• Wrong document? Swap it for free
  • Written by students who passed
  • Immediately available after payment
  • Read online or as PDF
Sell
Where do you study
Your language
Document preview thumbnail
Preview 3 out of 21 pages
Exam (elaborations)

Iso 27001 Foundation Correct Final Exams Questions And Answers Sure A.pdf

Document preview thumbnail
Preview 3 out of 21 pages

ISO 27001 FOUNDATION CORRECT FINAL EXAMS QUESTIONS AND ANSWERS SURE A.pdf

Content preview

ISO 27001 FOUNDATION CORRECT FINAL EXAMS
QUESTIONS AND ANSWERS SURE A+
✔✔1. With which of the following principles does an organization comply if it ensures
that only authorized users have access to their sensitive data?
A. Confidentiality
B. Integrity
C. Availability - ✔✔A. Confidentiality

✔✔1. What does the integrity principle entail?
A. That information is available to authorized individuals
B. That information is accurate and safe from unauthorized access
C. That information is accessible when needed - ✔✔B. That information is accurate and
safe from unauthorized access

✔✔1. Which of the options below represents an example of a vulnerability?
A. Unencrypted data
B. Unauthorized access by persons who have left the organization
C. Data input error by personnel - ✔✔A. Unencrypted data

✔✔1. What can have an impact on the availability of information?
A. Incorrect results
B. Deliberate change of information
C. Performance degradation - ✔✔C. Performance degradation

✔✔1. An organization has clearly defined the security procedures and uses an access
control software to avoid unauthorized access of the personnel to its confidential data.
What is the function of these security controls?
A. To prevent the occurrence of incidents
B. To correct errors arising from a problem
C. To report the occurrence of a malicious act - ✔✔A. To prevent the occurrence of
incidents

,✔✔1. To which classification of security controls does the implementation of patches
after the identification of system vulnerabilities belong?
A. Preventive by function and managerial by type
B. Corrective by function and technical by type
C. Detective by function and administrative by type - ✔✔B. Corrective by function and
technical by type

✔✔1. What is one of the main purposes of implementing an ISMS?
A. To determine the information security objectives
B. To define the information security requirements
C. To reduce information security risks - ✔✔C. To reduce information security risks

✔✔1. Which of the statements below regarding the ISMS scope is correct?
A. Any inclusions made in the ISMS scope should be justified
B. A key process is not considered part of organizational boundaries
C. The ISMS scope must be available as documented information - ✔✔C. The ISMS
scope must be available as documented information

✔✔1. Who is responsible for establishing the information security policy according to
ISO/IEC 27001?
A. The top management
B. Internal interested parties
C. The information security manager - ✔✔A. The top management

✔✔1. What criteria should be considered when selecting a risk assessment
methodology?
A. New technologies
B. Costs and availability of supporting software tools
C. Risk treatment plan - ✔✔B. Costs and availability of supporting software tools

✔✔1. An organization has decided to move its information-processing facilities to a
place where the risk of flooding is low. What option of risk treatment is this?
A. Risk avoidance
B. Risk evaluation
C. Risk sharing - ✔✔A. Risk avoidance

✔✔1. Why should an organization draft a Statement of Applicability?
A. To document the justifications for the inclusion and exclusion of Annex A controls
B. To ensure that the ISMS is aligned with the mission of the organization
C. To ensure compliance with industry best practices - ✔✔A. To document the
justifications for the inclusion and exclusion of Annex A controls

✔✔1. The risk that remains after risk treatment is known as:

, A. Inherent risk
B. Treated risk
C. Residual risk - ✔✔C. Residual risk

✔✔Webos is a software company that offers custom web-based IT solutions for banks
and financial institutions. They are focused on developing personalized and flexible
banking software. Hence, their services include processing sensitive data.
Recently, one of their main partners required an update of the software they got from
Webos because their current version was vulnerable to external attacks. Webos
provided an updated version that included migrating to the Windows Azure SQL
database to solve the encryption, authentication, and high availability problems.
However, the solution did not work and Webos's partner terminated their contract.
The project failed due to problems with the segregation of duties in Webos. Their only
software development team leader, Julia Robinson, was on maternity leave and her
duties and responsibilities were assigned to an inexperienced team member.
To increase the security of their services - ✔✔B. The database encryption problems

✔✔1. Webos's project failed due to the lack of segregation of duties during the
maternity leave of the software development team leader. Which of the following is a
threat that can impact Webos in this situation?
A. Failure to produce management reports
B. Insufficient software testing
C. Unauthorized use of the system - ✔✔C. Unauthorized use of the system

✔✔1. Webos conducted technical investigations after its partners reported security
incidents. What is the aim of implementing this security control?
A. To control software operations
B. To report the occurrence of an error or omission
C. To correct the problems and prevent their recurrence - ✔✔C. To correct the
problems and prevent their recurrence

✔✔1. By segregating the duties of the software development team, Webos
implemented:
A. A managerial control
B. An administrative control
C. A legal control - ✔✔B. An administrative control

✔✔1. Migration to the Windows Azure SQL database would solve the availability
problems by reducing the _____________.
A. Disruption of operations
B. Invasion of privacy of users
C. Leak of sensitive information - ✔✔A. Disruption of operations

✔✔1. What does ISO 19011 provide?
A. Guidance for auditors on information security controls

Document information

Uploaded on
July 8, 2026
Number of pages
21
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
EXAMCAFE
3.5
(43)
Sold
294
Followers
11
Items
36188
Last sold
3 days ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions