nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #46

Drag and Drop Question You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the…

The correct answer is review; assess; regular; suitability. PDCA Check Stage - Drag-and-Drop Explained The Reconstructed Sentence Based on ISO 27001 Clause 9.3 (Management Review), the sentence reads approximately: > "In the Check stage, you should [1] review and [2] assess the ISMS on a [3] regular basis to ensure its continuing [4]…

ISO/IEC 27001 Requirements

Question

Drag and Drop Question You are an experienced ISMS audit team leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the importance of the Check stage of the Plan-Do-Check-Act cycle in respect of the operation of the information security management system. You do this by asking him to select the words that best complete the sentence:

To complete the sentence with the best word(s), click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #46 exhibit

Answer Area

Drag items

plannedassessRisk AssessmentefficiencysuitabilityreviewRisk ManagementregularManagement Review

Correct arrangement

  • review
  • assess
  • regular
  • suitability

Explanation

PDCA Check Stage - Drag-and-Drop Explained

The Reconstructed Sentence

Based on ISO 27001 Clause 9.3 (Management Review), the sentence reads approximately:

"In the Check stage, you should [1] review and [2] assess the ISMS on a [3] regular basis to ensure its continuing [4] suitability, adequacy, and effectiveness."


Item-by-Item Breakdown

Position 1 - review The Check stage is fundamentally a reviewing activity. ISO 27001 Clause 9.3 explicitly states top management shall review the ISMS at planned intervals. "Review" is the governing verb that frames the entire Check activity. Management Review (a distractor) is a specific process, not the action verb needed here.

Position 2 - assess After reviewing, you must assess whether the ISMS is performing as intended. This reflects Clause 9.1 (monitoring, measurement, analysis, and evaluation). assess is the analytical follow-through to review - reviewing without assessing yields no actionable insight.

Position 3 - regular ISO 27001 requires the ISMS to be reviewed at planned intervals to be effective. "Regular" captures this recurring cadence. The distractor planned is tempting - the standard does use "planned intervals" - but in the context of this sentence, regular better conveys the frequency characteristic that distinguishes Check from a one-off activity.

Position 4 - suitability ISO 27001 Clause 9.3 uses the exact phrase: "continuing suitability, adequacy and effectiveness." suitability asks whether the ISMS still fits the organisation's context. The distractor efficiency is not standard ISO 27001 language for this clause - the standard never uses efficiency as a criterion in management review outputs.


Common Mistakes

MistakeWhy It's Wrong
Choosing planned over regular"Planned intervals" is ISO wording, but regular is the better fit for describing the nature of the cadence in this sentence
Choosing efficiency over suitabilityefficiency sounds plausible but is not part of the ISO 27001 Clause 9.3 triad (suitability, adequacy, effectiveness)
Choosing Management Review over reviewManagement Review is a named process, not the verb completing the sentence
Choosing Risk Assessment or Risk ManagementThese belong to the Plan stage, not Check

Key Takeaway

The Check stage = review + assess + regular cadence + suitability focus. Everything in this sentence maps directly to ISO 27001 Clause 9 (Performance Evaluation), which is the normative home of the Check stage activities.

Topics

#PDCA cycle#Check stage#ISMS operation#performance evaluation

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice