ISO 27002:2022 - Information Security Controls Auditor Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

During an audit of a financial services firm\'s information security program, an auditor discovers a critical, unpatched flaw within a proprietary trading platform\'s authentication module. This vulnerability, which allows for privilege escalation, was identified through an internal penetration test conducted after the platform\'s initial deployment. The organization\'s incident response plan has procedures for handling detected vulnerabilities, but the audit team is specifically examining the controls in place to *prevent* such flaws from being introduced during the software development lifecycle. Which ISO 27002:2022 control would be most directly applicable for assessing the organization\'s proactive measures against this type of vulnerability?

8.28 Secure coding
5.24 Information security incident management
8.16 Monitoring activities
8.23 Use of cryptography

About the ISO 27002:2022 - Information Security Controls Auditor Certification

These free practice questions are designed to help you assess your readiness for the ISO 27002:2022 - Information Security Controls Auditor exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.