Latest [May 12, 2026] APMG-International ISO-IEC-27001-Foundation Real Exam Dumps PDF [Q17-Q37]

Share

Latest [May 12, 2026] APMG-International ISO-IEC-27001-Foundation Real Exam Dumps PDF

ISO-IEC-27001-Foundation Practice Test Questions Updated 52 Questions

NEW QUESTION # 17
Identify the missing word in the following sentence.
The organization shall determine the [ ? ] of interested parties relevant to information security.

  • A. structure
  • B. requirements
  • C. number
  • D. influence

Answer: B

Explanation:
Clause 4.2 of ISO/IEC 27001:2022 states:
"The organization shall determine: a) interested parties that are relevant to the information security management system; b) the relevant requirements of these interested parties; c) which of these requirements will be addressed through the ISMS." This confirms that the missing word isrequirements. Neither number, structure, nor influence are specified in the standard.


NEW QUESTION # 18
Which International Standard can be used to implement an integrated management system with ISO/IEC
27001?

  • A. None of the above
  • B. ISO/IEC 27013
  • C. ISO 9001
  • D. ISO/IEC 27003

Answer: B

Explanation:
ISO/IEC 27013 provides specific guidance on theintegration of ISO/IEC 27001 (Information Security Management) and ISO/IEC 20000-1 (IT Service Management). It offers practical advice for organizations seeking a unified management system approach. While ISO/IEC 27003 (A) provides guidance on ISMS implementation, it does not address integration. ISO 9001 (C) is the Quality Management Standard and can be integrated, but the specific standard designed forintegrating 27001 with ITSMis ISO/IEC 27013.
Therefore, the correct answer isB: ISO/IEC 27013, as it is explicitly published for this purpose.


NEW QUESTION # 19
Identify the missing word in the following sentence.
According to ISO/IEC 27000, the definition of risk [?] is a "process to comprehend the nature of risk and to determine the level of risk."

  • A. Management
  • B. Analysis
  • C. Evaluation
  • D. Assessment

Answer: B

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27000 standards:
ISO/IEC 27000 defines:
* Risk analysis: "process to comprehend the nature of risk and to determine the level of risk" (Clause 3.58).
* Risk assessment: the overall process of risk identification, risk analysis, and risk evaluation.
* Risk evaluation: compares results of risk analysis against risk criteria to determine priority.
* Risk management: coordinated activities to direct and control an organization with regard to risk.
Therefore, the missing word in the given definition is"analysis".
This is important for ISMS implementation: organizations must understand the distinctions. Risk analysis is the core technical evaluation stage, while assessment is the broader process including evaluation, and management refers to the overall governance of risks.
Thus, the correct verified answer isB: Analysis.


NEW QUESTION # 20
Which statement describes the control for the Compliance with policies, rules and standards for information security within Annex A of ISO/IEC 27001?

  • A. Regular review of compliance
  • B. Maintain contact with legal authorities
  • C. Return assets to their legal owners
  • D. Regular review of contractual compliance

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.5.36 (Compliance with policies, rules and standards for information security) requires:
"Compliance with the organization's information security policies, rules and standards for information security should be regularly reviewed." This directly matches option A. Option B refers to contractual compliance, which is part of supplier management controls (Annex A.5.19). Option C relates to Annex A.5.7 (Contact with authorities). Option D refers to asset return controls (Annex A.5.9).
Thus, the correct answer isA.


NEW QUESTION # 21
Which item is required to be included in an information security policy?

