ISO 27001 PRACTICE EXAM QUESTIONS AND
ANSWERS
How does ISO/IEC 27000 define an asset? - ANSWER Anything that is
of value to the organization
What are ISO 27001 control sets, as outlined in the Annex? - ANSWER
Information security policies
Assess management
Access control
What does PDCA stand for? - ANSWER Plan, Do, Check, Act
What are some examples of threats to many organizations - ANSWER
Fraud
Loss of information
Unauthorized access
What is the purpose of ISO/IEC 27000? - ANSWER Provides terms and
definitions commonly used in ISO 27001
Within ISO/IEC 27001, what clause relates to corrective actions? -
ANSWER 10.1
Information security objectives shall be - ANSWER Consistent within the
organization security policy
measurable
communicated
When should organizations perform an information risk assessment? -
ANSWER At planned intervals or when significant changes are
proposed to occur
In line with clause 9.3, who shall review the organizations information
security management system at planned intervals to ensure its
continuing suitability, adequacy and effectiveness? - ANSWER Top
management
ANSWERS
How does ISO/IEC 27000 define an asset? - ANSWER Anything that is
of value to the organization
What are ISO 27001 control sets, as outlined in the Annex? - ANSWER
Information security policies
Assess management
Access control
What does PDCA stand for? - ANSWER Plan, Do, Check, Act
What are some examples of threats to many organizations - ANSWER
Fraud
Loss of information
Unauthorized access
What is the purpose of ISO/IEC 27000? - ANSWER Provides terms and
definitions commonly used in ISO 27001
Within ISO/IEC 27001, what clause relates to corrective actions? -
ANSWER 10.1
Information security objectives shall be - ANSWER Consistent within the
organization security policy
measurable
communicated
When should organizations perform an information risk assessment? -
ANSWER At planned intervals or when significant changes are
proposed to occur
In line with clause 9.3, who shall review the organizations information
security management system at planned intervals to ensure its
continuing suitability, adequacy and effectiveness? - ANSWER Top
management