ISO-IEC-27001-LEAD-AUDITOR Exam Questions
365 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 3 of 8.
- Question #104Audit Principles, Preparation and Initiation
Drag and Drop Question Select the words that best complete the sentence below to describe audit resources: Answer:
audit resourcesaudit planningaudit programme management - Question #105Conducting an Audit of an ISMS against ISO/IEC 27001
Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. You find all nursing home residen...
information security policysecurity objectivestop management commitmentaudit evidence mapping - Question #106Conducting an Audit of an ISMS against ISO/IEC 27001
You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next step in your audit plan is to verify the information security of AB...
software security managementoutsourced developmentacceptance testingnonconformity identification - Question #107Conducting an Audit of an ISMS against ISO/IEC 27001
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
PEOPLE controlsStatement of Applicabilitysurveillance auditISO 27001 Annex A - Question #108Conducting an Audit of an ISMS against ISO/IEC 27001
You are an audit team leader conducting a third-party surveillance audit of a telecom services provider. You have assigned responsibility for auditing the organisation's informatio...
information security objectivesISO 27001 clause 6.2documented informationISMS requirements - Question #109Conducting an Audit of an ISMS against ISO/IEC 27001
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for mo...
ISMS scopeinterested partiesoutsourced data centerISO 27001 clause 4 - Question #110Conducting an Audit of an ISMS against ISO/IEC 27001
You are performing an ISMS audit at a residential nursing home that provides healthcare services and are reviewing the Software Code Management (SCM) system. You found a total of 1...
access controluser deregistrationsource code managementterminated employee access - Question #111Conducting an Audit of an ISMS against ISO/IEC 27001
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify that the Statement of Applicability...
Statement of Applicabilityaccess control A.8.4source code managementnonconformity identification - Question #112Conducting an Audit of an ISMS against ISO/IEC 27001
You are a certification body auditor, conducting a surveillance audit to ISO/IEC 27001:2022 of a data centre operated by a client who provides hosting services for ICT facilities....
physical security monitoringdata centre auditphysical entry controlauditor response - Question #113Audit Reporting, Conclusion and Follow-up
You are an experienced ISMS audit team leader who is currently conducting a third party initial certification audit of a new client, using ISO/IEC 27001:2022 as your criteria. It i...
audit completionleadership and commitmentcertification recommendationincomplete audit coverage - Question #114Conducting an Audit of an ISMS against ISO/IEC 27001
Drag and Drop Question Your organisation is currently seeking ISO/IEC27001:2022 certification. You have just qualified as an Internal ISMS auditor and the ICT Manager wants to use...
incident management processISO 27001 Annex Aincident response lifecycleISMS controls - Question #115Audit Reporting, Conclusion and Follow-up
You are an experienced ISMS audit team leader providing guidance to an auditor in training. She asks you why it is important to have specific criteria relating to the grading of no...
nonconformity gradingaudit findings classificationaudit criteriagrading criteria purpose - Question #116Audit Reporting, Conclusion and Follow-up
You are an experienced ISMS audit team leader guiding an auditor in training. You decide to test her knowledge of follow-up audits by asking her a series of questions. Here are you...
follow-up auditcorrective action verificationnonconformity closureaudit follow-up process - Question #117Audit Principles, Preparation and Initiation
You are an audit team leader who has just completed a third-party audit of a mobile telecommunication provider. You are preparing your audit report and are just about to complete a...
audit report confidentialitythird party disclosureaudit ethicsconfidentiality obligations - Question #118Conducting an Audit of an ISMS against ISO/IEC 27001
Drag and Drop Question You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. The next step in your audit plan...
continual improvementcorrective actionpersonal data protectionGDPR compliance - Question #119Audit Reporting, Conclusion and Follow-up
You are the audit team leader conducting a third-party audit of an online insurance company. During Stage 1, you found that the organization took a very cautious risk approach and...
risk treatment planStatement of Applicabilitynonconformity withdrawalclosing meeting conduct - Question #120Conducting an Audit of an ISMS against ISO/IEC 27001
You are performing an ISO 27001 ISMS surveillance audit at a residential nursing home, ABC Healthcare Services. ABC uses a healthcare mobile app designed and maintained by a suppli...
supplier managementpersonal data breachcorrections vs corrective actionsnonconformity remediation - Question #121Information Security Controls (Annex A)
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospit...
information labelingasset managementprivacy protectionsecurity awareness - Question #122Improvement
What is meant by the term 'Corrective Action'? Select one
corrective actionnonconformityISMS improvementterminology - Question #123Audit Program Management
Which two of the following options do not participate in a first-party audit?
first-party auditaudit typescertification bodyinternal audit - Question #124Continual Improvement
Which two of the following phrases would apply to "act" in relation to the Plan-Do-Check-Act cycle for a business process?
