DOWNLOAD the newest PrepAwayPDF ISO-IEC-27002-Foundation PDF dumps from Cloud Storage for free: https://drive.google.com/open?id=1o3piOgxsqz9aiX8cp9MvnlsOR-BT8cSp
Our company always lays great emphasis on offering customers more wide range of choice on ISO-IEC-27002-Foundation exam questions. Now, we have realized our promise. Our website will provide you with ISO-IEC-27002-Foundation study materials that almost cover all kinds of official test and popular certificate. So you will be able to find what you need easily on our website for ISO-IEC-27002-Foundation training guide. Every ISO-IEC-27002-Foundation study material of our website is professional and accurate, which can greatly relieve your learning pressure and help you get the dreaming ISO-IEC-27002-Foundation certification.
| Certification Vendor: | PECB |
|---|---|
| Exam Name: | ISO/IEC 27002 Foundation Exam |
| Exam Number: | ISO-IEC-27002-Foundation |
| Exam Price: | $150 USD (included in training fee) |
| Certificate Validity Period: | Lifetime |
| Passing Score: | 28/40 (70%) |
| Exam Format: | Multiple Choice, Online / Paper-based |
| Available Languages: | Czech, Spanish, German, French, English |
| Exam Duration: | 60 minutes |
| Real Exam Qty: | 40 |
| Related Certifications: | ISO/IEC 27005 Foundation ISO/IEC 27001 Foundation |
| Recommended Training: | PECB ISO/IEC 27002 Foundation Training Course |
| Exam Registration: | PECB Official Registration |
| Sample Questions: | PECB ISO-IEC-27002-Foundation Sample Questions |
| Exam Way: | Online proctored or onsite paper-based |
| Pre Condition: | No formal prerequisites; basic knowledge of information security is recommended |
| Official Syllabus URL: | https://pecb.com/en/education-and-certification-for-individuals/iso-iec-27002/iso-iec-27002-foundation |
>> New ISO-IEC-27002-Foundation Exam Papers <<
You only need 20-30 hours to learn ISO/IEC 27002 Foundation Exam exam torrent and prepare the exam. Many people, especially the in-service staff, are busy in their jobs, learning, family lives and other important things and have little time and energy to learn and prepare the exam. But if you buy our ISO-IEC-27002-Foundation Test Torrent, you can invest your main energy on your most important thing and spare 1-2 hours each day to learn and prepare the exam. Our questions and answers are based on the real exam and conform to the popular trend in the industry.
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
NEW QUESTION # 16
Which statement below describes the principle of confidentiality?
Answer: B
Explanation:
Confidentiality means that information is protected from unauthorized disclosure or availability. The correct statement is option A because it expresses the essential confidentiality concept: information must not be made available or disclosed to unauthorized individuals, entities, or processes. ISO/IEC 27002 supports confidentiality through controls such as information classification, labelling, access control, identity management, authentication, cryptography, data masking, information transfer rules, and data leakage prevention. The purpose is to ensure that only approved users, systems, or processes can view or receive information according to business need and authorization. Option B describes integrity, because accuracy and completeness relate to whether information remains correct and unaltered. Option C describes availability, because accessibility and usability on demand relate to authorized access when needed. In ISO/IEC 27002, many controls are mapped to confidentiality, integrity, and availability through control attributes. A confidentiality breach can occur through excessive internal access, accidental disclosure, lost media, weak access permissions, exposed credentials, or insecure transfer. References/Chapters: ISO/IEC 27002:2022, Clause 4 control attributes; Control 5.12 Classification of information; Control 5.15 Access control; Control
8.24 Use of cryptography.
NEW QUESTION # 17
Which control requires the use of cryptography to protect the confidentiality, authenticity, or integrity of information?
Answer: B
Explanation:
Control 8.24 covers rules for the effective use of cryptography, including key management, to protect information appropriately.
NEW QUESTION # 18
During which phase of the Plan-Do-Check-Act cycle do organizations maintain and improve the information security management system?
Answer: B
Explanation:
The "Act" phase is the phase in which an organization maintains and improves the information security management system. In the PDCA logic, "Plan" establishes objectives, policies, processes, risk treatment plans, and controls. "Do" implements and operates the planned processes and controls. "Check" monitors, measures, audits, and reviews performance. "Act" uses the results of checking to correct weaknesses, improve effectiveness, and adapt the ISMS to changing conditions. ISO/IEC 27002 is not itself the PDCA requirements standard, but its controls support the management system lifecycle used by ISO/IEC 27001.
Examples include independent review of information security, compliance review, learning from incidents, management of vulnerabilities, and change management. These controls generate findings and lessons that feed improvement actions. "Do" is not the best answer because it focuses on implementation. "Check" is not the best answer because it evaluates performance but does not itself complete improvement. The phase that maintains and improves the ISMS is "Act." References/Chapters: ISO/IEC 27002:2022, Control 5.35 Independent review of information security; Control 5.27 Learning from information security incidents; ISO
/IEC 27001 PDCA-based management system model.
NEW QUESTION # 19
An organization does NOT authenticate the identity of persons that enter the server room, so unauthorized persons can easily gain access to the server. Which control of ISO/IEC 27002 should the organization implement to solve this problem?
Answer: A
Explanation:
This control requires secure entry procedures, including identity authentication, to ensure only authorized persons can access restricted areas such as server rooms.
NEW QUESTION # 20
An organization does NOT authenticate the identity of persons that enter the server room, so unauthorized persons can easily gain access to the server. Which control of ISO/IEC 27002 should the organization implement to solve this problem?
Answer: A
Explanation:
Control 7.2, Physical entry, is the correct control because the problem is unauthorized physical access to a server room. ISO/IEC 27002 expects secure areas to be protected by appropriate entry controls so that only authorized persons can enter. Authentication of identity at entry points may include badges, access cards, biometric verification, PINs, visitor registration, security guards, turnstiles, logs, escorts, or electronic access systems. The server room contains information processing facilities, and unauthorized physical access could lead to theft, tampering, cable disconnection, hardware compromise, installation of rogue devices, or direct access to consoles and storage media. Control 8.6, Capacity management, concerns resource capacity for information processing facilities, not physical access. Control 8.4, Access to source code, concerns protecting program source code from unauthorized access, not entry into a secure physical room. Because the scenario specifically says people can enter the server room without identity authentication, the matching ISO/IEC
27002 physical control is Control 7.2. References/Chapters: ISO/IEC 27002:2022, Control 7.2 Physical entry; Control 7.1 Physical security perimeter; Control 7.4 Physical security monitoring.
NEW QUESTION # 21
......
ISO-IEC-27002-Foundation Practice Exam Fee: https://www.prepawaypdf.com/PECB/ISO-IEC-27002-Foundation-practice-exam-dumps.html
BTW, DOWNLOAD part of PrepAwayPDF ISO-IEC-27002-Foundation dumps from Cloud Storage: https://drive.google.com/open?id=1o3piOgxsqz9aiX8cp9MvnlsOR-BT8cSp