nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #241

The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?

The correct answer is C. Detection. Detection risk refers to the risk that the auditor will not detect a material misstatement or significant issue within the organization's ISMS. In this case, the auditor's inability to identify Company A's insecure network architecture is a detection risk.

Planning an ISO/IEC 27001 Audit

Question

The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?

Options

  • AInherent
  • BControl
  • CDetection

How the community answered

(41 responses)
  • A
    5% (2)
  • B
    2% (1)
  • C
    93% (38)

Explanation

Detection risk refers to the risk that the auditor will not detect a material misstatement or significant issue within the organization's ISMS. In this case, the auditor's inability to identify Company A's insecure network architecture is a detection risk.

Topics

#detection risk#audit risk types#audit planning#hidden nonconformities

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice