ISO/IEC 27002:2022 - Information Security Controls Lead Implementer Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

An enterprise is migrating its customer relationship management (CRM) operations to a Software as a Service (SaaS) cloud platform. The CRM system will house sensitive customer Personally Identifiable Information (PII) and proprietary sales data. The organization needs to ensure robust information security for this critical data, considering the shared responsibility model inherent in cloud computing and the potential impact of regulations like GDPR. Which of the following actions would be the most effective initial step in establishing a secure cloud CRM environment?

Conduct thorough due diligence on prospective cloud service providers, scrutinizing their security certifications, audit reports, and contractual terms regarding data protection, access controls, and incident management.
Mandate comprehensive annual security awareness training for all employees who will access the cloud CRM, focusing on phishing and password hygiene.
Implement a policy requiring the anonymization of all customer PII before it is uploaded to the cloud CRM system.
Develop and test a detailed business continuity and disaster recovery plan specifically for the organization's on-premises IT infrastructure.

About the ISO/IEC 27002:2022 - Information Security Controls Lead Implementer Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27002:2022 - Information Security Controls Lead Implementer exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.