Question 1
What best describes the purpose of an ISMS aligned with ISO/IEC 27001:2022?
Show answer & explanation
Correct answer: B - Managing information security risks through a continual improvement system
10 exam-style questions with answers and explanations, straight from our 1,030-question bank. Tap an answer to check yourself. When you're ready, take the scored version in the free practice test.
The C)ISMS exam has 100 questions and runs 2 hours.
These 10 free C)ISMS questions are organized by exam domain, so you can see how each part of the Certified Information Security Management Systems: Lead Auditor/Lead Implementer blueprint is tested. Reveal the answer and explanation under each question.
What best describes the purpose of an ISMS aligned with ISO/IEC 27001:2022?
Correct answer: B - Managing information security risks through a continual improvement system
Preventing unauthorized disclosure of customer information primarily protects:
Correct answer: A - Confidentiality
A risk team identifies a high-impact vulnerability. What should occur before selecting a treatment?
Correct answer: B - Evaluate the risk using established criteria
Which statement correctly distinguishes a threat from a vulnerability?
Correct answer: A - A vulnerability is a weakness that can be exploited; a threat is a potential cause of harm
Purchasing cyber insurance to reduce financial consequences of a breach is an example of:
Correct answer: A - Risk sharing
An auditor reviews a department where they recently designed the security controls. Which audit principle is most affected?
Correct answer: C - Independence
During an ISO/IEC 27001 audit, which evidence best demonstrates that an access-control control is operating effectively?
Correct answer: A - Sampled user permissions and completed access reviews
An auditor finds that a required security review was not performed. The best next action is to:
Correct answer: C - Evaluate evidence against audit criteria and record the finding if supported
Defining audit scope, criteria, resources, and schedule occurs during which audit phase?
Correct answer: B - Planning
An employee describes a process that differs from documentation. What should the auditor do first?
Correct answer: B - Collect and evaluate additional evidence
The C)ISMS exam also covers these domains. Drill them in the full free practice test:
The full bank has 1,020 more C)ISMS questions with explanations.
Continue in the free practice test →
View plans