  • A. A Statement of Applicability which defines the necessary controls to be implemented
  • B. A framework enabling concerns with the information security policy to be addressed
  • C. A commitment to satisfy applicable requirements related to information security
  • D. A plan for the continual improvement of the information security management system

Answer: C

Explanation:
Clause 5.2 (Information security policy) requires that the policy:
* "includes information security objectives (or provides a framework for setting them)"
* "includes a commitment to satisfy applicable requirements related to information security"
* "includes a commitment to continual improvement of the ISMS."
Among the listed options, the exact mandatory requirement is"a commitment to satisfy applicable requirements related to information security". Option B partially reflects Clause 5.2 (commitment to continual improvement), but the wording given in the standard prioritizes the satisfaction of applicable requirements (e.g., legal, regulatory, contractual). Option C is not a policy requirement. Option D (Statement of Applicability) is a separate mandatory document (Clause 6.1.3) and not part of the policy itself.
Thus, the correct answer isA.


NEW QUESTION # 22
Which item is required to be considered when defining the scope and boundaries of the information security management system?

  • A. The level of quality to which the ISMS must adhere
  • B. The dependencies between activities performed by the organization
  • C. The lessons learned from the information security experiences of other organizations
  • D. The regular activities necessary to maintain and improve the ISMS

Answer: B

Explanation:
Clause 4.3 (Determining the scope of the ISMS) requires consideration of:
"the external and internal issues referred to in 4.1; the requirements referred to in 4.2; and interfaces and dependencies between activities performed by the organization, and those that are performed by other organizations." This confirms that dependencies between activities are a required factor when defining scope. Options B (quality levels), C (lessons learned), and D (regular activities for improvement) are not scope requirements, though they may be relevant in planning or improvement processes.
Thus, the verified answer is A: Dependencies between activities performed by the organization.


NEW QUESTION # 23
Which item is required to be defined when planning the organization's risk assessment process?

  • A. There are NO specific information requirements
  • B. How the effectiveness of the method will be measured
  • C. The parts of the ISMS scope which are excluded from the risk assessment
  • D. The criteria for acceptable levels of risk

Answer: D

Explanation:
Clause 6.1.2 (Information security risk assessment) requires organizations to "define and apply an information security risk assessment process that... establishes and maintains information security risk criteria, including criteria for accepting risk." This means that acceptable levels of risk (risk acceptance criteria) must be explicitly defined. These criteria ensure consistent decision-making when evaluating whether identified risks need further treatment or can be tolerated.
Option A is incorrect because exclusions relate to the ISMS scope (Clause 4.3), not risk assessment planning.
Option B is not a requirement; effectiveness of risk assessment methods is not required to be measured, though methods must be applied consistently. Option D is false-the standard clearly specifies required elements for risk assessment.
Thus, the correct answer isC: The criteria for acceptable levels of risk.


NEW QUESTION # 24
Which of the following is required to be considered when selecting appropriate information security risk treatment options?

  • A. Only risk controls in Annex A of ISO/IEC 27001
  • B. Only risk controls in ISO/IEC 27002
  • C. Criteria for performing risk assessments
  • D. Criteria for accepting identified risks

Answer: D

Explanation:
Clause 6.1.3 (c) requires organizations to:
"compare the controls determined in 6.1.3 b) with those in Annex A and verify that no necessary control has been omitted; and prepare a Statement of Applicability." It also requires organizations to select risk treatment options considering "the organization's risk acceptance criteria." This shows thatrisk acceptance criteriaare a fundamental factor when selecting risk treatment options.
Options C and D are incorrect because Annex A and ISO/IEC 27002 are reference sets, not the sole sources of controls - organizations can design their own. Criteria for performing risk assessments (B) are part of 6.1.2 (risk assessment process), not risk treatment.
Thus, the correct requirement isA: Criteria for accepting identified risks.


NEW QUESTION # 25
Which statement about the conduct of audits is true?

