nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #148

Drag and Drop Question Select the words that best complete the sentence below to describe a third-party audit plan. To complete the sentence with the best word(s), click on the blank section you…

The correct answer is inspect; report. Third-Party Audit Plan - Drag and Drop Explanation The sentence most likely reads something like: > "A third-party audit plan describes how auditors will [inspect] systems/controls and [report] their findings." --- Placement 1: inspect An audit is fundamentally an examination…

Audit Planning and Preparation

Question

Drag and Drop Question Select the words that best complete the sentence below to describe a third-party audit plan. To complete the sentence with the best word(s), click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #148 exhibit

Answer Area

Drag items

recommendationverifyreportaccessinspectquestion

Correct arrangement

  • inspect
  • report

Explanation

Third-Party Audit Plan - Drag and Drop Explanation

The sentence most likely reads something like:

"A third-party audit plan describes how auditors will [inspect] systems/controls and [report] their findings."


Placement 1: inspect

An audit is fundamentally an examination process. The first action in any audit is to inspect - meaning to actively examine, review, and evaluate the subject (systems, controls, processes, documentation, etc.).

  • "Inspect" is the operative verb that defines what auditors do during an audit.
  • It implies hands-on, methodical review - exactly what a third-party auditor is engaged to perform.
  • This comes first because you cannot report on something you haven't yet examined.

Placement 2: report

After inspection, auditors formalize their findings into a report delivered to stakeholders.

  • A "report" is the tangible deliverable of the audit - it communicates what was found during the inspection.
  • This comes second because reporting is the output step, not the input step.

Why the Other Options Are Wrong

OptionWhy it doesn't fit
verifyOverlaps with inspect but is narrower; auditors inspect broadly, not just verify specific claims
accessA prerequisite to auditing, not a goal described in the plan
recommendationA component within a report, not a standalone audit phase
questionA technique used during inspection, not a phase of the audit plan itself

Common Misconception

Many people confuse verify for inspect because both involve examination. However, "verify" implies confirming something specific is true, while "inspect" describes the full scope of an audit's examination phase - making it the better fit for describing an audit plan.

Topics

#audit plan#third-party audit#audit documentation

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice