Exam Question And Answers With Rationales 2026
1. Which of the following is the primary purpose of ISO 27001?
A. To provide a framework for an Information Security Management
System (ISMS)
B. To certify IT hardware
C. To audit financial records
D. To implement quality management systems
ISO 27001 is designed to establish, implement, maintain, and
continually improve an ISMS.
2. What does ISMS stand for?
A. Information Security Manual System
B. Information Security Management System
C. Information Systems Management Standard
D. Internal Security Monitoring System
ISMS refers to a systematic approach to managing sensitive company
information to ensure it remains secure.
3. Which clause of ISO 27001 focuses on leadership commitment?
A. Clause 4
B. Clause 5
C. Clause 5
D. Clause 7
Clause 5 emphasizes top management’s role in leadership and
commitment to the ISMS.
4. What is the purpose of a risk assessment in ISO 27001?
A. To evaluate employee performance
B. To identify, assess, and treat information security risks
C. To monitor financial risks
D. To comply with legal reporting requirements
,Risk assessment is critical for identifying threats and vulnerabilities
and determining how to manage them.
5. Which of the following is NOT a key component of ISO 27001?
A. Context of the organization
B. Leadership
C. Planning
D. Marketing strategy
ISO 27001 focuses on information security management, not business
marketing strategies.
6. What is an Annex A in ISO 27001?
A. A glossary of terms
B. A risk assessment methodology
C. A list of control objectives and controls
D. A sample ISMS policy
Annex A provides 114 controls categorized under different domains to
help manage information security risks.
7. Which ISO standard is directly linked with ISO 27001 for risk
management?
A. ISO 9001
B. ISO 27005
C. ISO 14001
D. ISO 31000
ISO 27005 provides guidelines for information security risk
management aligned with ISO 27001.
8. What is the first step in establishing an ISMS?
A. Risk treatment
B. Defining the scope and context of the ISMS
C. Implementing controls
D. Conducting internal audit
Defining the scope ensures clarity on which parts of the organization
the ISMS will cover.
, 9. Which of the following is an example of a preventive control?
A. Log analysis
B. Access control policies
C. Incident response
D. Forensic investigation
Preventive controls aim to stop security incidents before they occur.
10. What is the Plan-Do-Check-Act (PDCA) model used for in ISO
27001?
A. Financial planning
B. Marketing
C. Continual improvement of the ISMS
D. Employee training
PDCA ensures ongoing improvement of the information security
management system.
11. Which of the following best describes a “risk treatment plan”?
A. List of all threats
B. Employee awareness program
C. Plan detailing how identified risks will be managed
D. Audit checklist
A risk treatment plan defines the measures to mitigate, transfer,
avoid, or accept information security risks.
12. What is the primary purpose of an internal audit in ISO 27001?
A. To replace external audits
B. To monitor employee productivity
C. To verify that the ISMS conforms to ISO 27001 requirements
D. To implement new software
Internal audits help ensure the ISMS is effective and compliant with
ISO 27001.
13. Which of the following is considered a “confidentiality”
principle in information security?
A. Ensuring that information is accessible only to authorized