  • A. During Stage 1 of a certification audit, evidence is collected by observing activities
  • B. The certificate issued after a successful re-certification audit in typical schemes lasts for one year
  • C. One of the focus areas for a surveillance audit is the output from internal audits and management reviews
  • D. Third party audits are conducted by a customer of the organization

Answer: C

Explanation:
Clause 9.2 (Internal Audit) and Clause 9.3 (Management Review) highlight that audit outputs and management reviews are key inputs for evaluating ISMS performance. Surveillance audits, conducted by Certification Bodies, check ongoing compliance and effectiveness. ISO certification schemes (per ISO/IEC
17021) require surveillance audits to verify whether corrective actions and continuous improvements are being made. A critical focus area is theresults of internal audits and management reviews, ensuring that the organization maintains its ISMS between certification cycles.
Option A is incorrect - third-party audits are performed by independent Certification Bodies, not customers.
Option B is incorrect - certificates are typically valid forthree yearswith annual surveillance. Option D is incorrect - Stage 1 is primarily adocumentation and readiness review, not evidence observation.
Therefore, the verified correct answer isC.


NEW QUESTION # 26
Which of the following statements about the differences between an internal audit and a certification audit is true?
An internal audit is conducted at planned intervals and a certification audit is conducted annually An internal audit is known as a 1st party audit and a certification audit is known as a 3rd party audit

  • A. Only 2 is true
  • B. Both 1 and 2 are true
  • C. Neither 1 or 2 is true
  • D. Only 1 is true

Answer: A

Explanation:
ISO/IEC 27001 Clause 9.2 requires internal audits to be conducted at planned intervals, but it does not specify an annual frequency. Certification audits, under ISO/IEC 17021 rules, typically occur on a 3-year cycle with annual surveillance, not strictly "annually." This makes statement 1 inaccurate.
Audit types are defined in ISO/IEC 19011:
First-party audits: conducted internally by or on behalf of the organization (internal audits).
Third-party audits: conducted by independent external certification bodies.
Thus, statement 2 is correct. Therefore, the accurate choice is B: Only 2 is true.


NEW QUESTION # 27
Identify the missing word(s) in the following sentence.
"Information security, cybersecurity and privacy protection - [ ? ]" is the title of ISO/IEC 27005.

  • A. Information security controls
  • B. Information security management systems - Requirements
  • C. Guidelines for information security management systems auditing
  • D. Guidance on managing information security risks

Answer: D

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27005 standards:
ISO/IEC 27005:2022 is titled:
"Information security, cybersecurity and privacy protection - Guidance on managing information security risks." This standard provides structured methodologies for identifying, analyzing, evaluating, and treating risks, in alignment with ISO/IEC 27001's risk management requirements (Clause 6.1.2 and 6.1.3). It supports organizations in implementing the risk management process that underpins an ISMS. Options A and B are titles of other ISO standards (ISO/IEC 27007 for auditing, ISO/IEC 27001 for requirements). Option D refers to ISO/IEC 27002 (controls).
Thus, the correct answer isC: Guidance on managing information security risks.


NEW QUESTION # 28
What is a requirement for a corrective action made in response to a nonconformity?

  • A. They are proportionate to the likelihood of the nonconformity recurring
  • B. They do NOT change the organization's information security policies
  • C. They are appropriate to the effects of the nonconformity
  • D. They always eliminate the cause of the nonconformity

Answer: C

Explanation:
Clause 10.1 (Nonconformity and corrective action) specifies:
"The organization shall react to the nonconformity and, as applicable: take action to control and correct it; deal with the consequences; evaluate the need for action to eliminate the cause(s)...
Corrective actions shall be appropriate to the effects of the nonconformities encountered." This confirms optionB. Option A is inaccurate-ISO requires actions appropriate toeffects, not probability alone. Option C is false-policies may need updating to correct nonconformities. Option D is incorrect, as not every cause can always be eliminated; residual issues may exist.
Thus, the verified requirement isB.


NEW QUESTION # 29
Which attribute is NOT a required focus of continual ISMS improvement?

