ISO 27001:2022 - Annex A Controls Implementation Professional Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A global e-commerce firm is migrating its customer database to a new Software-as-a-Service (SaaS) CRM platform. This platform will house personally identifiable information (PII) and transaction histories. To ensure compliance with data protection regulations like GDPR and to establish a robust information security posture, what is the most critical initial step within Annex A of ISO 27001:2022 for managing the security of this new, outsourced information asset?

Establishing a comprehensive inventory of all information assets, including the CRM software, data types, and underlying cloud infrastructure, and assigning clear ownership for each asset.
Implementing robust encryption mechanisms for all data at rest and in transit within the SaaS CRM platform.
Defining and enforcing strict access control policies for all users accessing the CRM system, based on the principle of least privilege.
Deploying continuous monitoring solutions to detect and respond to any suspicious activities or security breaches within the CRM environment.

About the ISO 27001:2022 - Annex A Controls Implementation Professional Certification

These free practice questions are designed to help you assess your readiness for the ISO 27001:2022 - Annex A Controls Implementation Professional exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.