Key details for this exam, checked against the published exam outline
Each question shows the correct answer and an explanation of why it is right
Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?
Clause 7.2 (Competence) requires the organization to:
''determine the necessary competence of person(s) doing work under its control that affects its information security performance;''
''ensure that these persons are competent on the basis of appropriate education, training, or experience;''
''retain appropriate documented information as evidence of competence.''
This makes holding up-to-date records on training, skills, experience, and qualifications (D) the correct answer. Option A is irrelevant to competence. Option B is incorrect since ISO does not require Foundation-level training --- competence is context-based. Option C is related to compliance but does not ensure individual competence.
Thus, the verified correct answer is D.
Which activity is a required element of information security risk identification?
Clause 6.1.2 defines the mandatory elements of risk assessment. Under risk identification, the standard requires: ''identifies the information security risks: 1) apply the information security risk assessment process to identify risks...; and 2) identify the risk owners.'' By contrast, considering likelihood and determining levels of risk (options B and D) are part of risk analysis (6.1.2 d) ''assess the realistic likelihood...''; ''determine the levels of risk''), and prioritization for treatment (option C) is part of risk evaluation (6.1.2 e) ''prioritize the analysed risks for risk treatment''). Therefore, the specific activity that belongs to risk identification is to identify the risk owners. This sequencing is prescribed to ensure each risk has a designated owner responsible for decisions on treatment and acceptance downstream.
Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?
Clause 7.3 (Awareness) requires:
''Persons doing work under the organization's control shall be aware of: (a) the information security policy; (b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; (c) the implications of not conforming with the ISMS requirements.''
This applies not only to employees but also contractors and external parties under the organization's control. Competence (B) requires having skills, training, and experience, while Communication (C) covers defining communication processes (Clause 7.4). Nonconformity and corrective action (A) is part of Clause 10 (Improvement).
Therefore, the specific requirement that ensures contractors are made aware of the information security policies is found in Clause 7.3 Awareness. Correct answer: D.
Which output is a required result from risk analysis?
Clause 6.1.2 (d) states that during risk analysis, the organization shall:
''assess the potential consequences that would result if the risks identified... were to materialize;''
''assess the realistic likelihood of the occurrence of the risks identified;''
''determine the levels of risk.''
This makes it clear that the required output of risk analysis is the determined levels of risk. Risk acceptance criteria (A) are set earlier in 6.1.2(a), treatment control options (C) belong to 6.1.3, and prioritization (D) is part of risk evaluation (6.1.2 e). Therefore, the verified correct output is B: Determined levels of risk.
What activity is done first when preparing for an initial certification audit?
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27001:2022 standards and certification guidance:
Before a certification audit can begin, the scope of the ISMS must be clearly defined and agreed with the Certification Body. ISO/IEC 27001 Clause 4.3 requires: ''The scope shall be available as documented information.''
Certification Bodies require this scope statement to plan audit duration, resources, and coverage. Only after the scope is agreed does the Stage 1 audit begin, which reviews documented information and readiness. Stage 2 focuses on implementation and effectiveness. Evidence of corrective actions (C) is checked at Stage 2 if issues were identified earlier. Records provision (D) occurs during Stage 2, not first.
Thus, the first step in preparing for certification is A: Agreeing the scope of the ISMS with the Certification Body auditor.
50 questions covering all exam domains, starting from $20
9 domains from the APMG-International ISO-IEC-27001-Foundation exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from
Framework design creates reusable structural blueprints that support security development and ensure consistency across applications. Understanding how to develop, customize and deploy security frameworks is essential for building effective information security programs within organizations.
Data security involves safeguarding digital assets such as stored or transmitted data from unauthorized use, corruption or cyberattacks to maintain privacy and accuracy. Candidates must understand data classification, protection mechanisms and secure handling procedures throughout the information lifecycle.
Security breaches are incidents where security controls are compromised or about to be compromised, leading to unauthorized access or potential harm to data and systems. Candidates learn incident response procedures, breach containment, forensics and the reporting requirements defined in ISO/IEC 27001.
Cybersecurity focuses on protecting computer systems, networks and data from unauthorized access, damage, theft or disruption to preserve data integrity and availability. The exam covers how cybersecurity principles integrate into an overall ISMS and organizational governance.
Self-confidence reflects the trust an individual has in their skills, capabilities and worth, embodying a sense of assurance and personal strength. The Foundation exam validates foundational competency and builds confidence for professionals advancing into Practitioner and Auditor roles.
A continuous improvement process represents a consistent, structured effort aimed at refining products, services and processes to boost performance, efficiency and quality over time. ISO/IEC 27001 requires organizations to establish management review and internal audit processes that drive ongoing refinement of the ISMS.
Compliance describes an organization's dedication to recognizing and following relevant laws, regulations and policies to maintain operations within lawful and ethical boundaries. Candidates must understand how the ISMS supports regulatory compliance and provides evidence of adherence to legal and contractual obligations.
Information management covers the full process of handling information within an organization, including its acquisition, storage, distribution, use and eventual disposal or archiving. The ISO/IEC 27001 ISMS establishes controls across the entire information lifecycle to minimize risk and maintain compliance.
Risk management refers to the methodical approach of recognizing, assessing and mitigating risks to minimize their potential impact on achieving organizational objectives. The Foundation exam covers risk assessment, risk treatment and the risk management process that forms the core of ISO/IEC 27001.
Common questions about the exam itself