nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #135

ISO-IEC-27001-LEAD-AUDITOR Question #135: Real Exam Question with Answer & Explanation

Sign in or unlock ISO-IEC-27001-LEAD-AUDITOR to reveal the answer and full explanation for question #135. The question stem and answer options stay visible for context.

Question

You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process. The IT Security Manager presents the information security incident management procedure (Document reference ID: ISMS_L2_16, version 4). You review the document and notice a statement "Any information security weakness, event, and incident should be reported to the Point of Contact (PoC) within 1 hour after identification". When interviewing staff, you found that there were differences in the understanding of the meaning of the phrase "weakness, event, and incident". The IT Security Manager explained that an online "information security handling" training seminar was conducted 6 months ago. All the people interviewed participated in and passed the reporting exercise and course assessment. You would like to investigate other areas further to collect more audit evidence. Select three options that would not be valid audit trails.

Options

  • ACollect more evidence on how areas subject to information security incidents are quarantined to
  • BCollect more evidence on how information security incidents are reported via appropriate
  • CCollect more evidence on how the organisation conducts information security incident training and
  • DCollect more evidence on how the organisation learns from information security incidents and
  • ECollect more evidence on how the organisation manages the Point of Contact (PoC) which
  • FCollect more evidence on how the organisation tests the business continuity plan. (Relevant to
  • GCollect more evidence on whether terms and definitions are contained in the information security
  • HCollect more evidence to determine if ISO 27035 (Information security incident management) is

Unlock ISO-IEC-27001-LEAD-AUDITOR to see the answer

You've previewed enough free ISO-IEC-27001-LEAD-AUDITOR questions. Unlock ISO-IEC-27001-LEAD-AUDITOR for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full ISO-IEC-27001-LEAD-AUDITOR Practice