  • A. Adequacy
  • B. Suitability
  • C. Effectiveness
  • D. Importance

Answer: D

Explanation:
Clause 10.2 (Continual Improvement) specifies that the organization must"continually improve the suitability, adequacy and effectiveness of the information security management system." This makes it clear that three attributes are explicitly required to be addressed:
* Suitability: ensuring the ISMS continues to meet organizational needs in changing contexts.
* Adequacy: ensuring the ISMS covers the necessary scope and provides sufficient control coverage.
* Effectiveness: ensuring the ISMS achieves intended outcomes in protecting information security.
The word"importance"is not part of the continual improvement requirement. Importance is implicit in prioritization of risks and actions, but it is not a required continual improvement attribute in ISO/IEC 27001.
Therefore, optionD: Importanceis the correct choice as it is not specified.
This distinction reinforces that continual improvement is not about subjective importance, but about systematic enhancement of the ISMS'ssuitability, adequacy, and effectiveness.


NEW QUESTION # 30
Which activity is a required element of information security risk identification?

  • A. Determine the risk owners
  • B. Consider the likelihood of the occurrence
  • C. Determine the level of risk
  • D. Prioritize the risk for treatment

Answer: A

Explanation:
Clause 6.1.2 defines the mandatory elements of risk assessment. Under risk identification, the standard requires: "identifies the information security risks:1) apply the information security risk assessment process to identify risks...; and2) identify the risk owners." By contrast, considering likelihood and determining levels of risk (options B and D) are part ofrisk analysis(6.1.2 d) "assess the realistic likelihood...";
"determine the levels of risk"), and prioritization for treatment (option C) is part ofrisk evaluation(6.1.2 e)
"prioritize the analysed risks for risk treatment"). Therefore, the specific activity that belongs torisk identificationis toidentify the risk owners. This sequencing is prescribed to ensure each risk has a designated owner responsible for decisions on treatment and acceptance downstream.


NEW QUESTION # 31
Which of the following statements about the relationship between ISO/IEC 27001 and ISO/IEC 27002 is true?
* ISO/IEC 27002 provides implementation advice on the controls selected during the ISO/IEC 27001 information security risk management process
* ISO/IEC 27002 provides a process for information security risk management which implements the requirements of ISO/IEC 27001

  • A. Only 2 is true
  • B. Only 1 is true
  • C. Both 1 and 2 are true
  • D. Neither 1 or 2 is true

Answer: B

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27001 & 27002:2022 standards:
ISO/IEC 27001 Annex A lists reference controls. ISO/IEC 27002 providesdetailed guidance on the implementation of those controls, including purpose, guidance, and examples. Clause 6.1.3 of ISO/IEC
27001 makes the link explicit: controls from Annex A are referenced, but ISO/IEC 27002 explains how to implement them.
However, ISO/IEC 27002 doesnotprovide a process for risk management-that is covered by ISO/IEC
27005. Risk management requirements are in ISO/IEC 27001 (Clauses 6.1.2 and 6.1.3).
Therefore, statement 1 is true, but statement 2 is false. Correct answer:A.


NEW QUESTION # 32
Which statement describes the Classification of information control in Annex A of ISO/IEC 27001?

  • A. Ensures that information is classified based on confidentiality, integrity and availability
  • B. Ensures that all information assets are labelled with their classification
  • C. Ensures that security perimeters are used to protect assets
  • D. Ensures the rules to control physical and logical access apply to assets

Answer: A

Explanation:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A.5.12 (Classification of information) states:
"Information should be classified according to the information security needs of the organization based on confidentiality, integrity and availability." This aligns directly with option B. Option A (labelling) is a separate control (Annex A.5.13). Option C (security perimeters) is under physical controls (Annex A.7.1). Option D (access control rules) relates to Annex A.5.15 and A.8.2.
Thus, the verified correct statement for the Classification of information control isB.


NEW QUESTION # 33
Who is required to ensure that staff are supported so that they can contribute to the information security management system?

