nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #130

Drag and Drop Question You are an experienced ISMS audit team leader, assisting an auditor in training to write their first audit report. You want to check the auditor in training's understanding of…

The correct answer is This example relates to the use of audit criteria to determine conformity or nonconformity; This example relates to the identification of an audit finding; This description relates to the determination of an audit conclusion; This example relates to the collection of audit evidence. ISMS Audit Report Terminology - Drag-and-Drop Explained Core Concept This question tests knowledge of four distinct audit process terms defined in ISO 19011 (Guidelines for Auditing Management Systems). Each position represents a specific scenario/vignette; you must match the…

Audit Reporting

Question

Drag and Drop Question You are an experienced ISMS audit team leader, assisting an auditor in training to write their first audit report. You want to check the auditor in training's understanding of terminology relating to the contents of an audit report and chose to do this by presenting the following examples. For each example, you ask the auditor in training what the correct term is that describes the activity Match the activity to the description. Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #130 exhibit

Answer Area

Drag items

This example relates to the identification of an audit findingThis example relates to the use of audit criteria to determine conformity or nonconformityThis description relates to the determination of an audit conclusionThis example relates to the collection of audit evidence

Correct arrangement

  • This example relates to the use of audit criteria to determine conformity or nonconformity
  • This example relates to the identification of an audit finding
  • This description relates to the determination of an audit conclusion
  • This example relates to the collection of audit evidence

Explanation

ISMS Audit Report Terminology - Drag-and-Drop Explained

Core Concept

This question tests knowledge of four distinct audit process terms defined in ISO 19011 (Guidelines for Auditing Management Systems). Each position represents a specific scenario/vignette; you must match the correct terminology label to it.

The four terms in logical process order are:

StepTermWhat it means
1Audit EvidenceRaw information collected (interviews, docs, observations)
2Audit CriteriaThe benchmark (policy/standard) used to judge evidence
3Audit FindingThe result of comparing evidence against criteria
4Audit ConclusionThe overall outcome after considering all findings

Why Each Item Goes Where It Does

Position 1 → "Use of audit criteria to determine conformity or nonconformity"

The scenario at position 1 describes someone comparing collected evidence against a reference standard (e.g., "ISO 27001 clause 8.2 requires a risk assessment - the organization has one, therefore: conformity"). This is the definition of applying audit criteria. It is the evaluative act, not the data-gathering act.

Position 2 → "Identification of an audit finding"

An audit finding is the documented result of that evaluation - it records whether something conforms, doesn't conform, or presents an opportunity for improvement. The scenario here shows a specific, factual statement emerging from the criteria comparison (e.g., "Nonconformity: access reviews are not conducted at defined intervals per the organization's own policy").

Position 3 → "Determination of an audit conclusion"

A conclusion is the holistic judgement drawn after reviewing all findings collectively. The scenario at position 3 describes an auditor forming an overall opinion on the ISMS's effectiveness or suitability - not one single finding, but the sum of them. This always comes after findings are compiled.

Position 4 → "Collection of audit evidence"

The scenario here describes gathering raw information - sampling logs, interviewing staff, reviewing procedures, observing controls in action. Although evidence collection happens early in the real audit timeline, in this question the example appears at position 4 because the scenarios are not arranged chronologically - they are just four independent vignettes presented in the order the trainer chose.


Common Mistakes to Avoid

Confusing findings with conclusions. A finding is a specific, individual result (one nonconformity, one conformity). A conclusion is the aggregate verdict for the entire audit scope. Many trainees write conclusions where findings belong and vice versa.

Confusing evidence with findings. Evidence is raw and unevaluated (a screenshot, a log file, a staff statement). A finding is what you conclude after applying criteria to that evidence.

Assuming the positions are chronological. This is a matching exercise - the order the examples are presented does not reflect the order these steps occur in an audit. Don't let position 4 for "evidence collection" mislead you into thinking it happens last.

Treating criteria as criteria documents. Criteria are the reference requirements you audit against (ISO 27001 clauses, internal policies). Applying them means making a conformity judgement - it's an active comparison, not just citing a document.

Topics

#audit report terminology#nonconformity#findings classification#audit documentation

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice