Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?
A. Competence
B. Nonconformity and corrective action
C. Communication
D. Awareness
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Which item is required to be included in an information security policy?
A. A Statement of Applicability which defines the necessary controls to be implemented
B. A plan for the continual improvement of the information security management system
C. A commitment to satisfy applicable requirements related to information security
D. A framework enabling concerns with the information security policy to be addressed
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 3:
Which item is required to be defined when planning the organization's risk assessment process?
A. How the effectiveness of the method will be measured
B. The criteria for acceptable levels of risk
C. The parts of the ISMS scope which are excluded from the risk assessment
D. There are NO specific information requirements
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Identify the missing word in the following sentence.
According to ISO/IEC 27000, the definition of risk [?] is a "process to comprehend the nature of risk and to determine the level of risk."
A. Analysis
B. Assessment
C. Evaluation
D. Management
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
Which International Standard can be used to implement an integrated management system with ISO/IEC 27001?
A. ISO/IEC 27003
B. ISO 9001
C. None of the above
D. ISO/IEC 27013
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
When are the information security policies required to be reviewed, according to the Policies for information security control?
A. According to a schedule defined by the Certification Body
B. Annually
C. At planned intervals and if significant changes occur
D. Every six months
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
In an audit, what is the definition of an observation?
A. An issue excluded from the scope of the standard
B. A non-fulfilment of a requirement of ISO/IEC 27001
C. A conformity to the standard where there is an opportunity for improvement
D. An issue raised by an interested party
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
What is the purpose of corrective action in ISO/IEC 27001?
A. To punish employees
B. To eliminate the cause of a nonconformity and prevent recurrence
C. To perform an external audit
D. To increase the number of controls
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
779 お客様のコメント





青木** -
ISO-IEC-27001-Foundationの内容は問題数も増えた感じで内容も充実しているし、早速勉強していきたいと思います!