  • A. Auditors who audit each area of operation
  • B. ISO/IEC 27001 practitioners within the organization
  • C. Management responsible for each area of operation
  • D. Top management of the organization

Answer: D

Explanation:
Clause 5.1 (Leadership and Commitment) requires that:
"Top management shall demonstrate leadership and commitment with respect to the information security management system by... ensuring that the resources needed for the ISMS are available... and supporting persons to contribute to the effectiveness of the ISMS." This makes it explicit thattop managementhas the responsibility to ensure personnel are supported so they can contribute to the ISMS. Option B (line management) may provide local support, but ultimate accountability rests with top management. Auditors (C) only evaluate compliance, not provide support.
Practitioners (D) help implement, but they don't bear formal responsibility under the standard.
Thus, the verified answer isA: Top management of the organization.


NEW QUESTION # 34
Which information is required to be included in the Statement of Applicability?

  • A. The justification for including each information security control
  • B. The risk assessment approach of the organization
  • C. The criteria against which risk will be evaluated
  • D. The scope and boundaries of the ISMS

Answer: A

Explanation:
Clause 6.1.3 (d) requires that the organization"produce a Statement of Applicability that contains the necessary controls (see Annex A), and justification for inclusions, whether they are implemented or not, and the justification for exclusions." This is the defining requirement of the SoA: it documents which Annex A controls are relevant, which are implemented, and the justification for inclusion/exclusion. While the ISMS scope (A) is documented in Clause 4.3, and risk evaluation criteria (C) are defined in Clause 6.1.2, these do not belong in the SoA. The SoA does not describe the full risk assessment approach (B); that is part of the risk assessment methodology.
Therefore, the mandatory requirement for the SoA isjustification for including (or excluding) each information security control.


NEW QUESTION # 35
Which statement describes a requirement for information security objectives?

  • A. They shall all be measurable
  • B. They shall be consistent with the information security policy
  • C. They shall be contractually transferred to third parties
  • D. They shall be reviewed at least annually

Answer: B

Explanation:
Clause 6.2 (Information security objectives) requires that objectives:
* "be consistent with the information security policy"
* "be measurable (if practicable)"
* "take into account applicable information security requirements"
* "be monitored, communicated, and updated as appropriate."
From this, option A is correct since consistency with policy is an explicit requirement. Option B is incorrect because the standard allows objectives to be measurable "if practicable" (not mandatory for all). Option C is incorrect-objectives are not transferred contractually to third parties, though third-party agreements may include security requirements. Option D is incorrect because the standard requires regular review "as appropriate," not a fixed annual cycle.
Thus, the verified requirement isA: They shall be consistent with the information security policy.


NEW QUESTION # 36
Which statement describes a requirement of an internal audit programme?

  • A. Previous audit results are disregarded to ensure objectivity
  • B. All processes must be audited within a 3-year cycle
  • C. The programme must use third party auditors to ensure impartiality
  • D. The programme must consider the importance of the target processes

Answer: D

Explanation:
Clause 9.2.2 of ISO/IEC 27001:2022 specifies requirements for the internal audit programme. It requires organizations to:
"Plan, establish, implement and maintain an audit programme(s) including the frequency, methods, responsibilities, planning requirements and reporting, which shall take into consideration the importance of the processes concerned, changes affecting the organization, and the results of previous audits." This makes optionCcorrect, since importance of the processes is a required factor. Option A is incorrect because audits do not need third-party auditors; objectivity can be maintained internally if independence is respected. Option B is wrong because previous audit results must be considered, not disregarded. Option D is also incorrect - the standard does not specify a 3-year cycle; frequency depends on risks and needs.
Thus, the correct verified answer isC.


NEW QUESTION # 37
......

APMG-International ISO-IEC-27001-Foundation Dumps - Secret To Pass in First Attempt: https://www.pass4suresvce.com/ISO-IEC-27001-Foundation-pass4sure-vce-dumps.html

ISO-IEC-27001-Foundation Dumps - Grab Out For [NEW-2026] APMG-International Exam: https://drive.google.com/open?id=1Vyqixjy4RgBMc8E7RDa95q5dgJweN40T