ISO-IEC-27001-LEAD-AUDITOR Exam Questions
365 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 1 of 8.
- Question #1Asset Management
What is the difference between a restricted and confidential document?
information classificationdata classificationrestrictedconfidential - Question #2Asset Management
CEO sends a mail giving his views on the status of the company and the company's future strategy and the CEO's vision and the employee's part in it. The mail should be classified a...
information classificationemail classificationinternal communication - Question #3Asset Management
You see a blue color sticker on certain physical assets. What does this signify?
asset classificationasset labelingphysical assetscriticality - Question #4Information Security Concepts
Integrity of data means
integrityCIA triaddata integrity - Question #5Asset Management
You have a hard copy of a customer design document that you want to dispose off. What would you do?
secure disposalmedia handlinghard copydata classification - Question #6Information Security Incident Management
You receive the following mail from the IT support team: Dear User,Starting next week, we will be deleting all inactive email accounts in order to create spaceshare the below detai...
phishingsocial engineeringincident reportingsecurity awareness - Question #7Information Security Concepts
The following are definitions of Information, except:
information definitiondata concepts - Question #8Information Security Incident Management
In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:
incident managementroles and responsibilitiesincident response - Question #9Information Security Management System
What is the standard definition of ISMS?
ISMS definitionISO 27001ISMS - Question #10Asset Management
Information or data that are classified as ______ do not require labeling.
information classificationlabelingpublic information - Question #11Information Security Concepts
A property of Information that has the ability to prove occurrence of a claimed event.
non-repudiationintegritysecurity propertiesCIA triad - Question #12Asset Management
Stages of Information
information lifecycledata lifecycleinformation stages - Question #13Physical and Environmental Security
A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:
physical securityvisitor managementaccess control - Question #14Information Security Incident Management
Which of the following is not a type of Information Security attack?
attack typesinformation security incidentsthreat classification - Question #15Information Security Management System
The following are purposes of Information Security, except:
information security objectivesbusiness continuityrisk management - Question #16Access Control
The following are the guidelines to protect your password, except:
password managementaccess controlauthenticationpassword policy - Question #17Information Security Incident Management
Phishing is what type of Information Security Incident?
phishingsocial engineeringincident classificationhacker attacks - Question #18Information Security Management System
Information Security is a matter of building and maintaining ________ .
information security fundamentalstrustsecurity culture - Question #19Access Control
All are prohibited in acceptable use of information assets, except:
acceptable use policyemail usageinformation assets - Question #20Access Control
In acceptable use of Information Assets, which is the best practice?
acceptable use policyinformation assetsbusiness purposeaccess control - Question #21Information Security Management Concepts
CMM stands for?
CMMCapability Maturity Modelprocess maturityinformation security frameworks - Question #22Human Resource Security
Which is not a requirement of HR prior to hiring?
HR securitypre-employment requirementsbackground verificationinformation security controls - Question #23Access Control
Who are allowed to access highly confidential files?
access controlneed-to-know principleconfidential informationNDA - Question #24Information Security Concepts
Which is the glue that ties the triad together
CIA triadinformation security fundamentalstechnologypeople-process-technology - Question #25Information Security Management System (ISMS)
Implement plan on a test basis - this comes under which section of PDCA
PDCA cycleDo phaseISMS implementationISO 27001 framework - Question #26Information Security Management System (ISMS)
What is we do in ACT - From PDCA cycle
PDCA cycleAct phasecontinual improvementprocess performance - Question #27Information Security Concepts
-------------------------is an asset like other important business assets has value to an organization and consequently needs to be protected.
information assetasset managementinformation security fundamentals - Question #28Information Security Concepts
Below is Purpose of "Integrity", which is one of the Basic Components of Information Security
CIA triadintegrityinformation security principlesasset protection - Question #29Audit Planning and Preparation
Which one of the following options best describes the main purpose of a Stage 1 third-party audit?
