ISO 27000 Foundation Certification Exam — Questions and Answers
Question 1: What is the relationship between a 'threat' and a 'vulnerability' in ISO 27000 risk terminology?
- Threats apply only to physical assets; vulnerabilities apply to logical ones
- They are interchangeable terms for the same concept
- A vulnerability creates a threat automatically
- A threat exploits a vulnerability to cause harm to an asset (Correct answer)
Correct answer: A threat exploits a vulnerability to cause harm to an asset
A threat source exploits a vulnerability in a system or process to cause an adverse impact on information assets.
Question 2: A financial institution is conducting a security review. They are evaluating the effectiveness of their employee security awareness training, background verification screening for new hires, and the formal disciplinary process for security violations. Which Annex A control theme are they focusing on?
- Physical Controls
- Organizational Controls
- People Controls (Correct answer)
- Technological Controls
Correct answer: People Controls
The controls being evaluated—security awareness training, screening, and disciplinary processes—are all centered on managing security risks related to human factors. The People Controls theme specifically covers the entire employee lifecycle to mitigate risks arising from human error, negligence, or malicious intent.
Question 3: When defining the ISMS scope, an organization decides to exclude the finance department to reduce the initial implementation complexity. Which of the following is the MOST significant risk of this decision?
- Unmanaged security risks in the finance department could impact the information assets of in-scope departments. (Correct answer)
- The certification body will refuse to conduct the audit.
- The finance department will not be able to use the company's IT systems.
- The company will not be able to claim ISO 27001 certification.
Correct answer: Unmanaged security risks in the finance department could impact the information assets of in-scope departments.
While an organization can define its scope, it must consider the interfaces and dependencies between in-scope and out-of-scope areas. If the finance department has dependencies or interfaces with in-scope departments (e.g., sharing data, systems, or network infrastructure), excluding it without proper controls at the boundaries creates a significant vulnerability. An auditor would scrutinize this exclusion to ensure it doesn't compromise the security of the in-scope environment.
Question 4: What is the PRIMARY input to the risk treatment process in an ISMS?
- The results of the risk assessment (Correct answer)
- Previous audit findings only
- Employee satisfaction surveys
- The organization's annual budget
Correct answer: The results of the risk assessment
The risk assessment output, including prioritized risks and their levels, is the primary input used to determine appropriate treatment options.
Question 5: According to ISO/IEC 27001, who has the ultimate responsibility for deciding how to treat identified information security risks?
- The IT security team
- The external auditor
- Risk owners (Correct answer)
- The certification body
Correct answer: Risk owners
Risk owners are accountable for approving risk treatment plans and accepting residual risks within their area of responsibility.
Question 6: According to the vocabulary defined in the ISO 27000 family, which statement BEST describes the relationship between a threat, a vulnerability, and an asset?
- An asset is a weakness that can be exploited by a threat.
- A threat exploits an asset to cause harm to a vulnerability.
- A threat is a potential cause of an incident that may harm an asset by exploiting a vulnerability. (Correct answer)
- A vulnerability is a potential cause of an incident that may result in harm to an asset.
Correct answer: A threat is a potential cause of an incident that may harm an asset by exploiting a vulnerability.
The standard risk model is that a threat (a potential cause of an incident) can exploit a vulnerability (a weakness) to cause harm to an asset (something of value). For a risk to exist, all three elements are typically present. Option B correctly places these three components in their logical relationship.
Question 7: Which concept describes the degree to which an asset is exposed based on the likelihood of a threat exploiting a vulnerability?
- Exposure
- Impact
- Risk (Correct answer)
- Control gap
Correct answer: Risk
Risk in ISO 27000 combines the likelihood of a threat exploiting a vulnerability with the potential impact on the organization.
Question 8: According to ISO 27001, which of the following is the primary purpose of monitoring, measurement, analysis, and evaluation of the ISMS?
- To evaluate information security performance and the effectiveness of the ISMS. (Correct answer)
- To select and procure new security hardware and software based on performance data.
- To generate detailed reports exclusively for the annual external certification audit.
- To identify and discipline employees who do not comply with security policies.
