CompTIA Security+ Exam Notes

CompTIA Security+ Exam Notes
Let Us Help You Pass

Friday, August 28, 2026

ISO 27001 Practice Questions and Answers for Security+ and CySA+ Exam Prep

 ISO 27001 Practice Questions 

Security+ and CySA+

QUESTION 1. 

What is the primary purpose of ISO/IEC 27001?

A. Define network architectures

B. Establish an Information Security Management System (ISMS)

C. Provide encryption algorithms

D. Replace all regulatory requirements


Answer: B

Explanation: ISO 27001 provides requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).


QUESTION 2. 

Which three principles form the foundation of information security?

A. CIA Triad

B. AAA Framework

C. Risk Matrix

D. Defense in Depth


Answer: A

Explanation: The CIA Triad consists of Confidentiality, Integrity, and Availability, which ISO 27001 is designed to protect.


QUESTION 3. 

What does ISMS stand for?

A. Information Security Monitoring Solution

B. Integrated Security Management Standard

C. Information Security Management System

D. Information Systems Management Service


Answer: C

Explanation: ISMS stands for Information Security Management System. It is the central focus of ISO 27001.


QUESTION 4. 

Which ISO 27001 clause focuses on executive responsibility and commitment?

A. Context of the Organization

B. Leadership

C. Support

D. Improvement


Answer: B

Explanation: Clause 5, Leadership, requires management commitment, policy development, and assignment of security responsibilities.


QUESTION 5. 

Which risk treatment option involves purchasing cyber insurance?

A. Mitigation

B. Acceptance

C. Avoidance

D. Transfer


Answer: D

Explanation: Risk transfer shifts some financial burden to another party, such as through insurance.


QUESTION 6. 

An organization decides not to conduct a risky business activity. Which risk treatment strategy is being used?

A. Mitigate

B. Accept

C. Avoid

D. Transfer


Answer: C

Explanation: Risk avoidance removes exposure entirely by discontinuing the activity.


QUESTION 7. 

Which document identifies which Annex A controls are implemented and why?

A. Risk Register

B. Audit Report

C. Incident Log

D. Statement of Applicability


Answer: D

Explanation: The Statement of Applicability (SoA) documents selected controls, exclusions, and justifications.


QUESTION 8. 

Which ISO 27001 component is considered the driving force behind control selection?

A. Physical Security

B. Risk Assessment

C. Incident Response

D. Data Classification


Answer: B

Explanation: ISO 27001 uses a risk-based approach. Controls are selected based on identified risks.


QUESTION 9. 

What is the purpose of Annex A?

A. List legal penalties

B. Define audit schedules

C. Provide a catalog of security controls

D. Define encryption standards


Answer: C

Explanation: Annex A contains reference security controls used in risk treatment activities.


QUESTION 10. 

Which category would security awareness training fall under?

A. Technological Controls

B. People Controls

C. Physical Controls

D. Organizational Controls


Answer: B

Explanation: Security awareness, training, and personnel-related safeguards are People Controls.


QUESTION 11. 

Which category includes surveillance cameras and badge readers?

A. Technological Controls

B. Organizational Controls

C. Physical Controls

D. Preventive Controls


Answer: C

Explanation: Physical controls protect facilities, equipment, and physical access points.


QUESTION 12. 

A company performs periodic reviews to verify that controls are operating effectively. Which clause best aligns with this activity?

A. Performance Evaluation

B. Support

C. Planning

D. Leadership


Answer: A

Explanation: Clause 9 focuses on monitoring, measurement, internal audits, and management reviews.


QUESTION 13. 

Which formula is commonly used during risk assessment?

A. Risk = Assets ÷ Controls

B. Risk = Vulnerability × Security

C. Risk = Likelihood × Impact

D. Risk = Asset × Availability


Answer: C

Explanation: Risk assessments commonly evaluate the likelihood of a threat occurring and the resulting impact.


QUESTION 14. 

Which control category would encryption most likely belong to?

A. Physical

B. Technological

C. People

D. Administrative


Answer: B

Explanation: Encryption is a technical safeguard and is classified as a technological control.


QUESTION 15. 

What is the primary objective of continuous improvement in ISO 27001?

A. Reduce staffing costs

B. Eliminate all risk

C. Improve security effectiveness over time

D. Remove compliance requirements


Answer: C

Explanation: Clause 10 requires organizations to improve their ISMS continually through corrective actions and lessons learned.


QUESTION 16. 

Which activity is most closely associated with CySA+ and ISO 27001?

A. Hardware repair

B. Risk-based vulnerability management

C. Software sales

D. Database design


Answer: B

Explanation: CySA+ emphasizes analyzing, prioritizing, and mitigating vulnerabilities based on risk, a principle central to ISO 27001.


QUESTION 17. 

Which of the following is an example of a threat?

A. Unpatched Operating System

B. Weak Password Policy

C. Phishing Campaign

D. Missing Security Awareness Training


Answer: C

Explanation: A threat is a potential cause of harm. Phishing attacks are common threat vectors. The others are vulnerabilities.


QUESTION 18. 

Which clause requires organizations to establish security objectives?

A. Planning

B. Support

C. Improvement

D. Context


Answer: A

Explanation: Clause 6 (Planning) requires organizations to establish information security objectives and plans to achieve them.


QUESTION 19. 

Which framework is specifically designed as an Information Security Management System standard?

A. PCI DSS

B. GDPR

C. ISO/IEC 27001

D. HIPAA


Answer: C

Explanation: ISO 27001 is the globally recognized ISMS standard based on risk management and continuous improvement.


QUESTION 20. 

During an audit, management asks for evidence that security controls were selected based on organizational risk. What document should be provided?

A. Security Awareness Policy

B. Firewall Rule Base

C. Statement of Applicability

D. Vulnerability Scan Report


Answer: C

Explanation: The Statement of Applicability demonstrates which controls were selected, implemented, excluded, and justified based on risk assessment results.


Exam Quick Review


Memorize these high-value exam facts:

ISO 27001 = Information Security Management System (ISMS)

CIA Triad = Confidentiality, Integrity, Availability

Annex A = Security Controls

SoA = Statement of Applicability

Risk Responses = Mitigate, Transfer, Accept, Avoid

Clause 5 = Leadership

Clause 6 = Planning

Clause 9 = Performance Evaluation

Clause 10 = Continuous Improvement

CySA+ Focus = Risk Analysis, Monitoring, Incident Response

Security+ Focus = Governance, Risk, Compliance, Controls


No comments:

Post a Comment