Q: 1
Which is a control title within Annex A of ISO/IEC 27001?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 2
Which statement describes a requirement of an internal audit programme?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 3
Identify the missing word in the following sentence.
The organization shall determine the [ ? ] of interested parties relevant to information security.
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 4
Identify the missing word in the following sentence.
According to ISO/IEC 27000, the definition of risk [?] is a “process to comprehend the nature of risk
and to determine the level of risk.”
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 5
Which item is required to be included in an information security policy?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 6
Which benefit is NOT relevant by implementing an ISMS for an organization?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 7
Which International Standard can be used to implement an integrated management system with
ISO/IEC 27001?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 8
Which action is a required response to an identified residual risk?
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Q: 9
Which of the following statements about the differences between an internal audit and a
certification audit is true?
An internal audit is conducted at planned intervals and a certification audit is conducted annually
An internal audit is known as a 1st party audit and a certification audit is known as a 3rd party audit
Options
Discussion
No comments yet. Be the first to comment.
Be respectful. No spam.
Question 1 of 20 · Page 1 / 2