ISO-IEC-27001-LEAD-AUDITOR Exam Questions
365 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 2 of 8.
- Question #54Conducting an ISO/IEC 27001 Audit
You are performing an ISMS audit at a nursing home where residents always wear an electronic wristband for monitoring their location, heartbeat, and blood pressure. The wristband a...
mobile device policyinformation security objectivesaudit evidence samplingteleworking controls - Question #55Managing an ISO/IEC 27001 Audit Programme
The data center at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit a number of internal audits have been ca...
internal audit programmeClause 9.2audit programme nonconformitiesaudit criteria - Question #56ISO/IEC 27001 Controls
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
threat intelligence Control 5.7ISO 27001:2022 new controlsthreat information sourcesaudit checklist validation - Question #57Conducting an ISO/IEC 27001 Audit
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security of the busi...
business continuity managementBCP testinginformation security continuityaudit evidence collection - Question #58ISO/IEC 27001 Controls
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team....
physical entry control A.7.2contractor physical accesssecure areasnonconformity classification - Question #59ISO/IEC 27001 Requirements
Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to an auditor in training. They are unclear in their understanding of risk processes and...
risk management processesrisk assessmentrisk treatmentISO 27001 risk framework - Question #60Audit Findings and Conclusions
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing m...
closing meetingminor nonconformitycertification recommendationcorrective action plan - Question #61Audit Conclusion and Follow-up Activities
You are an ISMS audit team leader tasked with conducting a follow-up audit at a client's data centre. Following two days on-site you conclude that of the original 12 minor and 1 ma...
follow-up auditnonconformity managementcorrective actionaudit closure - Question #62Audit Reporting and Closing Activities
You are an experienced ISMS audit team leader guiding an auditor in training. Your team has just completed a third-party surveillance audit of a mobile telecom provider. The audito...
closing meetingaudit team managementaudit conclusionsthird-party surveillance audit - Question #63Audit Follow-up Activities
You are an experienced ISMS audit team leader guiding an auditor in training. You are testing her understanding of follow-up audits by asking her a series of questions to which the...
follow-up auditnonconformity classificationcertification suspensionaudit programme - Question #64Audit Findings and Nonconformity Management
Drag and Drop Question As the ISMS audit team leader, you are conducting a second-party audit of an international logistics company on behalf of an online retailer. During the audi...
access rightsnonconformity classificationISO 27001 Annex A controlssecond-party audit - Question #65Audit Evidence and Findings
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospit...
data leakage protectioninformation labellingphysical security monitoringISO 27001 controls mapping - Question #66Managing and Conducting an Audit
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospit...
nonconformity challengeauditor conductaudit objectivityaudit findings integrity - Question #67ISMS Concepts and Principles
Which two of the following statements are true?
ISMS purposerisk management processinformation security benefitscertification rationale - Question #68Audit Program Management and Planning
Drag and Drop Question The following options are key actions involved in a first-party audit. Order the stages to show the sequence in which the actions should take place. Answer:
first-party auditaudit stages sequenceinternal audit processaudit planning - Question #69Management System Principles
Which two of the following phrases would apply to "plan" in relation to the Plan-Do-Check-Act cycle for a business process?
PDCA cyclePlan phasemanagement system objectivescontinual improvement - Question #70Audit Objectives and Scope
Which two of the following phrases are 'objectives' in relation to a first-party audit?
first-party audit objectivesISMS scope confirmationinternal audit goalsaudit purpose - Question #71Audit Roles and Responsibilities
Drag and Drop Question Match the correct responsibility with each participant of a second-party audit: Answer:
second-party auditaudit rolesaudit responsibilitiesaudit participants - Question #72Certification Audit Process
Which one of the following options describes the main purpose of a Stage 1 audit?
Stage 1 auditcertification auditaudit readiness determinationthird-party audit - Question #73Audit Objectives and Scope
Objectives, criteria, and scope are critical features of a third-party ISMS audit. Which two issues are audit objectives?
audit objectivesthird-party auditISO 27001 conformityaudit scope - Question #74Audit Methods and Techniques
Which two of the following are examples of audit methods that 'do not' involve human interaction?
audit methodsremote auditdocument reviewdata analysis without interaction - Question #75Audit Planning and Preparation
Select two options that describe an advantage of using a checklist.
audit checklistaudit trailaudit plan implementationaudit preparation - Question #76Audit Evidence Collection and Verification
Which one of the following statements best describes the purpose of conducting a document review?
document reviewaudit criteriamanagement system documentationconformity assessment - Question #77Audit Findings and Nonconformity Management
Drag and Drop Question Select the words that best complete the sentence to descirbe an audit finding. Answer:
audit findings definitionaudit evidencenonconformityaudit criteria - Question #78Audit Scope Management
During a Stage 1 audit opening meeting, the Management System Representative (MSR) asks to extend the audit scope to include a new site overseas which they have expanded into since...
audit scopeStage 1 auditscope extensioncertification body notification - Question #79Audit Methods and Techniques
You have to carry out a third-party virtual audit. Which two of the following issues would you need to inform the auditee about before you start conducting the audit?