Correct answer: To evaluate information security performance and the effectiveness of the ISMS.
ISO 27001 Clause 9.1 requires the organization to evaluate the information security performance and the effectiveness of the Information Security Management System (ISMS). This process provides the data needed for management reviews and continual improvement, ensuring the ISMS is achieving its intended outcomes.
Question 9: A company stops offering an online service because the associated data-breach risk is too high. Which risk treatment option has been applied?
- Risk avoidance (Correct answer)
- Risk retention
- Risk sharing
- Risk modification
Correct answer: Risk avoidance
Risk avoidance involves deciding not to start or continue an activity that gives rise to the risk.
Question 10: An organization is implementing security awareness training as part of its risk treatment plan. This is an example of which PDCA phase?
- Act
- Check
- Plan
- Do (Correct answer)
Correct answer: Do
Implementing controls and programs defined in the risk treatment plan is a Do phase activity.
Question 11: According to ISO 27000, what is an information security event?
- A planned maintenance activity that temporarily affects information systems
- A confirmed successful attack on an organization's information assets
- An identified occurrence indicating a possible breach of information security policy (Correct answer)
- Any action taken by a user on a computer system
Correct answer: An identified occurrence indicating a possible breach of information security policy
ISO 27000 defines an information security event as an identified occurrence of a system, service, or network state indicating a possible breach of policy, failure of controls, or a previously unknown security-relevant situation.
Question 12: What has to be done as part of the monitoring, measuring, analysis, and evaluation process?
- Measure the number of risks
- Evaluate the effectiveness of the ISMS (Correct answer)
- Analyse the percentage use of automated process
- Monitor the cost of maintaining the ISMS
Correct answer: Evaluate the effectiveness of the ISMS
Clause 9.1 of ISO 27001, 'Monitoring, measurement, analysis and evaluation,' explicitly requires the organization to evaluate the information security performance and the effectiveness of the ISMS. This is a crucial step to ensure that the implemented controls and processes are achieving their intended outcomes and adequately protecting information assets.
Question 13: Which of the following is an administrative (managerial) information security control?
- Biometric door locks
- Data encryption at rest
- Security awareness training programs (Correct answer)
- Intrusion detection systems
Correct answer: Security awareness training programs
Administrative controls are policies, procedures, and training programs that govern people's behavior and organizational processes.
Question 14: How often must an organization conduct internal ISMS audits according to ISO 27001?
- At planned intervals determined by the organization (Correct answer)
- Every three years to align with certification cycles
- Annually without exception
- Only when a security incident occurs
Correct answer: At planned intervals determined by the organization
ISO 27001 requires internal audits at planned intervals, but the frequency is left to the organization to determine based on risk and importance.
Question 15: Which ISO standard provides the vocabulary and definitions used across the ISO 27000 family?
- ISO 27001
- ISO 27005
- ISO 27000 (Correct answer)
- ISO 27002
Correct answer: ISO 27000
ISO 27000 is the overview and vocabulary standard that provides common terms and definitions for the entire ISO 27000 family.
Question 16: What must the company create?
- Statement of applicability (Correct answer)
- Statement of control
- Statement of implementation
Correct answer: Statement of applicability
The Statement of Applicability (SoA) is a mandatory document under ISO 27001. It lists all controls from Annex A that are relevant to the organization's ISMS, along with justifications for their inclusion or exclusion, and a description of how they are implemented. This document demonstrates how the organization has addressed the identified risks and chosen its controls.
Question 17: Under ISO 27001, which document formally records top management's decision to accept residual risks?
- The risk treatment plan
- Signed risk acceptance records (Correct answer)
- The risk register
- The Statement of Applicability
Correct answer: Signed risk acceptance records
Formal records of risk acceptance decisions must be maintained and are typically documented as signed acceptance statements by authorized risk owners.
Question 18: In the context of ISO 27000, what does 'availability' mean in the CIA triad?
- Authorized users can access information when needed (Correct answer)
- Data has not been altered without authorization
- Data is encrypted at rest
- Information is not disclosed to unauthorized parties
Correct answer: Authorized users can access information when needed
Availability means ensuring that authorized users have access to information and associated assets when required.
