ISO 27001 Module 1-3 Questions
2025/2026 Exam All Answers and
Illustrations Given
A list of required documentation. - 🧠ANSWER ✔✔Scope of ISMS
Information secuirty and risk treatment
Information secuirty policy and objectives
Statement of Applicability
Risk treatment plan
Risk treatment report
Records of training, skills experience and qualifications
Monitoring measurement results
Internal audit program
Results of internal audit
Results of mangement review
Results of corrective actions
1
COPYRIGHT©JOSHCLAY 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE. PRIVACY
STATEMENT. ALL RIGHTS RESERVED
, Is ISO 27001 a standard that defines the technical details for information
security, e.g., how to configure a firewall? - 🧠ANSWER ✔✔No
Why is the Planning section described before the Operation section in the
standard? - 🧠ANSWER ✔✔In order to have efficient operations, you need
to plan them ahead
Identify which of the following information security controls are
organizational controls: - 🧠ANSWER ✔✔Defining a policy on the use of
cryptographic controls
Documenting a clear screen policy
Documenting a procedure for training employees
Choose which of the following activities are parts of the Plan phase: -
🧠ANSWER ✔✔Identify information security risks
Based on the results from the risk assessment, choose controls and
document a Statement of applicability
Document the Information Security Policy
2
COPYRIGHT©JOSHCLAY 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE. PRIVACY
STATEMENT. ALL RIGHTS RESERVED
2025/2026 Exam All Answers and
Illustrations Given
A list of required documentation. - 🧠ANSWER ✔✔Scope of ISMS
Information secuirty and risk treatment
Information secuirty policy and objectives
Statement of Applicability
Risk treatment plan
Risk treatment report
Records of training, skills experience and qualifications
Monitoring measurement results
Internal audit program
Results of internal audit
Results of mangement review
Results of corrective actions
1
COPYRIGHT©JOSHCLAY 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE. PRIVACY
STATEMENT. ALL RIGHTS RESERVED
, Is ISO 27001 a standard that defines the technical details for information
security, e.g., how to configure a firewall? - 🧠ANSWER ✔✔No
Why is the Planning section described before the Operation section in the
standard? - 🧠ANSWER ✔✔In order to have efficient operations, you need
to plan them ahead
Identify which of the following information security controls are
organizational controls: - 🧠ANSWER ✔✔Defining a policy on the use of
cryptographic controls
Documenting a clear screen policy
Documenting a procedure for training employees
Choose which of the following activities are parts of the Plan phase: -
🧠ANSWER ✔✔Identify information security risks
Based on the results from the risk assessment, choose controls and
document a Statement of applicability
Document the Information Security Policy
2
COPYRIGHT©JOSHCLAY 2025/2026. YEAR PUBLISHED 2025. COMPANY REGISTRATION NUMBER: 619652435. TERMS OF USE. PRIVACY
STATEMENT. ALL RIGHTS RESERVED