
2026年最新のISO-IEC-27001-Foundation試験問題集で最近更新された72問題
APMG-International ISO-IEC-27001-Foundationリアル2026年最新のブレーン問題集で模擬試験問題集
APMG-International ISO-IEC-27001-Foundation 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|---|
| トピック 1 |
|
| トピック 2 |
|
| トピック 3 |
|
| トピック 4 |
|
| トピック 5 |
|
| トピック 6 |
|
| トピック 7 |
|
| トピック 8 |
|
質問 # 43
Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?
- A. Awareness
- B. Competence
- C. Nonconformity and corrective action
- D. Communication
正解:A
解説:
Clause 7.3 (Awareness) requires:
"Persons doing work under the organization's control shall be aware of: (a) the information security policy; (b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; (c) the implications of not conforming with the ISMS requirements." This applies not only to employees but also contractors and external parties under the organization's control.
Competence (B) requires having skills, training, and experience, while Communication (C) covers defining communication processes (Clause 7.4). Nonconformity and corrective action (A) is part of Clause 10 (Improvement).
Therefore, the specific requirement that ensures contractors are made aware of the information security policies is found in Clause 7.3 Awareness. Correct answer: D.
質問 # 44
What should an organization do after identifying a risk?
- A. Delete the affected asset
- B. Perform risk treatment
- C. Ignore it if it is unlikely
- D. Report it to customers immediately
正解:B
解説:
After assessing risks, the organization should determine appropriate treatment options, such as avoiding, reducing, sharing, or accepting the risk. Selected controls should reduce risk to an acceptable level aligned with business objectives.
質問 # 45
What is a requirement for a corrective action made in response to a nonconformity?
- A. They are proportionate to the likelihood of the nonconformity recurring
- B. They always eliminate the cause of the nonconformity
- C. They are appropriate to the effects of the nonconformity
- D. They do NOT change the organization's information security policies
正解:C
解説:
Clause 10.1 (Nonconformity and corrective action) specifies:
"The organization shall react to the nonconformity and, as applicable: take action to control and correct it; deal with the consequences; evaluate the need for action to eliminate the cause(s)...
Corrective actions shall be appropriate to the effects of the nonconformities encountered." This confirms optionB. Option A is inaccurate-ISO requires actions appropriate toeffects, not probability alone. Option C is false-policies may need updating to correct nonconformities. Option D is incorrect, as not every cause can always be eliminated; residual issues may exist.
Thus, the verified requirement isB.
質問 # 46
Identify the missing words in the following sentence.
The organization shall establish, implement, maintain and [ ? ] an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document.
- A. report on
- B. enforce standards for
- C. continually improve
- D. communicate the importance of
正解:C
解説:
Clause 4.4 of ISO/IEC 27001:2022 states:
"The organization shall establish, implement, maintain and continually improve an information security management system, including the processes needed and their interactions, in accordance with the requirements of this document."
質問 # 47
What is the primary purpose of an Information Security Management System (ISMS)?
- A. To comply only with legal requirements
- B. To eliminate all information security risks
- C. To prevent cyberattacks completely
- D. To protect information through a systematic risk management process
正解:D
解説:
An ISMS provides a structured framework for managing information security risks. ISO/IEC 27001 focuses on protecting confidentiality, integrity, and availability through continual improvement and risk-based decision-making, rather than eliminating all risks or guaranteeing complete protection.
質問 # 48
Which of the following is NOT one of the four Annex A control themes?
- A. Technological Controls
- B. Financial Controls
- C. Organizational Controls
- D. People Controls
正解:B
解説:
The four Annex A control themes are Organizational, People, Physical, and Technological Controls. Financial Controls are not part of Annex A, although financial considerations may influence information security risk management decisions.
質問 # 49
Which of the following best describes a security control?
- A. A weakness in an asset
- B. A legal requirement
- C. A type of cyberattack
- D. A measure that modifies risk
正解:D
解説:
A security control is any measure that modifies risk by preventing, detecting, correcting, or reducing the impact of security incidents. Controls may be administrative, physical, or technical, depending on the organization's needs.
質問 # 50
What is a vulnerability?
- A. A weakness that can be exploited by a threat
- B. An information asset
- C. A type of malware
- D. A security incident
正解:A
解説:
A vulnerability is a weakness in an asset, process, or security control that may be exploited by a threat. Examples include weak passwords, outdated software, or missing security patches, which increase the likelihood of successful attacks.
質問 # 51
What is the purpose of corrective action in ISO/IEC 27001?
- A. To punish employees
- B. To increase the number of controls
- C. To perform an external audit
- D. To eliminate the cause of a nonconformity and prevent recurrence
正解:D
解説:
Corrective action addresses the root cause of a nonconformity rather than its symptoms. By identifying causes and implementing appropriate actions, organizations reduce the likelihood of similar issues occurring again and support continual improvement of the ISMS.
質問 # 52
What is the name of the control clause used to control information security breaches within Annex A of ISO
/IEC 27001?
- A. Reporting information security incidents
- B. Response to information security events
- C. Information security event management
- D. Information security event reporting
正解:D
解説:
Comprehensive and Detailed Explanation From Exact Extract ISO/IEC 27002:2022 standards:
Annex A in ISO/IEC 27001 refers directly to ISO/IEC 27002 for control guidance. In ISO/IEC 27002:2022, Clause 6.8 is titled:
"Information security event reporting - Information security events should be reported through appropriate management channels as quickly as possible." This control ensures breaches, incidents, or suspected issues are reported for action. The other options (B, C, D) are not the exact titles in Annex A. The official title isInformation security event reporting, confirming
質問 # 53
What is a requirement for a corrective action made in response to a nonconformity?
- A. They are proportionate to the likelihood of the nonconformity recurring
- B. They always eliminate the cause of the nonconformity
- C. They are appropriate to the effects of the nonconformity
- D. They do NOT change the organization's information security policies
正解:C
解説:
Clause 10.1 (Nonconformity and corrective action) specifies:
"The organization shall react to the nonconformity and, as applicable: take action to control and correct it; deal with the consequences; evaluate the need for action to eliminate the cause(s)...
Corrective actions shall be appropriate to the effects of the nonconformities encountered."
質問 # 54
In which clause would the requirements for internal audit be found?
- A. Planning
- B. Performance Evaluation
- C. Improvement
- D. Operation
正解:B
解説:
The requirements for internal audit are explicitly placed inClause 9.2 (Performance Evaluation)of ISO/IEC
27001:2022. The standard requires:
* "The organization shall conduct internal audits at planned intervals to provide information on whether the information security management system... conforms to the organization's own requirements... and to the requirements of this document." (9.2.1)
* "The organization shall plan, establish, implement and maintain an audit programme(s)..." (9.2.2) This clause clearly falls underPerformance Evaluation (Clause 9), not Planning (Clause 6), Operation (Clause 8), or Improvement (Clause 10). Therefore, the correct answer isC.
質問 # 55
Which aspect of ISO/IEC 27001 requires that contractors know about the organization's information security policies?
- A. Awareness
- B. Competence
- C. Nonconformity and corrective action
- D. Communication
正解:A
解説:
Clause 7.3 (Awareness) requires:
"Persons doing work under the organization's control shall be aware of: (a) the information security policy; (b) their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance; (c) the implications of not conforming with the ISMS requirements."
質問 # 56
Which of the following is required to be considered when selecting appropriate information security risk treatment options?
- A. Criteria for accepting identified risks
- B. Criteria for performing risk assessments
- C. Only risk controls in Annex A of ISO/IEC 27001
- D. Only risk controls in ISO/IEC 27002
正解:A
解説:
Clause 6.1.3 (c) requires organizations to:
"compare the controls determined in 6.1.3 b) with those in Annex A and verify that no necessary control has been omitted; and prepare a Statement of Applicability." It also requires organizations to select risk treatment options considering "the organization's risk acceptance criteria." This shows thatrisk acceptance criteriaare a fundamental factor when selecting risk treatment options.
Options C and D are incorrect because Annex A and ISO/IEC 27002 are reference sets, not the sole sources of controls - organizations can design their own. Criteria for performing risk assessments (B) are part of 6.1.2 (risk assessment process), not risk treatment.
Thus, the correct requirement isA: Criteria for accepting identified risks.
質問 # 57
Which statement describes the Classification of information control in Annex A of ISO/IEC
27001?
- A. Ensures that security perimeters are used to protect assets
- B. Ensures the rules to control physical and logical access apply to assets
- C. Ensures that all information assets are labelled with their classification
- D. Ensures that information is classified based on confidentiality, integrity and availability
正解:D
解説:
Annex A.5.12 (Classification of information) states:
"Information should be classified according to the information security needs of the organization based on confidentiality, integrity and availability."
質問 # 58
......
厳密検証されたISO-IEC-27001-Foundation試験問題集と解答で無料提供のISO-IEC-27001-Foundation問題と正解付き:https://www.passtest.jp/APMG-International/ISO-IEC-27001-Foundation-shiken.html
ISO-IEC-27001-Foundation試験問題 リアルISO-IEC-27001-Foundation練習問題集:https://drive.google.com/open?id=1XHZqxYK3kqk9B1zvsrzrIYFUyi07u6Sg