verified answer isC.
NEW QUESTION # 34
What is the name of the control clause used to control information security breaches within Annex A of ISO
/IEC 27001?
- A. Information security event management
- B. Reporting information security incidents
- C. Information security event reporting
- D. Response to information security events
Answer: C
Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A in ISO/IEC 27001 refers directly to ISO/IEC 27002 for control guidance. In ISO/IEC 27002:2022, Clause 6.8 is titled:
"Information security event reporting - Information security events should be reported through appropriate management channels as quickly as possible." This control ensures breaches, incidents, or suspected issues are reported for action. The other options (B, C, D) are not the exact titles in Annex A. The official title isInformation security event reporting, confirming
NEW QUESTION # 35
When are the information security policies required to be reviewed, according to the Policies for information security control?
- A. According to a schedule defined by the Certification Body
- B. At planned intervals and if significant changes occur
- C. Annually
- D. Every six months
Answer: B
Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.5.1 (Policies for information security) specifies:
"Information security policy and topic-specific policies should be defined, approved by management, published, communicated to and acknowledged by relevant personnel and relevant interested parties, and reviewed at planned intervals and if significant changes occur." This clearly identifies the review frequency requirement: planned intervalsandwhenever there are significant changes. Options A and B (six-monthly or annually) are not prescribed by ISO - timing is left to the organization. Option C is also wrong, since Certification Bodies do not dictate policy review schedules.
Therefore, the verified correct answer isD.
NEW QUESTION # 36
Which statement describes a purpose of monitoring, measurement, analysis and evaluation according to ISO/IEC 27001?
- A. To monitor the use of information assets
- B. To track the use of outsourced processes
- C. To evaluate information security performance
- D. To ensure that employees and contractors are competent
Answer: C
Explanation:
Clause 9.1 requires:
"The organization shall evaluate the information security performance and the effectiveness of the information security management system."
NEW QUESTION # 37
Which item is required to be considered when defining the scope and boundaries of the information security management system?
- A. The regular activities necessary to maintain and improve the ISMS
- B. The lessons learned from the information security experiences of other organizations
- C. The level of quality to which the ISMS must adhere
- D. The dependencies between activities performed by the organization
Answer: D
Explanation:
Clause 4.3 (Determining the scope of the ISMS) requires consideration of:
"the external and internal issues referred to in 4.1; the requirements referred to in 4.2; and interfaces and dependencies between activities performed by the organization, and those that are performed by other organizations."
NEW QUESTION # 38
To whom does the scope of the Terms and conditions of employment control apply?
- A. Employees only
- B. Personnel and the organization
- C. Contractors only
- D. All employees, contractors and third-party users
Answer: D
Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.6.1 (Terms and conditions of employment) states:
"The contractual agreements with employees and contractors shall state their and the organization's responsibilities for information security." This means the control applies not just to employees, but also contractors and, where relevant, third-party users who are subject to contractual obligations with the organization. The goal is to ensure thatall parties engaged in work under the organization's control understand their security responsibilities before, during, and after employment or contract engagement.
Options A and B are too narrow, excluding key groups. Option C misrepresents the scope by implying a mutual responsibility but not identifying the individuals covered. The explicit scope includesemployees, contractors, and third-party users.
Therefore, the correct answer isD.
NEW QUESTION # 39
Which information is required to be included in the Statement of Applicability?
- A. The scope and boundaries of the ISMS
- B. The risk assessment approach of the organization
- C. The criteria against which risk will be evaluated
- D. The justification for including each information security control
Answer: D
Explanation:
Clause 6.1.3 (d) requires that the organization"produce a Statement of Applicability that contains the necessary controls (see Annex A), and justification for inclusions, whether they are implemented or not, and the justification for exclusions." This is the defining requirement of the SoA: it documents which Annex A controls are relevant, which are implemented, and the justification for inclusion/exclusion. While the ISMS scope (A) is documented in Clause 4.3, and risk evaluation criteria (C) are defined in Clause 6.1.2, these do not belong in the SoA. The SoA does not describe the full risk assessment approach (B); that is part of the risk assessment methodology.
Therefore, the mandatory requirement for the SoA isjustification for including (or excluding) each information security control.
NEW QUESTION # 40
Which trend in information security performance is required to be considered during a management review of the ISMS?
- A. Validity of information continuity controls
- B. Relevant external and internal requirements changes
- C. Achievement of information security objectives
- D. Decisions related to continual improvement opportunities
Answer: C
Explanation:
Clause 9.3.2 (Management Review Inputs) states that management reviews shall include:
"c) information on the information security performance, including trends in: (1) nonconformities and corrective actions; (2) monitoring and measurement results; (3) audit results; and (4) fulfilment of information security objectives." This makesachievement of information security objectives(option A) a required trend to be considered.
While external/internal requirements (C) and continual improvement opportunities (D) are also part of management review inputs, they are not specifically listed under "trends in performance." Option B is outside the direct requirement.
Thus, the verified answer isA.
NEW QUESTION # 41
Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?
- A. Nonconformity and corrective action
- B. Awareness
- C. Communication
- D. Competence
Answer: B
Explanation:
Clause 7.3 (Awareness) requires:
"Persons doing work under the organization's control shall be aware of: (a) the information security policy; (b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; (c) the implications of not conforming with the ISMS requirements."
NEW QUESTION # 42
Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC
27002 is true?
(1) ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC
27001 information security risk management process
(2) ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001
- A. Only 1 is true
- B. Both 1 and 2 are true
- C. Neither 1 or 2 is true
- D. Only 2 is true
Answer: A
Explanation:
ISO/IEC 27001 Annex A lists reference controls. ISO/IEC 27002 provides detailed guidance on the implementation of those controls, including purpose, guidance, and examples. Clause 6.1.3 of ISO/IEC 27001 makes the link explicit: controls from Annex A are referenced, but ISO/IEC 27002 explains how to implement them.
However, ISO/IEC 27002 does not provide a process for risk management--that is covered by ISO/IEC 27005. Risk management requirements are in ISO/IEC 27001 (Clauses 6.1.2 and 6.1.3).
NEW QUESTION # 43
Which clause of ISO/IEC 27001:2022 requires the organization to determine the scope of its ISMS?
- A. Clause 5.1
- B. Clause 6.1
- C. Clause 4.3
- D. Clause 9.2
Answer: C
NEW QUESTION # 44
What is the purpose of an internal audit?
- A. To certify the ISMS
- B. To verify that the ISMS conforms to ISO/IEC 27001 and is effectively implemented
- C. To perform vulnerability scanning
- D. To conduct employee training
Answer: B
Explanation:
An internal audit evaluates whether the ISMS conforms to organizational requirements and ISO/IEC 27001. It also verifies that processes are effectively implemented, maintained, and continually improved before external certification or surveillance audits.
NEW QUESTION # 45
Which document lists the security controls that are applicable to the organization?
- A. Risk Register
- B. Business Continuity Plan
- C. Information Security Policy
- D. Statement of Applicability (SoA)
Answer: D
Explanation:
The Statement of Applicability (SoA) identifies which Annex A controls are selected, why they are included or excluded, and their implementation status. It demonstrates how security controls support the organization's risk treatment process.
NEW QUESTION # 46
......
Get 2026 Updated Free APMG-International ISO-IEC-27001-Foundation Exam Questions and Answer: https://braindumps2go.dumpstorrent.com/ISO-IEC-27001-Foundation-exam-prep.html