2026年最新のISO-IEC-27001-Foundation試験問題集で最近更新された72問題 [Q43-Q58]

Share

2026年最新のISO-IEC-27001-Foundation試験問題集で最近更新された72問題

APMG-International ISO-IEC-27001-Foundationリアル2026年最新のブレーン問題集で模擬試験問題集


APMG-International ISO-IEC-27001-Foundation 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Self Confidence: Self-confidence is the belief in one’s abilities, competence, and value, reflecting a sense of assurance and inner strength.
トピック 2
  • Framework Design: Framework design is the process of developing a reusable structural foundation that supports and guides the creation and organization of software systems.
トピック 3
  • Compliance: Regulatory compliance refers to an organization’s commitment to understanding and adhering to applicable laws, policies, and regulations to operate within established legal and ethical standards.
トピック 4
  • Continuous Improvement Process (CI, CIP): A continuous or continual improvement process (CIP or CI) involves ongoing, systematic efforts to enhance products, services, or operational processes to achieve higher efficiency and effectiveness over time.
トピック 5
  • Security Breaches: Security breaches occur when unauthorized access or violations of security protocols are detected or imminent, potentially compromising data or system integrity.
トピック 6
  • Data Security: Data security refers to protecting digital information—such as that stored in databases or networks—from destruction, unauthorized access, or malicious attacks, ensuring confidentiality and integrity.
トピック 7
  • Information Management (IM): Information management (IM) encompasses the entire lifecycle of information within an organization—from its collection and storage to its distribution, use, and eventual archiving or disposal.
トピック 8
  • Cybersecurity: Cybersecurity, also known as IT security or computer security, involves safeguarding computer systems, networks, and data from unauthorized access, theft, damage, or disruption to ensure the integrity and availability of digital information.

 

質問 # 43
Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?

  • A. Awareness
  • B. Competence
  • C. Nonconformity and corrective action
  • D. Communication

正解:A

解説:
Clause 7.3 (Awareness) requires:
"Persons doing work under the organization's control shall be aware of: (a) the information security policy; (b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; (c) the implications of not conforming with the ISMS requirements." This applies not only to employees but also contractors and external parties under the organization's control.
Competence (B) requires having skills, training, and experience, while Communication (C) covers defining communication processes (Clause 7.4). Nonconformity and corrective action (A) is part of Clause 10 (Improvement).
Therefore, the specific requirement that ensures contractors are made aware of the information security policies is found in Clause 7.3 Awareness. Correct answer: D.


質問 # 44
What should an organization do after identifying a risk?

  • A. Delete the affected asset
  • B. Perform risk treatment
  • C. Ignore it if it is unlikely
  • D. Report it to customers immediately

正解:B

解説:
After assessing risks, the organization should determine appropriate treatment options, such as avoiding, reducing, sharing, or accepting the risk. Selected controls should reduce risk to an acceptable level aligned with business objectives.


質問 # 45
What is a requirement for a corrective action made in response to a nonconformity?

  • A. They are proportionate to the likelihood of the nonconformity recurring
  • B. They always eliminate the cause of the nonconformity
  • C. They are appropriate to the effects of the nonconformity
  • D. They do NOT change the organization's information security policies

正解:C

解説:
Clause 10.1 (Nonconformity and corrective action) specifies:
"The organization shall react to the nonconformity and, as applicable: take action to control and correct it; deal with the consequences; evaluate the need for action to eliminate the cause(s)...
Corrective actions shall be appropriate to the effects of the nonconformities encountered." This confirms optionB. Option A is inaccurate-ISO requires actions appropriate toeffects, not probability alone. Option C is false-policies may need updating to correct nonconformities. Option D is incorrect, as not every cause can always be eliminated; residual issues may exist.
Thus, the verified requirement isB.


質問 # 46
Identify the missing words in the following sentence.
The organization shall establish, implement, maintain and [ ? ] an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.

  • A. report on
  • B. enforce standards for
  • C. continually improve
  • D. communicate the importance of

正解:C

解説:
Clause 4.4 of ISO/IEC 27001:2022 states:
"The organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document."


質問 # 47
What is the primary purpose of an Information Security Management System (ISMS)?

  • A. To comply only with legal requirements
  • B. To eliminate all information security risks
  • C. To prevent cyberattacks completely
  • D. To protect information through a systematic risk management process

正解:D

解説:
An ISMS provides a structured framework for managing information security risks. ISO/IEC 27001 focuses on protecting confidentiality, integrity, and availability through continual improvement and risk-based decision-making, rather than eliminating all risks or guaranteeing complete protection.


質問 # 48
Which of the following is NOT one of the four Annex A control themes?

  • A. Technological Controls
  • B. Financial Controls
  • C. Organizational Controls
  • D. People Controls

正解:B

解説:
The four Annex A control themes are Organizational, People, Physical, and Technological Controls. Financial Controls are not part of Annex A, although financial considerations may influence information security risk management decisions.


質問 # 49
Which of the following best describes a security control?

  • A. A weakness in an asset
  • B. A legal requirement
  • C. A type of cyberattack
  • D. A measure that modifies risk

正解:D

解説:
A security control is any measure that modifies risk by preventing, detecting, correcting, or reducing the impact of security incidents. Controls may be administrative, physical, or technical, depending on the organization's needs.


