CertiProf
I27001F
Q1:
According to ISO/IEC 27001:2022, is it necessary to ensure that the Information Security Management System can achieve its intended results?
○
A
It is only an observation to keep in mind when auditing the management system○
B
It is a requirement to be fulfilled○
C
It is a recommendation, but not a requirement○
D
None of the above
CertiProf
I27001F
Q2:
What does ISO/IEC 27001:2022 require for the control of documented information?
○
A
A person designated by top management with expertise to control documented information○
B
Acquisition of a set of information security tools for effective documented information control○
C
A consultancy to accurately perform documented information control○
D
Appropriate protection, for example, against loss of confidentiality, improper use, or loss of integrity
CertiProf
I27001F
Q3:
During the operation of the ISMS, what is a requirement for information security objectives?
○
A
Develop improvement plans using ISO/IEC 27002 to achieve the information security objectives○
B
Maintain documented information about the objectives○
C
Ensure that the objectives are consistent with the information security policy○
D
Establish objectives for relevant functions and levels
CertiProf
I27001F
Q4:
What are the phases of the PDCA cycle?
○
A
Plan, Validate, Verify, Act○
B
Plan, Do, Check, Act○
C
Plan, Do, Verify, Assure○
D
Propose, Do, Validate, Act
CertiProf
I27001F
Q5:
What does ISO/IEC 27001:2022 require for internal audits?
○
A
A person designated by top management who can perform internal audits in all areas within the system scope○
B
Acquisition of a set of information security tools to document internal audits○
C
Conducting internal audits at planned intervals to provide information on whether the Information Security Management System conforms to the organization's own requirements and to the requirements of ISO/IEC 27001:2022○
D
A consultancy to perform second-party internal audits accurately