ISO-IEC-27001-LEAD-AUDITOR Exam Questions
365 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 5 of 8.
- Question #204Information Security Controls
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
control typespreventive controlstechnical controlscontrol classification - Question #205Risk Management
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
business impactreputational riskincident consequencesrisk impact - Question #206Fundamental Principles and Concepts of Information Security
Which situation presented below represents a threat?
threat identificationthreat scenariospassword crackingthreat types - Question #207Fundamental Principles and Concepts of Information Security
An organization does not check the source code of the updated version of an application when it is updated automatically. Thus, the application may be open to unauthorized modifica...
vulnerabilityintegrityapplication securitysource code - Question #208Information Security Controls
A telecommunications company uses the AES method for ensuring that confidential information is protected. This means that they use a single key to encrypt and decrypt the informati...
symmetric encryptionAESpreventive controlscryptographic controls - Question #209Fundamental Principles and Concepts of Information Security
You received an email requiring you to send information such as name, email, and password in order to continue using your email account. If you do not send such information, your e...
phishingsocial engineeringunauthorized actionthreat types - Question #210Fundamental Principles and Concepts of Information Security
Which statement below best describes the relationship between information security aspects?
threat-vulnerability relationshipassetsrisk conceptsinformation security model - Question #211Information Security Controls
Which of the options below is a control related to the management of personnel that aims to avoid the occurrence of incidents?
security awareness trainingpersonnel securitypreventive controlshuman resource security - Question #212Fundamental Principles and Concepts of Information Security
A data processing tool crashed when a user added more data in the buffer than its storage capacity allows. The incident was caused by the tool's inability to bound check arrays. Wh...
buffer overflowintrinsic vulnerabilityapplication vulnerabilitysoftware security - Question #213Fundamental Principles and Concepts of Information Security
PayBell, a finance corporation, is using an accounting software to track financial transactions. The software can be accessed from anywhere with an internet connection. It also ena...
cloud computingSaaSinternet accessibilityservice models - Question #214Risk Management
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
vulnerability identificationrisk identificationsecurity assessmentISMS context - Question #215Risk Management
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
risk treatmentrisk modificationrisk optionsrisk response - Question #216ISMS Planning and Establishment
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
ISMS scopeorganizational scopeISO 27001 planningscope definition - Question #217ISMS Implementation
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
Statement of ApplicabilitySoAcontrol justificationISO 27001 documentation - Question #218Risk Management
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
residual riskrisk acceptancetop management approvalrisk treatment - Question #219Risk Management
A marketing agency has developed its own risk assessment approach as part of the ISMS implementation. Is this acceptable?
risk assessment methodologyISO 27001 compliancecustom methodologyrisk process - Question #220Performance Evaluation and Continual Improvement
ISMS (1)---------------helps determine (2)--------------.
management reviewcontinual improvementISMS performanceperformance evaluation - Question #221ISMS Documentation and Scope
Which option below about the ISMS scope is correct?
ISMS scopedocumented informationISO 27001 requirements - Question #222ISO/IEC 27001 Compliance Requirements
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
legal complianceISO 27001 requirementsapplicable legislationISMS conformance - Question #223Audit Evidence and Sampling
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
audit evidence typesmathematical evidenceevidence classification - Question #224ISO/IEC 27001 Annex A Controls
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
Annex A controlsintellectual property rightscontrol mappingISO 27001 Annex A - Question #225Auditor Competence and Ethics
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
auditor ethicsconfidentialityauditor principlesprofessional conduct - Question #226Auditor Competence and Ethics
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
financial crimeauditor responsibilitiesconflict of interestaudit reporting - Question #227ISMS Operations and Supplier Relationships
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
business continuitysupplier managementcontract terminationrecovery plan - Question #228ISMS Operations and Supplier Relationships
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
business continuity planningoutsourcing risksupplier dependencyimpact analysis - Question #229Audit Evidence and Sampling
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
audit evidence reliabilityverbal evidenceoutsourced operations monitoringevidence sufficiency - Question #230Audit Evidence and Sampling
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
technical evidencefirewall configurationaudit testingtechnical controls validation - Question #231Auditor Competence and Ethics
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
professional skepticismauditor behaviorrisk-based auditingaudit principles - Question #232Audit Evidence and Sampling
Which is an example of a qualitative evidence?
qualitative evidenceaudit interviewsevidence typesinformation security processes - Question #233Certification Body and Audit Program Management
Finnco, a subsidiary of a certification body, provided ISMS consultancy services to an organization. Considering this scenario, when can the certification body certify the organiza...
conflict of interestcertification body independenceconsultancy servicesimpartiality - Question #234Audit Team Management and Leadership
Which option below is NOT a role of the audit team leader?
audit team leader rolesethics committeeaudit leadershipauditor responsibilities - Question #235Audit Techniques and Technology
How does the use of new technologies such as big data impact auditing?
big dataemerging technologiesaudit challengesdata analysis - Question #236Certification Body and Audit Program Management
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
audit program managementaudit team appointmentcertification body responsibilitiesaudit planning - Question #237Audit Planning and Preparation
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
audit mandateaudit durationauditor rightsaudit scope negotiation - Question #238Risk Assessment and Treatment
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
risk typescontrol riskinherent riskrisk assessment - Question #239Audit Reporting and Follow-up
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
audit assurancereasonable assuranceISMS conformanceaudit conclusions - Question #240Certification Body and Audit Program Management
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
certification agreementaudit initiationcertification processaudit stages - Question #241Planning an ISO/IEC 27001 Audit
The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?
detection riskaudit risk typesaudit planninghidden nonconformities - Question #242Planning an ISO/IEC 27001 Audit
Costs related to nonconformities and failures to comply with legal and contractual requirements are assessed when defining:
materialitynonconformity costslegal complianceaudit planning - Question #243Planning an ISO/IEC 27001 Audit
AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the...
audit scopeISMS scopecertification auditscope alignment - Question #244Fundamental Principles and Concepts of an ISMS Audit
An external auditor received an offer to conduct an ISMS audit at a research development company. Before accepting it, they discussed with the internal auditor of the auditee, who...
auditor independenceobjectivityaudit ethicsconflict of interest - Question #245Fundamental Principles and Concepts of an ISMS
The scope of an organization certified against ISO/IEC 27001 states that they provide editing and web hosting services. However, due to some changes in the organization, the techni...
ISMS scopeoutsourcingscope managementexternal environment - Question #246Planning an ISO/IEC 27001 Audit
The auditor should consider (1)-------when determining the (2)--------
audit risksaudit objectivesaudit planningrisk consideration - Question #247Planning an ISO/IEC 27001 Audit
Why should materiality be considered during the initial contact?
materialityreasonable assuranceinitial contactaudit planning - Question #248Conducting an ISO/IEC 27001 Audit
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
documentation reviewauditee rightson-site vs off-siteconfidentiality - Question #249Conducting an ISO/IEC 27001 Audit
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
access rightsinformation security policyaudit scopeISMS controls - Question #250Conducting an ISO/IEC 27001 Audit
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
stage 1 auditnonconformity correctionaudit stagescorrective action - Question #251Conducting an ISO/IEC 27001 Audit
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
stage 1 auditdocument reviewISO 27001 requirementsaudit procedures - Question #252Conducting an ISO/IEC 27001 Audit
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
Annex A controlsevent loggingISO 27001 requirementsaudit verification - Question #253Closing an ISO/IEC 27001 Audit
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
nonconformityaudit findingsfinding classificationISMS evaluation