APMG-International ISO-IEC-27001-Foundation Practice Exam Questions & Answers

5 Free Questions · Last reviewed: August 25, 2026 · Prepared & Reviewed by the ValidExamDumps Editorial Team

Exam Facts

APMG-International ISO-IEC-27001-Foundation Exam Details

Key details for this exam, checked against the published exam outline

50 Practice Questions (Our Bank)
120 minutes Exam Duration
Exam Code
ISO-IEC-27001-Foundation
Full Name
ISO/IEC 27001 (2022) Foundation Exam
Issuing Body
APMG-International
Question Format (Our Bank)
Multiple Choice
Delivery
Online proctored or at authorized test centers
Eligibility
No prerequisites required
Practice Questions

Free ISO-IEC-27001-Foundation Practice Questions

Each question shows the correct answer and an explanation of why it is right

VA
ValidExamDumps Editorial Team Every question and its answer is checked by our ISO-IEC-27001-Foundation exam preparation team, who also write the explanation shown with each one. How we research and review these pages
Question 1

Which action is an organization required to take to ensure that personnel are competent to perform their assigned tasks within the ISMS?

Correct Answer: D
Explanation

Clause 7.2 (Competence) requires the organization to:

''determine the necessary competence of person(s) doing work under its control that affects its information security performance;''

''ensure that these persons are competent on the basis of appropriate education, training, or experience;''

''retain appropriate documented information as evidence of competence.''

This makes holding up-to-date records on training, skills, experience, and qualifications (D) the correct answer. Option A is irrelevant to competence. Option B is incorrect since ISO does not require Foundation-level training --- competence is context-based. Option C is related to compliance but does not ensure individual competence.

Thus, the verified correct answer is D.

Question 2

Which activity is a required element of information security risk identification?

Correct Answer: A
Explanation

Clause 6.1.2 defines the mandatory elements of risk assessment. Under risk identification, the standard requires: ''identifies the information security risks: 1) apply the information security risk assessment process to identify risks...; and 2) identify the risk owners.'' By contrast, considering likelihood and determining levels of risk (options B and D) are part of risk analysis (6.1.2 d) ''assess the realistic likelihood...''; ''determine the levels of risk''), and prioritization for treatment (option C) is part of risk evaluation (6.1.2 e) ''prioritize the analysed risks for risk treatment''). Therefore, the specific activity that belongs to risk identification is to identify the risk owners. This sequencing is prescribed to ensure each risk has a designated owner responsible for decisions on treatment and acceptance downstream.

Question 3

Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?

Correct Answer: D
Explanation

Clause 7.3 (Awareness) requires:

''Persons doing work under the organization's control shall be aware of: (a) the information security policy; (b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; (c) the implications of not conforming with the ISMS requirements.''

This applies not only to employees but also contractors and external parties under the organization's control. Competence (B) requires having skills, training, and experience, while Communication (C) covers defining communication processes (Clause 7.4). Nonconformity and corrective action (A) is part of Clause 10 (Improvement).

Therefore, the specific requirement that ensures contractors are made aware of the information security policies is found in Clause 7.3 Awareness. Correct answer: D.

Question 4

Which output is a required result from risk analysis?

Correct Answer: B
Explanation

Clause 6.1.2 (d) states that during risk analysis, the organization shall:

''assess the potential consequences that would result if the risks identified... were to materialize;''

''assess the realistic likelihood of the occurrence of the risks identified;''

''determine the levels of risk.''

This makes it clear that the required output of risk analysis is the determined levels of risk. Risk acceptance criteria (A) are set earlier in 6.1.2(a), treatment control options (C) belong to 6.1.3, and prioritization (D) is part of risk evaluation (6.1.2 e). Therefore, the verified correct output is B: Determined levels of risk.

Question 5

What activity is done first when preparing for an initial certification audit?

Correct Answer: A
Explanation

Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27001:2022 standards and certification guidance:

Before a certification audit can begin, the scope of the ISMS must be clearly defined and agreed with the Certification Body. ISO/IEC 27001 Clause 4.3 requires: ''The scope shall be available as documented information.''

Certification Bodies require this scope statement to plan audit duration, resources, and coverage. Only after the scope is agreed does the Stage 1 audit begin, which reviews documented information and readiness. Stage 2 focuses on implementation and effectiveness. Evidence of corrective actions (C) is checked at Stage 2 if issues were identified earlier. Records provision (D) occurs during Stage 2, not first.

Thus, the first step in preparing for certification is A: Agreeing the scope of the ISMS with the Certification Body auditor.

Get Full Access

50 questions covering all exam domains, starting from $20

Study Guide

What the APMG-International ISO-IEC-27001-Foundation Exam Covers

9 domains from the APMG-International ISO-IEC-27001-Foundation exam outline, with approximate weightings. Every sample question above is tagged with the domain it comes from

Domain 1: Framework Design

Framework design creates reusable structural blueprints that support security development and ensure consistency across applications. Understanding how to develop, customize and deploy security frameworks is essential for building effective information security programs within organizations.

