Aegentra Labs
Menu
Login

Free · no account required

ISO/IEC 27001 Foundation practice questions

This Foundation sample checks whether you can recognise core ISMS concepts in a payroll incident without jumping ahead to an implementation or audit role. Reveal each answer to see the reasoning and why the other options fail.

What this exact sample covers

Information-security fundamentals in context

  • Confidentiality, integrity and availability
  • Assets, threats and vulnerabilities
  • Risk and control types
  1. Question 01Domain 1 · recall

    Which response best explains confidentiality, integrity and availability in the payroll incident?

    1. AExplain the purpose, relationship and expected outcome of confidentiality, integrity and availability.
    2. BMemorise a label for, but do not connect it to the management-system outcome of confidentiality, integrity and availability.
    3. CAssume the concept can be ignored until a certification body explains it during an external audit.
    the answer and reasoning

    Correct answerA. Explain the purpose, relationship and expected outcome of confidentiality, integrity and availability.

    The stronger response connects confidentiality, integrity and availability to a defined purpose, accountable action and usable evidence. Explain the purpose, relationship and expected outcome of confidentiality, integrity and availability. This avoids mistaking a document, assumption or outsourced activity for an effective and reviewable practice.

    Why the other options fail

    • B. This response deflects an accountability that remains with the organisation or practitioner and would leave the relevant competency unevidenced.
    • C. This response treats the visible artefact as the outcome and does not establish that the underlying process is suitable, owned and operating.

    Published exam-scope sources: ISO/IEC 27001 Foundation candidate handbook · ISO/IEC 27001:2022 information security management systems

  2. Question 02Domain 1 · analysis

    Which response best connects information assets with accountable asset ownership?

    1. AMemorise a label for, but do not connect it to the management-system outcome of information assets and asset ownership.
    2. BExplain the purpose, relationship and expected outcome of information assets and asset ownership.
    3. CAssume the concept can be ignored until a certification body explains it during an external audit.
    the answer and reasoning

    Correct answerB. Explain the purpose, relationship and expected outcome of information assets and asset ownership.

    The stronger response connects information assets and asset ownership to a defined purpose, accountable action and usable evidence. Explain the purpose, relationship and expected outcome of information assets and asset ownership. This avoids mistaking a document, assumption or outsourced activity for an effective and reviewable practice.

    Why the other options fail

    • A. This response treats the visible artefact as the outcome and does not establish that the underlying process is suitable, owned and operating.
    • C. This response treats the visible artefact as the outcome and does not establish that the underlying process is suitable, owned and operating.

    Published exam-scope sources: ISO/IEC 27001 Foundation candidate handbook · ISO/IEC 27001:2022 information security management systems

  3. Question 03Domain 1 · application

    Which response best distinguishes the threat, vulnerability and consequence in this case?

    1. AMemorise a label for, but do not connect it to the management-system outcome of threats, vulnerabilities and consequences.
    2. BAssume the concept can be ignored until a certification body explains it during an external audit.
    3. CExplain the purpose, relationship and expected outcome of threats, vulnerabilities and consequences.
    the answer and reasoning

    Correct answerC. Explain the purpose, relationship and expected outcome of threats, vulnerabilities and consequences.

    The stronger response connects threats, vulnerabilities and consequences to a defined purpose, accountable action and usable evidence. Explain the purpose, relationship and expected outcome of threats, vulnerabilities and consequences. This avoids mistaking a document, assumption or outsourced activity for an effective and reviewable practice.

    Why the other options fail

    • A. This response treats the visible artefact as the outcome and does not establish that the underlying process is suitable, owned and operating.
    • B. This response deflects an accountability that remains with the organisation or practitioner and would leave the relevant competency unevidenced.

    Published exam-scope sources: ISO/IEC 27001 Foundation candidate handbook · ISO/IEC 27001:2022 information security management systems

  4. Question 04Domain 1 · analysis

    Which response best explains information-security risk in the context of the payroll service?

    1. AExplain the purpose, relationship and expected outcome of information-security risk.
    2. BMemorise a label for, but do not connect it to the management-system outcome of information-security risk.
    3. CAssume the concept can be ignored until a certification body explains it during an external audit.
    the answer and reasoning

    Correct answerA. Explain the purpose, relationship and expected outcome of information-security risk.

    The stronger response connects information-security risk to a defined purpose, accountable action and usable evidence. Explain the purpose, relationship and expected outcome of information-security risk. This avoids mistaking a document, assumption or outsourced activity for an effective and reviewable practice.

    Why the other options fail

    • B. This response deflects an accountability that remains with the organisation or practitioner and would leave the relevant competency unevidenced.
    • C. This response treats the visible artefact as the outcome and does not establish that the underlying process is suitable, owned and operating.

    Published exam-scope sources: ISO/IEC 27001 Foundation candidate handbook · ISO/IEC 27001:2022 information security management systems

  5. Question 05Domain 1 · recall

    Which response best distinguishes preventive, detective and corrective controls for this incident?

    1. AMemorise a label for, but do not connect it to the management-system outcome of preventive, detective and corrective controls.
    2. BExplain the purpose, relationship and expected outcome of preventive, detective and corrective controls.
    3. CAssume the concept can be ignored until a certification body explains it during an external audit.
    the answer and reasoning

    Correct answerB. Explain the purpose, relationship and expected outcome of preventive, detective and corrective controls.

    The stronger response connects preventive, detective and corrective controls to a defined purpose, accountable action and usable evidence. Explain the purpose, relationship and expected outcome of preventive, detective and corrective controls. This avoids mistaking a document, assumption or outsourced activity for an effective and reviewable practice.

    Why the other options fail

    • A. This response treats the visible artefact as the outcome and does not establish that the underlying process is suitable, owned and operating.
    • C. This response treats the visible artefact as the outcome and does not establish that the underlying process is suitable, owned and operating.

    Published exam-scope sources: ISO/IEC 27001 Foundation candidate handbook · ISO/IEC 27001:2022 information security management systems

Continue preparing

Move from examples to a saved practice session.

Casual mode shows feedback as you answer. Full access adds the complete weighted bank, exam mode, saved results and domain-level analysis for this exact qualification.

Start free practice Read the complete exam guideBuy the official PECB course