ISO-IEC-27001-LEAD-AUDITOR Exam Questions
365 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 4 of 8.
- Question #154ISMS Controls and Annex A
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
threat intelligencecontrol 5.7ISO 27001:2022audit checklist validation - Question #155Audit Reporting and Follow-up
You are an ISMS audit team leader preparing to chair a closing meeting following a third-party surveillance audit. You are drafting a closing meeting agenda setting out the topics...
closing meetingsurveillance auditaudit agendasampling disclaimer - Question #156Audit Reporting and Follow-up
Which four of the following statements about audit reports are true?
audit reportaudit documentationaudit team leaderconfidentiality - Question #157Auditor Competence
Auditors should have certain knowledge and skills; while audit team leaders should have some additional knowledge and skills. From the following list, select two that only apply to...
audit team leaderauditor rolesaudit planningresource management - Question #158Audit Ethics and Conduct
An auditor of organisation A performs an audit of supplier B. Which two of the following actions is likely to represent a breach of confidentiality by the auditor after having iden...
auditor confidentialitysupplier auditaudit ethicsinformation sharing - Question #159Understanding ISO/IEC 27001 Requirements
Drag and Drop Question Select the words that best complete the sentence: Answer:
ISMS conceptsISO 27001 terminologyaudit definitions - Question #160Audit Planning and Preparation
Which two of the following options for information are not required for audit planning of a certification audit?
audit planningcertification auditrequired documentationaudit inputs - Question #161Audit Execution and Evidence Collection
You are carrying out a third-party surveillance audit of a client's ISMS. You are currently in the secure storage area of the data centre where the organisation's customers are abl...
physical securitypest riskincident managementrisk treatment - Question #162Audit Types and Objectives
Which one of the following options best describes the main purpose of a Stage 2 third-party audit?
Stage 2 auditthird-party certificationnonconformance identification - Question #163Audit Planning
Which two of the following statements are true?
audit planaudit programmeaudit management terminology - Question #164Audit Concepts and Terminology
Drag and Drop Question Select the word that best completes the sentence: Answer:
audit terminologysentence completion - Question #165Audit Evidence Collection and Evaluation
An audit finding is the result of the evaluation of the collected audit evidence against audit criteri
audit evidencedocumented informationevidence acceptability - Question #166Audit Criteria and Standards
Which two of the following standards are used as ISMS third-party certification audit criteria?
audit criteriaISO/IEC 27001certification standards - Question #167Audit Findings
Drag and Drop Question Select the words that best complete the sentence to describe an audit finding. Answer:
audit findingsaudit terminologyevidence vs criteria - Question #168Audit Execution and Supply Chain Security
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the information security...
supplier managementmobile app securitypersonal data handlingoutsourcing - Question #169Information Security Controls Auditing
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
threat intelligenceISO/IEC 27001:2022 new controlsaudit checklistcontrol 5.7 - Question #170Physical Security and Asset Management Auditing
You are carrying out your first third-party ISMS surveillance audit as an audit team leader. You are presently in the auditee's data centre with another member of your audit team a...
secure disposalstorage media lifecyclephysical securityasset management - Question #171Audit Follow-up and Closure
You are an ISMS audit team leader tasked with conducting a follow-up audit at a client's data centre. Following two days on-site you conclude that of the original 12 minor and 1 ma...
follow-up auditnonconformity closurecorrective actionaudit programme - Question #172Audit Planning and Scope Management
After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include...
audit scope extensionStage 1 auditcertification bodyaudit programme management - Question #173Audit Methodology and Conduct
Review the following statements and determine which two are false:
virtual auditonsite auditaudit methodologyaudit duration determination - Question #174Audit Findings and Nonconformity Determination
You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next step in your audit plan is to verify the information security of AB...
nonconformity identificationsoftware security managementsupplier controlsService Manager compliance - Question #175Information Security Controls Auditing
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
organisational controlsStatement of ApplicabilityISO/IEC 27001 Annex ASoA review - Question #176Nonconformity and Corrective Action
An audit team leader is planning a follow-up audit after the completion of a third-party surveillance audit earlier in the year. They have decided they will verify the nonconformit...
corrections vs corrective actionsnonconformity remediationfollow-up auditimmediate fixes - Question #177Certification Benefits and Value
Which two options are benefits of third-party accredited certification of information security management systems to ISO/IEC 27001:2022 for organisations and interested parties?
