nerdexam
PECB

ISO-IEC-27001-LEAD-AUDITOR · Question #97

Drag and Drop Question Select the words that best complete the sentence: Answer:

The correct answer is evaluate; management system; a certification. Explanation The sentence being completed is most likely from ISO/quality management auditing contexts, reading something like: > "The purpose of a third-party audit is to \_\_\_ a \_\_\_ in order to award \_\_\_." Resulting in: "...to evaluate a management system in order to…

Information Security Management System Overview

Question

Drag and Drop Question Select the words that best complete the sentence:

Answer:

Exhibit

ISO-IEC-27001-LEAD-AUDITOR question #97 exhibit

Answer Area

Drag items

approveinspecta compliancean accreditationproductsevaluatemanagement systema certificationprocesses

Correct arrangement

  • evaluate
  • management system
  • a certification

Explanation

Explanation

The sentence being completed is most likely from ISO/quality management auditing contexts, reading something like:

"The purpose of a third-party audit is to ___ a ___ in order to award ___."

Resulting in: "...to evaluate a management system in order to award a certification."


Why Each Item Goes Where It Does

1. evaluate (position 1 - the verb)

Audits evaluate - they assess conformance against a standard. The distractors are tempting but wrong:

  • inspect applies to physical products or processes in isolation, not systemic audits
  • approve implies a one-sided sign-off, not the objective evidence-gathering that defines an audit

2. management system (position 2 - the object being audited)

A third-party audit targets the management system as a whole (e.g., ISO 9001 QMS). The distractors:

  • processes are part of a management system but auditing processes alone doesn't lead to certification
  • products are evaluated in product inspection/testing, not system-level audits

3. a certification (position 3 - the outcome/purpose)

Third-party audits exist specifically to grant certification to the management system. The distractors:

  • an accreditation - this is what certifying bodies receive (e.g., UKAS accredits BSI). A common misconception: organizations get certified, bodies get accredited
  • a compliance - not a standard noun phrase; compliance is a state, not something formally "awarded"

Common Mistakes

MistakeWhy it's wrong
Choosing inspect over evaluateInspection = product-level; evaluation = system-level
Choosing an accreditation over a certificationAccreditation goes to the auditing body, not the organization being audited
Choosing processes over management systemToo narrow; certification covers the entire system, not individual processes

Topics

#ISO 27001 concepts#management system terminology#ISMS principles#information security

Community Discussion

No community discussion yet for this question.

Full ISO-IEC-27001-LEAD-AUDITOR Practice