ISO 27001 FOUNDATION UPDATED CORRECT
QUESTIONS AND ANSWERS SURE A+
✔✔Reassessment of risk should be performed - ✔✔Regularly and when significant
changes occur
✔✔As per ISO/IEC 27001 requirements, documenting the results of the risk treatment
plan is - ✔✔Mandatory
✔✔Reporting information security incidents is the responsibility of - ✔✔It security staff,
internal auditor, ISMS manager , all employees.
✔✔Which of the following is a valid option for risk treatment according to ISO/IEC
27001 - ✔✔Buying an insurance to share the risk
✔✔When is an organization required to perform a security risk assessment? - ✔✔When
a significant change occurs
✔✔Changes to software packages should be controlled and restricted in order to -
✔✔Minimise introducing security vulnerabilities
✔✔A nonconformity occurs when - ✔✔A certain requirement is not complied with
✔✔Which of the following is an activity of the plan phase? - ✔✔Risk Identification
✔✔Which of the following statements are true about Information security continuity?
Information security continuity should be regularly
1-Verfied
2-Controlled
3-Reviewed
4-Evaluated - ✔✔Verified, Reviewed, evaluated
QUESTIONS AND ANSWERS SURE A+
✔✔Reassessment of risk should be performed - ✔✔Regularly and when significant
changes occur
✔✔As per ISO/IEC 27001 requirements, documenting the results of the risk treatment
plan is - ✔✔Mandatory
✔✔Reporting information security incidents is the responsibility of - ✔✔It security staff,
internal auditor, ISMS manager , all employees.
✔✔Which of the following is a valid option for risk treatment according to ISO/IEC
27001 - ✔✔Buying an insurance to share the risk
✔✔When is an organization required to perform a security risk assessment? - ✔✔When
a significant change occurs
✔✔Changes to software packages should be controlled and restricted in order to -
✔✔Minimise introducing security vulnerabilities
✔✔A nonconformity occurs when - ✔✔A certain requirement is not complied with
✔✔Which of the following is an activity of the plan phase? - ✔✔Risk Identification
✔✔Which of the following statements are true about Information security continuity?
Information security continuity should be regularly
1-Verfied
2-Controlled
3-Reviewed
4-Evaluated - ✔✔Verified, Reviewed, evaluated