Stage 1 auditthird-party certification auditaudit readinessaudit programme - Question #30Audit Roles and Responsibilities
Which two of the following statements are true?
certification body auditauditor responsibilitiesthird-party auditaudit evaluation - Question #33Internal Audit Management
Which two activities align with the "Check'' stage of the Plan-Do-Check-Act cycle when applied to the process of managing an internal audit program as described in ISO 19011?
PDCA cycleCheck phaseinternal audit programmeISO 19011 - Question #34Audit Roles and Responsibilities
Drag and Drop Question Please match the roles to the following descriptions: To complete the table click on the blank section you want to complete so that it is highlighted in red,...
audit rolesauditor responsibilitiesISO 19011 - Question #35Audit Conduct
Which two of the following are examples of audit methods that 'do' involve human interaction?
audit methodshuman interactionaudit techniquesremote audit - Question #36Audit Principles and Ethics
In the context of a third-party certification audit, confidentiality is an issue in an audit programme. Select two options which correctly state the function of confidentiality in...
audit confidentialityaudit principlesthird-party auditaudit ethics - Question #37Information Security Management System (ISMS)
Drag and Drop Question Select the words that best complete the sentence: To complete the sentence with the best word(s), click on the blank section you want to complete so that it...
ISO 27001 conceptsISMS terminology - Question #38Audit Planning and Preparation
Which three of the following phrases are objectives' in relation to an audit?
audit objectivesaudit scopeaudit criteriaaudit planning - Question #39Audit Programme Management
Which six of the following actions are the individual(s) managing the audit programme responsible for?
audit programme managementauditor responsibilitiesaudit planningISO 19011 - Question #40Audit Planning and Preparation
Which three of the following work documents are not required for audit planning by an auditor conducting a certification audit?
audit planningaudit documentationcertification auditaudit work documents - Question #41Audit Planning and Preparation
Which three of the following options are an advantage of using a sampling plan for the audit?
audit samplingsampling planaudit methodologyaudit confidence - Question #42Managing an ISO/IEC 27001 Audit Programme
After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include...
audit scope extensionStage 1 auditcertification body notificationaudit team leader - Question #44Managing an ISO/IEC 27001 Audit Programme
During discussions with the individual(s) managing the audit programme of a certification body, the Management System Representative of the client organisation asks for a specific...
auditor independenceauditor selectionaudit programme managementcertification body - Question #45Conducting an ISO/IEC 27001 Audit
During an opening meeting of a Stage 2 audit, the Managing Director of the client organisation invites the audit team to view a new company video lasting 45 minutes. Which two of t...
opening meetingaudit schedule managementaudit team leaderauditee relations - Question #46ISO/IEC 27001 Requirements
Drag and Drop Question You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they under...
PDCA cycleCheck stageISMS operationperformance evaluation - Question #47ISO/IEC 27001 Requirements
You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before...
Clause 8.1 operational planningdocumented informationwork instructionsISMS nonconformity - Question #48ISO/IEC 27001 Requirements
During a third-party certification audit you are presented with a list of issues by an auditee. Which four of the following constitute 'external' issues in the context of a managem...
external issuesClause 4.1 contextorganizational contextISO 27001:2022 - Question #49Conducting an ISO/IEC 27001 Audit
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementISO/IEC 27035audit evidence collectionransomware incident - Question #50ISO/IEC 27001 Controls
You are an experienced audit team leader guiding an auditor in training, Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
technological controlsStatement of ApplicabilityAnnex A ISO 27001:2022malware protection - Question #51Audit Findings and Conclusions
You are preparing the audit findings. Select two options that are correct.
audit findings classificationnonconformity vs OFIincident trainingaudit conclusions - Question #52ISO/IEC 27001 Requirements
You are an experienced ISMS auditor, currently providing support to an ISMS auditor in training who is carrying out her first initial certification audit. She asks you what she sho...
information security objectivesClause 6.2audit checklist reviewISO 27001:2022 conformity - Question #53ISO/IEC 27001 Controls
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team....
information security incidentssecurity events vs incidentsincident classificationISO/IEC 27035