Question 19: Which task must be completed while analyzing risks?
- Accept all evaluated risks
- Determine the likelihood of the occurrence of the risks (Correct answer)
- Select appropriate controls
- Identify the risks associated with loss of confidentiality
Correct answer: Determine the likelihood of the occurrence of the risks
Risk analysis, as a key part of the risk assessment process (Clause 6.1.2), involves identifying risks, determining their likelihood of occurrence, and evaluating their potential consequences. Determining the likelihood helps the organization understand the probability of a risk materializing, which is essential for prioritizing and selecting appropriate treatment options.
Question 20: All of the above
- Provides terms and definitions commonly used in ISO/IEC 27001 (Correct answer)
- Outlines a code of practice for information security controls
- Provides information on security risk management
- Provides guidelines for network security
Correct answer: Provides terms and definitions commonly used in ISO/IEC 27001
ISO/IEC 27000 serves as the foundational standard within the ISO 27000 family. Its primary purpose is to provide an overview of the information security management system (ISMS) standards and, crucially, to define the terms and definitions commonly used across these standards, including ISO/IEC 27001. This ensures a consistent understanding and application of terminology for anyone working with information security management systems.
Question 21: What is the main output of the risk treatment process within an operational ISMS?
- An updated organizational chart showing security roles
- A report submitted directly to regulators
- A final list of all organizational assets
- A risk treatment plan and updated Statement of Applicability (Correct answer)
Correct answer: A risk treatment plan and updated Statement of Applicability
Risk treatment produces a risk treatment plan detailing selected controls and updates the SoA to reflect implementation decisions.
Question 22: In the PDCA model, what is the primary risk of skipping the 'Check' phase?
- Ineffective controls may go undetected, leaving the organization exposed (Correct answer)
- New employees will not receive security training
- The risk treatment plan cannot be updated
- The ISMS will become too expensive to operate
Correct answer: Ineffective controls may go undetected, leaving the organization exposed
Without Check phase activities, failed or ineffective controls are not identified, undermining the entire ISMS.
Question 23: Which of the following BEST describes 'information security risk treatment' according to ISO 27005?
- Selecting and implementing measures to modify risk (Correct answer)
- Identifying and listing all risks in the organization's environment
- Evaluating risks against pre-defined acceptance criteria
- Communicating risk results to senior management
Correct answer: Selecting and implementing measures to modify risk
Risk treatment is the process of selecting and implementing options to address risk, which may include modifying, avoiding, sharing, or retaining it.
Question 24: Which of the following best describes 'risk transfer' as a risk treatment option?
- Accepting that the risk is within tolerance levels
- Moving risk responsibility to another party such as via insurance or outsourcing (Correct answer)
- Reducing the likelihood of a threat occurring
- Eliminating the asset that carries the risk
Correct answer: Moving risk responsibility to another party such as via insurance or outsourcing
Risk transfer involves shifting the financial or operational consequences of a risk to a third party, such as purchasing cyber insurance.
Question 25: What does 'asset classification' involve under ISO 27001?
- Disposing of assets that are no longer in use
- Categorizing assets based on their value and sensitivity to apply appropriate protection (Correct answer)
- Encrypting all organizational assets
- Inventorying only physical hardware assets
Correct answer: Categorizing assets based on their value and sensitivity to apply appropriate protection
Asset classification assigns labels such as public, internal, confidential, or secret to determine the level of protection each asset requires.
Question 26: Under ISO 27001, what must happen if a significant change occurs in the organization?
- The ISMS certification is immediately revoked
- Only the IT department needs to be notified
- The ISMS scope and risk assessment must be reviewed and updated (Correct answer)
- No action is required until the next scheduled audit
Correct answer: The ISMS scope and risk assessment must be reviewed and updated
ISO 27001 requires organizations to review their ISMS, including scope and risk assessment, whenever significant changes occur.
Question 27: Which ISO 27000 series standard provides requirements for establishing an Information Security Management System (ISMS)?
- ISO 27005
- ISO 27002
- ISO 27017
- ISO 27001 (Correct answer)
Correct answer: ISO 27001
ISO 27001 is the standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS.