accredited certificationISO/IEC 27001 benefitsmanagement system credibility - Question #178Certification Benefits and Value
An organisation has ISO/IEC 27001 Information Security Management System (ISMS) certification from a third-party certification body. Which one of the following represents an advant...
accredited certificationcertification credibilitythird-party audit value - Question #179Documentation and Records Requirements
Which one option best describes the purpose of retaining documented information related to the Information Security Management System (ISMS) of an organisation?
documented informationISMS recordsprocess evidenceISO/IEC 27001 clause 7.5 - Question #180Audit Communication and Reporting
In the context of a third-party certification audit, it is very important to have effective communication. Select an option that contains the correct answer about communication in...
audit communicationformal communication channelsaudit team leader responsibility - Question #181Certification Audit Process
Which one of the following options best describes the purpose of a Stage 2 audit?
Stage 2 auditcertification auditISMS implementationaudit phases - Question #182Audit Management and Team Leadership
In the context of a third-party certification audit, which two options state the management responsibilities of the audit team leader in managing the audit and the audit team?
audit team leaderrisk-based audit planningauditee contactaudit management - Question #183Certification Audit Process
Which one of the following conclusions in the audit report is not required by the certification body when deciding to grant certification?
certification bodynonconformity resolutioncertification decisionaudit report - Question #184ISMS Scope Definition and Context
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for mo...
ISMS scopeoutsourced servicescloud servicesscope definition - Question #185ISO/IEC 27001:2022 Annex A Controls
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
PEOPLE controlsStatement of Applicabilitypersonnel securityawareness training - Question #186ISO/IEC 27001:2022 Annex A Controls
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
technological controlsStatement of Applicabilitymalware protectionvulnerability management - Question #187Internal Audit (Clause 9.2)
The data centre at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit, several internal audits have been carri...
internal audit programmeClause 9.2audit criteriaaudit methods - Question #188Information Security Incident Management
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementISO 27035nonconformity vs OFIaudit findings - Question #189Audit Management and Closing
You are an experience ISMS audit team leader carrying out a third-party certification audit of an organization specialising in the secure disposal of confidential documents and rem...
audit team leaderclosing meetinglate-stage evidenceaudit ethics - Question #190Business Continuity Management
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security of the busi...
business continuityBCP testinginformation security during disruptionmobile devices - Question #191Information Security Risk Management
Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of in...
risk management processISO 27001 Clause 6risk assessmentrisk treatment - Question #192Audit Findings and Reporting
You are conducting an Information Security Management System audit in the despatch department of an international logistics organisation that provides shipping services to large or...
audit findingsnonconformity wordingprocess effectivenessoperational control - Question #193Audit Principles and Fundamentals
Select the option which best describes how Information Security Management System audits should be conducted:
audit methodsobjective evidenceaudit findingsaudit process - Question #194Audit Principles and Fundamentals
The purpose of a management system audit is to?
audit purposemanagement system auditperformance evaluation - Question #195Audit Planning and Preparation
When preparing for an audit, which of the following statements is false?
audit preparationaudit checklist confidentialityaudit planauditee communication - Question #196ISO 27001 Operational Requirements (Clause 8)
You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before...
Clause 8.1operational planning and controldocumented informationISMS operational requirements - Question #197Physical and Environmental Security
You are carrying out your first third-party ISMS surveillance audit as an audit team leader. You are presently in the auditee's data centre with another member of your audit team a...
supporting utilitiesAnnex A.7.11physical securityaudit evidence collection - Question #198Asset Management and Media Disposal
You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer re...
asset managementICT media disposalaudit findingsinformation handling - Question #199Internal Audit Process (Clause 9.2)
You are an experienced ISMS audit team leader. You are currently conducting a third-party surveillance audit of an international haulage organisation. You have sampled four interna...
nonconformity gradingcorrective actionsinternal audit reportsaudit programme - Question #200Access Control Management
As the Information Security Management System audit team leader, you are conducting a second- party audit of an international logistics company on behalf of an online retailer. Dur...
access rightsAnnex A control 5.18nonconformity classificationsecond-party audit - Question #201Fundamental Principles and Concepts of Information Security
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
machine learningartificial intelligencecloud computingdata classification - Question #202Fundamental Principles and Concepts of Information Security
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
vulnerabilitiesthreatsrisk conceptsinformation security fundamentals - Question #203Fundamental Principles and Concepts of Information Security
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
CIA triadintegritydata accuracyinformation security principles