Domain 2: Data Security

Data security involves safeguarding digital assets such as stored or transmitted data from unauthorized use, corruption or cyberattacks to maintain privacy and accuracy. Candidates must understand data classification, protection mechanisms and secure handling procedures throughout the information lifecycle.

Domain 3: Security Breaches

Security breaches are incidents where security controls are compromised or about to be compromised, leading to unauthorized access or potential harm to data and systems. Candidates learn incident response procedures, breach containment, forensics and the reporting requirements defined in ISO/IEC 27001.

Domain 4: Cybersecurity

Cybersecurity focuses on protecting computer systems, networks and data from unauthorized access, damage, theft or disruption to preserve data integrity and availability. The exam covers how cybersecurity principles integrate into an overall ISMS and organizational governance.

Domain 5: Self Confidence

Self-confidence reflects the trust an individual has in their skills, capabilities and worth, embodying a sense of assurance and personal strength. The Foundation exam validates foundational competency and builds confidence for professionals advancing into Practitioner and Auditor roles.

Domain 6: Continuous Improvement Process

A continuous improvement process represents a consistent, structured effort aimed at refining products, services and processes to boost performance, efficiency and quality over time. ISO/IEC 27001 requires organizations to establish management review and internal audit processes that drive ongoing refinement of the ISMS.

Domain 7: Compliance

Compliance describes an organization's dedication to recognizing and following relevant laws, regulations and policies to maintain operations within lawful and ethical boundaries. Candidates must understand how the ISMS supports regulatory compliance and provides evidence of adherence to legal and contractual obligations.

Domain 8: Information Management

Information management covers the full process of handling information within an organization, including its acquisition, storage, distribution, use and eventual disposal or archiving. The ISO/IEC 27001 ISMS establishes controls across the entire information lifecycle to minimize risk and maintain compliance.

Domain 9: Risk Management

Risk management refers to the methodical approach of recognizing, assessing and mitigating risks to minimize their potential impact on achieving organizational objectives. The Foundation exam covers risk assessment, risk treatment and the risk management process that forms the core of ISO/IEC 27001.

FAQ

ISO-IEC-27001-Foundation Exam FAQ

Common questions about the exam itself

What prior experience or background do I need before sitting the ISO/IEC 27001 Foundation exam?
There are no formal prerequisites for the Foundation exam. However, background in information security, IT or service management is advantageous. The exam is designed for professionals new to ISO/IEC 27001 who want to understand how to establish or maintain an ISMS in their organization.
How long should I prepare for the ISO/IEC 27001 Foundation exam?
Most candidates prepare for 3 to 4 weeks if they have information security background, or 6 to 8 weeks if they are new to the field. A formal three-day accredited training course covering the ISMS framework, controls and organizational requirements accelerates understanding significantly.
What makes the Risk Management domain the hardest part of ISO/IEC 27001 Foundation?
Risk Management requires candidates to understand risk identification, analysis, evaluation and treatment processes that feed the entire ISMS. Many struggle with the difference between risk assessment and risk evaluation, and how asset valuation and threat analysis interact. Working through realistic scenarios and case studies helps clarify the relationships between these concepts.
How is the ISO/IEC 27001 Foundation exam structured and what happens on exam day?
The exam is 120 minutes long and contains 40 multiple-choice questions. You can take it online proctored or at an authorized test center. The exam is closed book for most formats, though some delivery options may allow restricted access to ISO standards. You will receive provisional results immediately after completion.
What is the passing score for the ISO/IEC 27001 Foundation exam?
APMG-International publishes a specific passing score threshold, but the exact percentage varies based on exam difficulty adjustments. Candidates typically need to answer approximately 60-65% of questions correctly to pass, though you should verify the current requirement with APMG-International directly.
How long is the ISO/IEC 27001 Foundation certification valid for and what renewal is required?
You should check the current validity period with APMG-International, as this information is not standardized across all APMG certifications. Some APMG credentials require renewal after three years through continuing professional development or reexamination, while others do not expire.
What job roles typically pursue the ISO/IEC 27001 Foundation certification?
The Foundation certification is pursued by IT security professionals, compliance officers, internal auditors, ISMS coordinators and anyone implementing or maintaining information security systems. It is often the starting point for professionals advancing to the ISO/IEC 27001 Practitioner or Auditor certifications.
How does the Foundation exam relate to the Practitioner and Auditor exams in the APMG ISO/IEC 27001 track?
The Foundation is the entry-level exam covering basic ISMS concepts, structure and requirements. The Practitioner exam builds on this and covers implementation and information security officer responsibilities. The Auditor exam focuses on auditing and assessing ISMS effectiveness. Foundation is a prerequisite for pursuing the Practitioner certification.
Can I retake the ISO/IEC 27001 Foundation exam if I fail, and how does rescheduling work?
Retakes are permitted and you can typically schedule another attempt immediately after failing. Specific retake policies and rescheduling windows depend on your exam delivery provider. Contact APMG-International or your training provider for their exact retake and rescheduling terms.
Is the ISO/IEC 27001 Foundation exam available in languages other than English?
The exam is offered in multiple languages to support global candidates, though the exact list of available languages varies by delivery method and region. Check with APMG-International or your authorized training provider to confirm which languages are available for your preferred exam delivery date and location.