ISO-IEC-27001-LEAD-AUDITOR Exam Questions
335 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 3 of 7.
- Question #122
What is meant by the term 'Corrective Action'? Select one
- Question #123
Which two of the following options do not participate in a first-party audit?
- Question #124
Which two of the following phrases would apply to "act" in relation to the Plan-Do-Check-Act cycle for a business process?
- Question #126
During an audit, the audit team leader reached timely conclusions based on logical reasoning and analysis. What professional behaviour was displayed by the audit team leader?
- Question #127
Audit methods can be either with or without interaction with individuals representing the auditee. Which two of the following methods are with interaction?
- Question #129
Which two of the following options are an advantage of using a sampling plan for the audit?
- Question #131
You are an experienced ISMS audit team leader conducting a third-party surveillance visit. You notice that although the auditee is claiming conformity with ISO/IEC 27001:2022 they...
- Question #132
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
- Question #133
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organ...
- Question #134
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment pro...
- Question #135
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
- Question #136
You are conducting an ISMS audit. The next step in your audit plan is to verify that the organisation's information security risk treatment plan has been established and implemente...
- Question #137
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team....
- Question #138
You are an ISMS audit team leader assigned by your certification body to carry out a follow-up audit of a Data Centre client. According to ISO 19011:2018, the purpose of a follow-u...
- Question #139
You are an experienced ISMS audit team leader guiding an auditor in training. She asks you about the grading of nonconformities in audit reports. You decide to test her knowledge b...
- Question #140
Which two of the following are valid audit conclusions?
- Question #141
You are the audit team leader conducting a third-party audit of an online insurance organisation. During Stage 1, you found that the organisation took a very cautious risk approach...
- Question #142
Which one of the following options is the definition of the context of an organisation?
- Question #145
Which two of the following phrases would apply to "audit objectives"?
- Question #147
Auditor competence is a combination of knowledge and skills. Which two of the following activities are predominately related to "knowledge"?
- Question #149
Review the following statements and determine which two are false:
- Question #151
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organ...
- Question #152
You are an experienced ISMS audit team leader providing guidance to an auditor in training. The auditor in training appears to be confused about the interpretation of competence in...
- Question #153
You are an experienced ISMS audit team leader. You are providing an introduction to ISO/IEC 27001:2022 to a class of Quality Management System Auditors who are seeking to retrain t...
- Question #154
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
- Question #155
You are an ISMS audit team leader preparing to chair a closing meeting following a third-party surveillance audit. You are drafting a closing meeting agenda setting out the topics...
- Question #156
Which four of the following statements about audit reports are true?
- Question #157
Auditors should have certain knowledge and skills; while audit team leaders should have some additional knowledge and skills. From the following list, select two that only apply to...
- Question #158
An auditor of organisation A performs an audit of supplier B. Which two of the following actions is likely to represent a breach of confidentiality by the auditor after having iden...
- Question #160
Which two of the following options for information are not required for audit planning of a certification audit?
- Question #161
You are carrying out a third-party surveillance audit of a client's ISMS. You are currently in the secure storage area of the data centre where the organisation's customers are abl...
- Question #162
Which one of the following options best describes the main purpose of a Stage 2 third-party audit?
- Question #163
Which two of the following statements are true?
- Question #165
An audit finding is the result of the evaluation of the collected audit evidence against audit criteri
- Question #166
Which two of the following standards are used as ISMS third-party certification audit criteria?
- Question #168
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the information security...
- Question #169
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
- Question #170
You are carrying out your first third-party ISMS surveillance audit as an audit team leader. You are presently in the auditee's data centre with another member of your audit team a...
- Question #171
You are an ISMS audit team leader tasked with conducting a follow-up audit at a client's data centre. Following two days on-site you conclude that of the original 12 minor and 1 ma...
- Question #172
After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include...
- Question #173
Review the following statements and determine which two are false:
- Question #174
You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next step in your audit plan is to verify the information security of AB...
- Question #175
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
- Question #176
An audit team leader is planning a follow-up audit after the completion of a third-party surveillance audit earlier in the year. They have decided they will verify the nonconformit...
- Question #177
Which two options are benefits of third-party accredited certification of information security management systems to ISO/IEC 27001:2022 for organisations and interested parties?
- Question #178
An organisation has ISO/IEC 27001 Information Security Management System (ISMS) certification from a third-party certification body. Which one of the following represents an advant...
- Question #179
Which one option best describes the purpose of retaining documented information related to the Information Security Management System (ISMS) of an organisation?
- Question #180
In the context of a third-party certification audit, it is very important to have effective communication. Select an option that contains the correct answer about communication in...
- Question #181
Which one of the following options best describes the purpose of a Stage 2 audit?
- Question #182
In the context of a third-party certification audit, which two options state the management responsibilities of the audit team leader in managing the audit and the audit team?