質問 # 50
What is a vulnerability?

  • A. A weakness that can be exploited by a threat
  • B. An information asset
  • C. A type of malware
  • D. A security incident

正解:A

解説:
A vulnerability is a weakness in an asset, process, or security control that may be exploited by a threat. Examples include weak passwords, outdated software, or missing security patches, which increase the likelihood of successful attacks.


質問 # 51
What is the purpose of corrective action in ISO/IEC 27001?

  • A. To punish employees
  • B. To increase the number of controls
  • C. To perform an external audit
  • D. To eliminate the cause of a nonconformity and prevent recurrence

正解:D

解説:
Corrective action addresses the root cause of a nonconformity rather than its symptoms. By identifying causes and implementing appropriate actions, organizations reduce the likelihood of similar issues occurring again and support continual improvement of the ISMS.


質問 # 52
What is the name of the control clause used to control information security breaches within Annex A of ISO
/IEC 27001?

  • A. Reporting information security incidents
  • B. Response to information security events
  • C. Information security event management
  • D. Information security event reporting

正解:D

解説:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A in ISO/IEC 27001 refers directly to ISO/IEC 27002 for control guidance. In ISO/IEC 27002:2022, Clause 6.8 is titled:
"Information security event reporting - Information security events should be reported through appropriate management channels as quickly as possible." This control ensures breaches, incidents, or suspected issues are reported for action. The other options (B, C, D) are not the exact titles in Annex A. The official title isInformation security event reporting, confirming


質問 # 53
What is a requirement for a corrective action made in response to a nonconformity?

  • A. They are proportionate to the likelihood of the nonconformity recurring
  • B. They always eliminate the cause of the nonconformity
  • C. They are appropriate to the effects of the nonconformity
  • D. They do NOT change the organization's information security policies

正解:C

解説:
Clause 10.1 (Nonconformity and corrective action) specifies:
"The organization shall react to the nonconformity and, as applicable: take action to control and correct it; deal with the consequences; evaluate the need for action to eliminate the cause(s)...
Corrective actions shall be appropriate to the effects of the nonconformities encountered."


質問 # 54
In which clause would the requirements for internal audit be found?

  • A. Planning
  • B. Performance Evaluation
  • C. Improvement
  • D. Operation

正解:B

解説:
The requirements for internal audit are explicitly placed inClause 9.2 (Performance Evaluation)of ISO/IEC
27001:2022. The standard requires:
* "The organization shall conduct internal audits at planned intervals to provide information on whether the information security management system... conforms to the organization's own requirements... and to the requirements of this document." (9.2.1)
* "The organization shall plan, establish, implement and maintain an audit programme(s)..." (9.2.2) This clause clearly falls underPerformance Evaluation (Clause 9), not Planning (Clause 6), Operation (Clause 8), or Improvement (Clause 10). Therefore, the correct answer isC.


質問 # 55
Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?

  • A. Awareness
  • B. Competence
  • C. Nonconformity and corrective action
  • D. Communication

正解:A

解説:
Clause 7.3 (Awareness) requires:
"Persons doing work under the organization's control shall be aware of: (a) the information security policy; (b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; (c) the implications of not conforming with the ISMS requirements."


質問 # 56
Which of the following is required to be considered when selecting appropriate information security risk treatment options?

  • A. Criteria for accepting identified risks
  • B. Criteria for performing risk assessments
  • C. Only risk controls in Annex A of ISO/IEC 27001
  • D. Only risk controls in ISO/IEC 27002

正解:A

解説:
Clause 6.1.3 (c) requires organizations to:
"compare the controls determined in 6.1.3 b) with those in Annex A and verify that no necessary control has been omitted; and prepare a Statement of Applicability." It also requires organizations to select risk treatment options considering "the organization's risk acceptance criteria." This shows thatrisk acceptance criteriaare a fundamental factor when selecting risk treatment options.
Options C and D are incorrect because Annex A and ISO/IEC 27002 are reference sets, not the sole sources of controls - organizations can design their own. Criteria for performing risk assessments (B) are part of 6.1.2 (risk assessment process), not risk treatment.
Thus, the correct requirement isA: Criteria for accepting identified risks.


質問 # 57
Which statement describes the Classification of information control in Annex A of ISO/IEC
27001?

  • A. Ensures that security perimeters are used to protect assets
  • B. Ensures the rules to control physical and logical access apply to assets
  • C. Ensures that all information assets are labelled with their classification
  • D. Ensures that information is classified based on confidentiality, integrity and availability

正解:D

解説:
Annex A.5.12 (Classification of information) states:
"Information should be classified according to the information security needs of the organization based on confidentiality, integrity and availability."


質問 # 58
......

厳密検証されたISO-IEC-27001-Foundation試験問題集と解答で無料提供のISO-IEC-27001-Foundation問題と正解付き:https://www.passtest.jp/APMG-International/ISO-IEC-27001-Foundation-shiken.html

ISO-IEC-27001-Foundation試験問題 リアルISO-IEC-27001-Foundation練習問題集:https://drive.google.com/open?id=1XHZqxYK3kqk9B1zvsrzrIYFUyi07u6Sg