Question 28: What does 'residual risk' mean in the context of ISO 27001?
- Risk remaining after risk treatment measures have been applied (Correct answer)
- Risk that has been transferred to an insurance provider
- Risk identified but not yet assessed
- Risk that has been fully eliminated by controls
Correct answer: Risk remaining after risk treatment measures have been applied
Residual risk is the level of risk that remains after the organization has implemented its chosen risk treatment controls.
Question 29: A company's ISMS scope includes 'information in all formats.' What does this imply?
- Physical documents, verbal communications, and digital data are all within scope (Correct answer)
- Only structured database records are included
- Printed materials are always excluded from ISMS controls
- Only digital data stored on servers is covered
Correct answer: Physical documents, verbal communications, and digital data are all within scope
When scope includes 'information in all formats,' it encompasses digital, physical (paper), and other forms of information, ensuring comprehensive protection.
Question 30: An organization discovers during an internal audit that its incident response procedures are not being followed. Which PDCA phase does this discovery belong to?
- Check (Correct answer)
- Act
- Do
- Plan
Correct answer: Check
Internal audits and reviews are Check phase activities that measure whether implemented controls are effective.
Question 31: How does incident management relate to an organization's ISMS under ISO 27001?
- Incident management replaces the need for a formal ISMS in smaller organizations
- Incident management is a separate discipline and does not form part of the ISMS
- The ISMS only addresses prevention of incidents, not their management
- Incident management is a required component of the ISMS covering response and improvement (Correct answer)
Correct answer: Incident management is a required component of the ISMS covering response and improvement
ISO 27001 requires organizations to plan and implement incident management processes as a mandatory part of the ISMS, particularly through Annex A controls A.5.24 to A.5.28.
Question 32: What is the primary purpose of an Information Security Management System (ISMS) as described in the ISO 27000 series?
- To guarantee the complete elimination of all information security incidents.
- To exclusively implement technical controls to prevent cyberattacks.
- To provide a systematic approach for establishing, implementing, maintaining, and continually improving information security. (Correct answer)
- To satisfy legal and regulatory requirements as the sole objective.
Correct answer: To provide a systematic approach for establishing, implementing, maintaining, and continually improving information security.
An ISMS is a systematic, risk-based approach to managing an organization's information security. It is a management framework that involves policies, processes, procedures, and controls to protect information assets, and it is based on a cycle of continual improvement (Plan-Do-Check-Act). While it helps satisfy requirements and implement controls, its primary purpose is the overall management system. Eliminating all incidents is not a realistic goal.
Question 33: Which PDCA phase includes defining the ISMS scope?
- Check
- Do
- Act
- Plan (Correct answer)
Correct answer: Plan
Defining the ISMS scope is a foundational planning activity that determines what the ISMS will cover.
Question 34: Which ISO 27001 clause requires organizations to determine and provide resources needed for the ISMS?
- Clause 6 — Planning
- Clause 4 — Context of the Organization
- Clause 9 — Performance Evaluation
- Clause 7 — Support (Correct answer)
Correct answer: Clause 7 — Support
Clause 7 (Support) addresses resources, competence, awareness, communication, and documented information required for ISMS operation.
Question 35: Which of the following best describes 'documented information' in the context of ISO 27001 ISMS operation?
- Emails exchanged between employees about security topics
- Information that must be controlled and maintained, in any format or media (Correct answer)
- Only paper-based policies stored in a locked cabinet
- Verbal instructions given during security briefings
Correct answer: Information that must be controlled and maintained, in any format or media
ISO 27001 uses 'documented information' broadly to mean any information that must be controlled, whether electronic, paper, or other media.
Question 36: Which of the following is NOT considered one of the three core properties of information security defined in the CIA triad within ISO/IEC 27000?
- Integrity
- Availability
- Accountability (Correct answer)
- Confidentiality
Correct answer: Accountability
The CIA triad, a fundamental concept in ISO/IEC 27000, stands for Confidentiality, Integrity, and Availability. While accountability is an important security principle, it is not one of the three core components of the triad itself as formally defined in the standard.
Question 37: Which benefit does running an information security management system NOT provide?
