ISO/IEC 27002:2022 - Information Security Controls Foundation Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

A multinational corporation, \"Aethelred Dynamics,\" has migrated a significant portion of its sensitive research and development data to a public cloud infrastructure. The organization\'s Chief Information Security Officer (CISO) is reviewing the contractual agreements and internal policies to ensure compliance with ISO/IEC 27002:2022 principles regarding cloud service usage. Considering the shared responsibility model inherent in cloud computing, what is the primary and non-delegable security obligation of Aethelred Dynamics as the customer organization in this scenario?

Ensuring the cloud service provider implements robust physical security measures for the data centers hosting their data.
Defining and enforcing the organization's specific security requirements for the cloud service, including access controls and data handling, and monitoring the provider's adherence to these requirements.
Relying solely on the cloud service provider's certifications and audits to validate the overall security posture of the cloud environment.
Assuming that all data processed and stored within the cloud environment is automatically protected by the provider's security framework without any further customer action.

About the ISO/IEC 27002:2022 - Information Security Controls Foundation Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27002:2022 - Information Security Controls Foundation exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.