virtual auditremote audit conductpre-audit notificationauditee confidentiality - Question #80Information Security Risk Management
Drag and Drop Question You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the re...
risk terminologyrisk assessmentrisk management processISO 27001 risk concepts - Question #81Audit Findings and Nonconformities
You ask the IT Manager why the organisation still uses the mobile app while personal data encryption and pseudonymisation tests failed. Also, whether the Service Manager is authori...
nonconformity identificationsoftware security procedureacceptance testingauthorization controls - Question #82Audit Findings and Nonconformities
You ask the IT Manager why the organisation still uses the mobile app while personal data encryption and pseudonymization tests failed. Also, whether the Service Manager is authori...
nonconformity identificationchange managementsoftware security procedureexternal service providers - Question #83Context of the Organization
During a third-party certification audit, you are presented with a list of issues by an auditee. Which four of the following constitute 'internal' issues in the context of a manage...
internal issuesexternal issuesorganizational contextISO 27001 clause 4 - Question #84Information Security Risk Management
You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk manage...
risk assessmentrisk treatment planrisk management processISO 27001 clause 6 - Question #85Context of the Organization
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for mo...
ISMS scopeinterested partiesoutsourced serviceshealthcare personal data - Question #86Supplier Relationships and External Providers
You are an experienced ISMS audit team leader providing guidance to an ISMS auditor in training. They have been asked to carry out an assessment of external providers and have prep...
external providerssupplier managementaudit checklist reviewthird-party audit - Question #87Conducting an Audit
You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer re...
audit findingsasset managementphysical securityauditor conduct - Question #88Audit Program Management
Drag and Drop Question You are an experienced ISMS audit team leader. An auditor in training has approached you to ask you to clarify the different types of audits she may be requi...
audit typesfirst-party auditsecond-party auditthird-party audit - Question #89Audit Findings and Nonconformities
You are performing an ISMS audit at a residential nursing home railed ABC that provides healthcare services. The next step in your audit plan is to verify the effectiveness of the...
data privacynonconformity identificationservice agreement compliancecontinual improvement - Question #90Audit Program Management
You are an ISMS audit team leader who has been assigned by your certification body to carry out a follow-up audit of a client. You are preparing your audit plan for this audit. Whi...
follow-up auditcorrective action verificationaudit planningaudit effectiveness - Question #91Audit Program Management
During a follow-up audit, you notice that a nonconformity identified for completion before the follow-up audit is still outstanding. Which four of the following actions should you...
follow-up auditoutstanding nonconformitycorrective actionsaudit reporting - Question #92Audit Findings and Nonconformities
You are performing an ISO 27001 ISMS surveillance audit at a residential nursing home, ABC Healthcare Services. ABC uses a healthcare mobile app designed and maintained by a suppli...
corrective action evidencenonconformity closuredata privacy controlssupplier compliance - Question #93Context of the Organization
Which one of the following options is the definition of an interested party?
interested partyISO 27001 terminologystakeholder definitionclause 4 - Question #94Information Security Management System Overview
Which two of the following statements are true?
ISMS purposeISMS benefitsrisk managementinformation security objectives - Question #95Compliance
Drag and Drop Question Select the words that best complete the sentence: "The purpose of maintaining regulatory compliance in a management system is to To complete the sentence wit...
regulatory compliancelegal requirementsmanagement systemcompliance obligations - Question #96Performance Evaluation
Which two of the following phrases would apply to 'check' in the Plan-Do-Check-Act cycle for a business process?
PDCA cycleperformance evaluationmonitoring and measurementcheck phase - Question #97Information Security Management System Overview
Drag and Drop Question Select the words that best complete the sentence: Answer:
ISO 27001 conceptsmanagement system terminologyISMS principlesinformation security - Question #98Audit Program Management
Which two of the following actions are the individual(s) managing the audit programme responsible for?
audit program managementaudit roles and responsibilitiesISO 19011audit programme manager - Question #99Conducting an Audit
Drag and Drop Question The audit lifecycle describes the ISO 19011 process for conducting an individual audit. Drag and drop the steps of the audit lifecycle into the correct seque...
audit lifecycleaudit process sequenceISO 19011audit phases - Question #100Audit Program Management
You are the person responsible for managing the audit programme and deciding the size and composition of the audit team for a specific audit. Select the two factors that should be...
audit team compositionaudit team competenceaudit scopeaudit planning - Question #101Audit Principles, Preparation and Initiation
Drag and Drop Question Auditors need to communicate effectively with auditees. Therefore, their personal behaviour is a key characteristic needed to ensure a successful audit. Belo...
auditor personal behaviourauditor characteristicsaudit communicationauditor competence - Question #102Audit Team Management and Competence
Select two of the following options that are the responsibility of a legal technical expert on the audit team during a certification audit.
audit team roleslegal technical expertcertification auditaudit team competence - Question #103Audit Principles, Preparation and Initiation
The audit team leader prepares the audit plan for an initial certification stage 2 audit to ISO/IEC 27001:2022. Which one of the following statements is true?
audit planinitial certification auditstage 2 auditaudit team leader responsibilities