- Eliminate all information security vulnerabilities in the organization (Correct answer)
- Provide consistent management and operation of information security across the organization
- Reduce the probability of information security incidents
- Increase in shareholder trust in the organization
Correct answer: Eliminate all information security vulnerabilities in the organization
While an ISMS significantly reduces information security risks and vulnerabilities, it is impossible to eliminate *all* vulnerabilities. Information security is an ongoing process, and new threats and vulnerabilities constantly emerge. The goal of an ISMS is to manage and reduce risk to an acceptable level, not to achieve absolute elimination of all vulnerabilities.
Question 38: What must be included in an information security policy according to ISO 27001?
- Employee salary information
- Objectives and a commitment to satisfying applicable requirements (Correct answer)
- Specific firewall configurations
- Detailed network architecture
Correct answer: Objectives and a commitment to satisfying applicable requirements
ISO 27001 specifies that the information security policy must include security objectives or a framework for setting them and a commitment to satisfying applicable requirements.
Question 39: Which term describes the combination of the likelihood of a threat exploiting a vulnerability and the resulting impact on the organization?
- Vulnerability
- Risk (Correct answer)
- Asset value
- Control
Correct answer: Risk
Risk is defined as the combination of the probability of a threat event occurring and the magnitude of its impact.
Question 40: In ISO 27000, what is the difference between a 'threat' and a 'threat actor'?
- A threat is the potential cause of harm; a threat actor is the entity that exploits it (Correct answer)
- A threat actor is a technical vulnerability; a threat is a business risk
- A threat only applies to digital assets; a threat actor applies to physical assets
- They are synonymous terms used interchangeably
Correct answer: A threat is the potential cause of harm; a threat actor is the entity that exploits it
A threat is the potential cause of an unwanted incident, while a threat actor (or threat source) is the human or environmental entity that carries it out.
Question 41: What is the significance of 'preventive actions' in the PDCA cycle as applied to an ISMS?
- They replace the need for corrective actions
- They are performed exclusively by external auditors
- They are only relevant during the Do phase
- They address potential nonconformities before they occur, applied during Plan and Act phases (Correct answer)
Correct answer: They address potential nonconformities before they occur, applied during Plan and Act phases
Preventive actions anticipate and eliminate causes of potential nonconformities, typically planned in the Plan phase and reinforced in Act.
Question 42: An organization is establishing its ISMS according to ISO 27001 and is determining its 'interested parties' as required by Clause 4.2. Which of the following would be the LEAST likely to be considered a relevant interested party with requirements pertinent to the ISMS?
- The company's shareholders who are concerned about business continuity.
- A government regulatory body that enforces data protection laws.
- A major customer who requires security assurances in their service contract.
- A competitor company operating in the same market. (Correct answer)
Correct answer: A competitor company operating in the same market.
Interested parties are individuals or organizations that can affect, be affected by, or perceive themselves to be affected by the organization's ISMS. Regulators, customers, and shareholders have direct requirements and expectations for the organization's information security. While a competitor is part of the business environment, they do not typically have direct, legitimate requirements *for* the organization's ISMS that need to be addressed within its framework.
Question 43: Which concept ensures that information security governance decisions are traceable back to accountable individuals?
- Redundancy
- Segmentation
- Encryption
- Accountability (Correct answer)
Correct answer: Accountability
Accountability in governance means that every security decision and action can be traced to a specific responsible individual, supporting audit and oversight.
Question 44: Which ISO/IEC 27000 series standard specifically defines the PDCA model's application to information security management?
- ISO/IEC 27001 (Correct answer)
- ISO/IEC 27002
- ISO/IEC 27003
- ISO/IEC 27005
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the ISMS requirements standard that formally applies the PDCA model to information security management.
Question 45: Which of the following is NOT a required input to management review under ISO 27001 Clause 9.3?
- Competitor analysis and market positioning reports (Correct answer)
- Feedback on information security performance including trends in nonconformities
- Opportunities for continual improvement
- Results of risk assessment and status of the risk treatment plan
Correct answer: Competitor analysis and market positioning reports
ISO 27001 does not require competitor analysis as an input to management review — it focuses on ISMS performance, risk, and stakeholder feedback.
Question 46: During a risk evaluation phase, an organization compares the estimated levels of risk against criteria they have predefined. What is the primary goal of this activity?
- To select the most cost-effective security controls from Annex A.
- To make decisions on which risks require treatment. (Correct answer)
- To assign ownership for each of the identified risks.
- To identify all possible threats and vulnerabilities to the organization's assets.
Correct answer: To make decisions on which risks require treatment.
The risk evaluation step involves comparing the results of the risk analysis (the calculated risk levels) with the organization's predefined risk acceptance criteria. This comparison is crucial for deciding which risks are unacceptably high and therefore need to be treated, and which risks are low enough to be accepted without further action.
Question 47: In the context of ISO 27001, what is the PRIMARY purpose of a Statement of Applicability (SoA)?
- To list all identified risks and their owners
- To record residual risk acceptance decisions
- To document which Annex A controls are applicable and their justification (Correct answer)
- To define the risk appetite of the organization
Correct answer: To document which Annex A controls are applicable and their justification
The SoA documents which of the ISO 27001 Annex A controls have been selected or excluded and the reasons why.
Question 48: When selecting risk treatment options, which ISO/IEC 27001 principle requires that control costs should be proportionate to the risks they address?
- Zero-risk tolerance
- Risk elimination principle
- Cost-benefit analysis (Correct answer)
- Mandatory compliance
Correct answer: Cost-benefit analysis
ISO/IEC 27001 encourages cost-benefit analysis to ensure that the cost of implementing a control does not exceed the value of the risk being mitigated.
Question 49: Which term refers to the remaining risk after security controls have been applied?
- Residual risk (Correct answer)
- Accepted risk
- Inherent risk
- Transferred risk
Correct answer: Residual risk
Residual risk is the level of risk that remains after risk treatment measures have been implemented.
Question 50: What role does the Statement of Applicability (SoA) play in the PDCA cycle?
- It is an Act phase document for continual improvement plans
- It is a Check phase report on control effectiveness
- It is produced in the Do phase to document implemented controls
- It is a Plan phase output that links Annex A controls to the risk treatment decisions (Correct answer)
Correct answer: It is a Plan phase output that links Annex A controls to the risk treatment decisions
The SoA is created during the Plan phase to document which Annex A controls are applicable, included, or excluded and why.
Question 51: What should be done with documented information resulting from monitoring and measurement activities?
- Retained as evidence of the results (Correct answer)
- Deleted after each audit cycle to reduce storage costs
- Shared only with executive management
- Submitted to ISO certification bodies immediately
Correct answer: Retained as evidence of the results
ISO 27001 Clause 9.1 requires that documented information be retained as evidence of the monitoring and measurement results.
Question 52: What does 'dwell time' refer to in the context of information security incidents?
- The time taken to fully restore systems and services after an incident is resolved
- The time elapsed between incident detection and successful containment
- The duration required to write and submit a formal incident report
- The period an attacker remains undetected within a compromised system (Correct answer)
Correct answer: The period an attacker remains undetected within a compromised system
Dwell time is the period between when an attacker first gains access to a system and when the breach is detected; shorter dwell time generally means less damage.
Question 53: Which ISO/IEC standard specifically provides requirements for establishing and maintaining an ISMS?
- ISO/IEC 27005
- ISO/IEC 27000
- ISO/IEC 27001 (Correct answer)
- ISO/IEC 27002
Correct answer: ISO/IEC 27001
ISO/IEC 27001 specifies the requirements for establishing, implementing, maintaining, and continually improving an ISMS.
Question 54: A multinational company defines its ISMS scope to cover only its US operations. Which obligation must it still consider?
- Implementing ISO 27001 in all regions immediately
- Hiring separate security staff for each region
- It has no further obligations since the scope is limited
- Interfaces with out-of-scope regions that could affect information security (Correct answer)
Correct answer: Interfaces with out-of-scope regions that could affect information security
Even with a limited scope, the organization must consider interfaces and dependencies with out-of-scope areas that could affect the ISMS's effectiveness.
