ISO-IEC-27001-LEAD-AUDITOR · Question #241
The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?
The correct answer is C. Detection. Detection risk refers to the risk that the auditor will not detect a material misstatement or significant issue within the organization's ISMS. In this case, the auditor's inability to identify Company A's insecure network architecture is a detection risk.
Question
The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?
Options
- AInherent
- BControl
- CDetection
How the community answered
(41 responses)- A5% (2)
- B2% (1)
- C93% (38)
Explanation
Detection risk refers to the risk that the auditor will not detect a material misstatement or significant issue within the organization's ISMS. In this case, the auditor's inability to identify Company A's insecure network architecture is a detection risk.
Topics
Community Discussion
No community discussion yet for this question.