Which control of ISO/IEC 27002 aims to ensure the correct and secure operation of information processing facilities?
Answer : B
Control 5.37, Documented operating procedures, aims to ensure the correct and secure operation of information processing facilities. Operating procedures translate security and operational requirements into repeatable instructions for administrators, operators, support teams, and users. They can cover system startup and shutdown, backup, restoration, logging, error handling, media handling, job scheduling, maintenance, incident escalation, access administration, and secure processing steps. Without documented procedures, operations become inconsistent and dependent on individual memory or informal practice, increasing the likelihood of mistakes, outages, unauthorized changes, or insecure handling. Control 7.2, Physical entry, protects secure physical areas by controlling access to facilities, but it does not define operational procedures. Control 5.35, Independent review of information security, assesses whether the information security approach remains suitable, adequate, and effective, but it does not provide the day-to-day operating instructions. ISO/IEC 27002 places documented procedures in the organizational control group because reliable operation requires governance, clarity, and repeatability. Therefore, option B is the verified answer. Reference/Chapters: ISO/IEC 27002:2022, Control 5.37 Documented operating procedures; Control 7.2 Physical entry; Control 5.35 Independent review of information security.
An organization has set up a fire alarm. What type of control is this?
Answer : B
A fire alarm is a detective and technical control. It is detective because it identifies or signals that a fire-related event may be occurring. The alarm does not normally stop the fire from starting, and it does not restore damaged assets after the event. Its purpose is to detect indicators such as smoke, heat, or fire and trigger response actions such as evacuation, suppression, emergency communication, or incident handling. It is technical because it operates through engineered or electronic mechanisms rather than through management approval, legal clauses, or purely administrative processes. ISO/IEC 27002:2022 classifies controls using attributes, including control type. Control types include preventive, detective, and corrective. Fire alarms align with the physical security control area because fire is a physical and environmental threat to information processing facilities, equipment, storage media, and supporting infrastructure. The value of the control is timely detection, reducing the chance that a physical event escalates unnoticed into major damage or service disruption. Reference/Chapters: ISO/IEC 27002:2022, Clause 4 control attributes; Control 7.4 Physical security monitoring; Control 7.5 Protecting against physical and environmental threats.
Company A has configured its employees' browsers to block the IP address of malicious websites. Which information security control has been implemented by Company A?
Answer : B
Company A has implemented Control 8.23, Web filtering. Web filtering is intended to protect systems from compromise by preventing access to known malicious or inappropriate web resources. Blocking IP addresses or domains associated with malicious websites is a typical web filtering technique. It can reduce exposure to malware, phishing pages, command-and-control infrastructure, drive-by downloads, credential harvesting, and unauthorized content. Control 8.11, Data masking, is unrelated because it protects sensitive data by obscuring or substituting values so users or systems do not see the original data. Control 5.18, Access rights, concerns granting, reviewing, modifying, and removing user access privileges to information and systems. Browser configuration that blocks malicious destinations is not primarily user access rights management; it is filtering web traffic based on destination risk. ISO/IEC 27002 places web filtering under technological controls because it is implemented through browsers, gateways, DNS filtering, proxies, endpoint tools, or secure web gateways. Therefore, option B is verified. Reference/Chapters: ISO/IEC 27002:2022, Control 8.23 Web filtering; Control 8.7 Protection against malware; Control 8.20 Network security.
ISO/IEC 27002:2022 provides guidance for selecting, implementing, and managing information security controls. It is not the certification requirements standard; that role belongs to ISO/IEC 27001. ISO/IEC 27002 supports organizations by explaining the purpose of each control, the implementation guidance, and other related information needed to apply controls appropriately. Its controls are grouped into organizational, people, physical, and technological themes. The standard is intended to be used as a reference when organizations design security measures based on their risks, business needs, legal obligations, contractual requirements, and information security objectives. Therefore, option A is correct because ''guidance'' is the core function of ISO/IEC 27002. Option B is incorrect because ISO/IEC 27002 does not set mandatory requirements for certification. Option C is related to risk management, but it is not the main purpose of ISO/IEC 27002; risk management guidance is more directly associated with ISO/IEC 27005. ISO/IEC 27002 guides control implementation after risk and control needs are determined. Reference/Chapters: ISO/IEC 27002:2022, Clause 1 Scope; Clause 4 Structure of the standard; Controls 5--8.
According to Control 5.27 Learning from information security incidents, how can organizations use the information gained from the evaluation of information security incidents?
Answer : B
Information gained from evaluating information security incidents should be used to improve both user awareness and training and the incident management plan. Control 5.27 focuses on learning from incidents so that organizations reduce the likelihood or impact of recurrence. Incident evaluation can reveal root causes, control failures, user mistakes, unclear procedures, delayed escalation, insufficient logging, poor communication, supplier weaknesses, or technical vulnerabilities. If users contributed to the incident through phishing response, mishandling of information, weak passwords, or reporting delays, awareness and training should be improved. If the incident response process showed weaknesses in roles, escalation, evidence collection, communication, containment, recovery, or decision-making, the incident management plan should be updated. ISO/IEC 27002 treats incidents as a feedback mechanism for continual improvement, not merely isolated events to close. Option B is correct because both listed uses are valid and mutually reinforcing. Strong incident learning improves controls, procedures, monitoring, user behavior, and readiness for future events. Reference/Chapters: ISO/IEC 27002:2022, Control 5.27 Learning from information security incidents; Control 5.24 Information security incident management planning and preparation; Control 6.3 Information security awareness, education and training.
Unlock All Features of PECB ISO-IEC-27002-Foundation Dumps Software
Just have a look at the best and updated features of our ISO-IEC-27002-Foundation dumps which are described in detail in the following tabs. We are very confident that you will get the best deal on this platform.
Select Question Types you want
Set your desired pass percentage
Allocate Time (Hours: Minutes)
Create Multiple Practice test with limited questions
Customer Support
Latest Success Metrics For actual ISO-IEC-27002-Foundation Exam
This is the best time to verify your skills and accelerate your career. Check out last week's results, more than 90% of students passed their exam with good scores. You may be the Next successful Candidate.
I wish to express thank PremiumDumps very much for being here. I passed PECB ISO-IEC-27002-Foundation test with a good score!
Lily Anne
June 21, 2026
My colleague suggested me to attempt PECB ISO-IEC-27002-Foundation exam and prepare it with premiumdumps. I feel lucky, I attempted exam only with experts made practice questions
Leon Müller
June 19, 2026
I wish to share enthusiastically that I have finally advanced the credentials. And this has become possible just because of the Premiumdumps exam preparation material.
Jhonson
June 17, 2026
Premiumdumps is providing a very reliable support to all of the customers and so to me! I am very much obliged! I got 85% marks in my Certification test and this happened just because of Premiumdumps.
James Henry
June 15, 2026
Premiumdumps made me self-confident and assured with success. Its real exam simulation and self assessment tools helped me to pass ISO-IEC-27002-Foundation exam with good grades.
Ava Grace
June 14, 2026
When I got enrolled in PECB ISO-IEC-27002-Foundation, I was told that Premiumdumps is the only key to all of my worries regarding my Exam. I scored well and it justifies the standard of Premiumdumps
Mia Elizabeth
June 12, 2026
I passed the PECB ISO-IEC-27002-Foundation exam with the help of Premiumdumps. I am glad to chose the right material to become successful in my career.