Question 55: Which quantitative measure expresses the expected monetary loss from a specific threat occurring once?
- Single Loss Expectancy (SLE) (Correct answer)
- Annualized Loss Expectancy (ALE)
- Annualized Rate of Occurrence (ARO)
- Exposure Factor (EF)
Correct answer: Single Loss Expectancy (SLE)
Single Loss Expectancy (SLE) represents the monetary loss expected each time a specific threat event occurs.
Question 56: Why is it mandatory for the scope of the ISMS to be maintained as documented information?
- To provide a clear basis for the information security risk assessment and to inform stakeholders. (Correct answer)
- To allow the marketing team to use it in promotional materials.
- To fulfill a legal requirement mandated by international trade agreements.
- To serve as the main input for the annual financial audit.
Correct answer: To provide a clear basis for the information security risk assessment and to inform stakeholders.
ISO/IEC 27001 Clause 4.3 explicitly states, 'The scope shall be available as documented information.' This documentation is crucial because it defines the boundaries for all subsequent ISMS activities, including risk assessment (Clause 6.1.2) and the creation of the Statement of Applicability. It also serves to clearly communicate the coverage of the ISMS to all stakeholders, including auditors, customers, and employees.
Question 57: What should an organization do when a planned information security objective cannot be achieved on schedule?
- Remove the objective from the ISMS scope permanently
- Immediately certify the ISMS anyway and address gaps later
- Keep the objective private to avoid negative audit findings
- Escalate to top management and revise the plan with corrective actions (Correct answer)
Correct answer: Escalate to top management and revise the plan with corrective actions
Unmet objectives must be escalated with a revised plan, ensuring accountability and corrective action in line with ISO 27001 requirements.
Question 58: A financial firm applies PDCA to its ISMS after a data breach. In which phase would root cause analysis of the breach be performed?
- Plan
- Do
- Check (Correct answer)
- Act
Correct answer: Check
Investigating incidents and performing root cause analysis are Check phase activities that evaluate what went wrong.
Question 59: How should information security responsibilities be communicated to employees according to ISO 27001?
- Through IT system access logs
- Only verbally during onboarding
- Via annual performance reviews only
- Through documented policies, procedures, and awareness programs (Correct answer)
Correct answer: Through documented policies, procedures, and awareness programs
ISO 27001 requires that roles and responsibilities be documented and communicated through formal policies, procedures, and ongoing awareness activities.
Question 60: What distinguishes a 'vulnerability' from a 'threat' in information security risk terminology?
- There is no distinction — the terms are interchangeable in ISO 27000
- A vulnerability causes impact; a threat reduces likelihood
- A threat is a potential cause of harm; a vulnerability is a weakness that can be exploited by a threat (Correct answer)
- A vulnerability is an external actor; a threat is an internal weakness
Correct answer: A threat is a potential cause of harm; a vulnerability is a weakness that can be exploited by a threat
ISO 27000 defines a threat as a potential cause of an unwanted incident, while a vulnerability is a weakness that may be exploited by one or more threats.
Question 61: Which activity DOES NOT fall under a certifying body's mandates and obligations?
- Advise how to fill the gaps found during a readiness assessment (Correct answer)
- Check and approve the scope of the ISMS
- Internal and lead auditor training
- Use external auditors to carry out formal assessment against ISO/IEC 27001
Correct answer: Advise how to fill the gaps found during a readiness assessment
A certifying body's role is to conduct independent audits and assess an organization's conformity to the standard, maintaining impartiality. Providing specific advice on how to fill gaps or implement controls would be considered consulting, which creates a conflict of interest for a certifying body. They identify nonconformities but do not prescribe solutions.
ISO 27000 Foundation Certification Exam
The ISO 27000 Foundation Certification Exam exam validates essential knowledge and skills required for certification or licensure in this field.
Exam Rules
- You can skip questions and return to them later
- Flag questions for review before submitting
- No feedback shown until you submit the entire exam
- Unanswered questions count as wrong — answer everything
- 10 pretest questions are mixed in and don't affect your score
- Timer auto-submits when time runs out
- Your progress is auto-saved every 30 seconds