PDCA cycleAct phasecontinual improvementprocess management - Question #125Conducting an Audit
Drag and Drop Question In the context of a management system audit, please identify the sequence of a typical process of collecting and verifying information. The first one has bee...
audit methodologyinformation collectionverification sequenceaudit process - Question #126Auditor Competence and Evaluation
During an audit, the audit team leader reached timely conclusions based on logical reasoning and analysis. What professional behaviour was displayed by the audit team leader?
auditor competenciesprofessional behaviordecisiveaudit team leader - Question #127Conducting an Audit
Audit methods can be either with or without interaction with individuals representing the auditee. Which two of the following methods are with interaction?
audit methodsauditee interactioninterviewsaudit techniques - Question #128Conducting an Audit
Drag and Drop Question A key audit process is the way auditors gather information and determine the findings' characteristics. Put the actions listed in the correct order to comple...
audit findingsinformation gatheringevidence evaluationaudit process order - Question #129Conducting an Audit
Which two of the following options are an advantage of using a sampling plan for the audit?
sampling planaudit efficiencyaudit confidenceaudit methodology - Question #130Audit Reporting
Drag and Drop Question You are an experienced ISMS audit team leader, assisting an auditor in training to write their first audit report. You want to check the auditor in training'...
audit report terminologynonconformityfindings classificationaudit documentation - Question #131Audit Reporting and Follow-up
You are an experienced ISMS audit team leader conducting a third-party surveillance visit. You notice that although the auditee is claiming conformity with ISO/IEC 27001:2022 they...
ISO 27001:2022version transitionopportunity for improvementdocumented information - Question #132Information Security Controls (Annex A) - Physical
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
physical controlsStatement of Applicabilitydata center securityAnnex A controls - Question #133Planning - Risk Treatment
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organ...
Statement of Applicabilitycontrol justificationISO 27001 requirementsAnnex A - Question #134Risk Assessment and Treatment
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment pro...
risk assessmentnonconformity criteriarisk treatmentrisk criteria - Question #135Information Security Incident Management
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementaudit evidence collectionISO 27035documented procedures - Question #136Risk Assessment and Treatment
You are conducting an ISMS audit. The next step in your audit plan is to verify that the organisation's information security risk treatment plan has been established and implemente...
risk treatment planresidual risk acceptancetop management responsibilityaudit findings classification - Question #137Physical and Environmental Security
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team....
physical securitycontractor accesssecure areasaudit evidence gathering - Question #138Audit Program Management
You are an ISMS audit team leader assigned by your certification body to carry out a follow-up audit of a Data Centre client. According to ISO 19011:2018, the purpose of a follow-u...
follow-up auditISO 19011corrective actionsaudit types - Question #139Audit Reporting
You are an experienced ISMS audit team leader guiding an auditor in training. She asks you about the grading of nonconformities in audit reports. You decide to test her knowledge b...
nonconformity gradingmajor nonconformityminor nonconformityaudit findings - Question #140Audit Reporting
Which two of the following are valid audit conclusions?
audit conclusionsaudit findings distinctionISMS effectivenessaudit report - Question #141Information Security Risk Management
You are the audit team leader conducting a third-party audit of an online insurance organisation. During Stage 1, you found that the organisation took a very cautious risk approach...
Statement of Applicabilityrisk treatmentAnnex A controlsnonconformity remediation - Question #142Understanding ISO/IEC 27001 Requirements
Which one of the following options is the definition of the context of an organisation?
context of organizationISO 27001 clause 4internal external issues - Question #143Information Security Risk Management
Drag and Drop Question Select the correct sequence for the information security risk assessment process in an ISMS. To complete the sequence click on the blank section you want to...
risk assessment processISMSrisk identificationrisk evaluation - Question #144Audit Planning and Preparation
Drag and Drop Question Please match the following situations to the type of audit required. Answer:
audit typesfirst-party auditsecond-party auditthird-party audit - Question #145Audit Planning and Preparation
Which two of the following phrases would apply to "audit objectives"?
audit objectivesconformityimprovement opportunities - Question #146Certification and Surveillance Audits
Drag and Drop Question An organisation is looking for management system initial certification. Please identify the sequence of the activities to be undertaken by the organisation....
certification processStage 1 auditStage 2 auditinitial certification - Question #147Auditor Competence
Auditor competence is a combination of knowledge and skills. Which two of the following activities are predominately related to "knowledge"?
auditor competenceknowledge vs skillschecklist designevidence gathering - Question #148Audit Planning and Preparation
Drag and Drop Question Select the words that best complete the sentence below to describe a third-party audit plan. To complete the sentence with the best word(s), click on the bla...
audit planthird-party auditaudit documentation - Question #149Audit Execution
Review the following statements and determine which two are false:
virtual auditremote auditauditor trainingaudit duration - Question #150ISMS Controls and Annex A
Drag and Drop Question You are an experienced ISMS internal auditor. You have just completed a scheduled information security audit of your organisation when the IT Manager approac...
ISO 27001:2022 control themesAnnex A controlsStatement of Applicabilitycontrol categorization - Question #151ISMS Documentation
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organ...
Statement of ApplicabilityAnnex A controlsISO 27001 requirementsSoA content - Question #152ISMS Human Resources
You are an experienced ISMS audit team leader providing guidance to an auditor in training. The auditor in training appears to be confused about the interpretation of competence in...
competenceISO 27001 clause 7.2human resources securityscenario analysis - Question #153Information Security Fundamentals
You are an experienced ISMS audit team leader. You are providing an introduction to ISO/IEC 27001:2022 to a class of Quality Management System Auditors who are seeking to retrain t...
CIA triadconfidentialityintegrityavailability