ISO-IEC-27001-LEAD-AUDITOR Exam Questions
365 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 6 of 8.
- Question #254Closing an ISO/IEC 27001 Audit
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
audit recordsdocumented informationaudit documentationretention - Question #255Conducting an ISO/IEC 27001 Audit
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
audit stagesstage 2 auditaudit planaudit team leader responsibilities - Question #256Conducting an ISO/IEC 27001 Audit
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
samplingsample sizeaudit conclusionsaudit methodology - Question #257Conducting an ISO/IEC 27001 Audit
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
auditee consentdocument accessaudit rightsaudit evidence collection - Question #258Closing an ISO/IEC 27001 Audit
As an auditor, you have noticed that ABC Inc. has established a procedure to manage the removable storage media. The procedure is based on the classification scheme adopted by ABC...
conformityaudit findingsfinding classificationremovable media controls - Question #259Conducting an ISO/IEC 27001 Audit
To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team verified a sample of server logs to determine if they can be edited or deleted. Which audit pr...
audit proceduresanalysisAnnex A logging controlsevidence collection - Question #260Closing an ISO/IEC 27001 Audit
The auditor discovered that two out of 15 employees of the IT Department have not received adequate information security training. What does this represent?
audit findingsaudit evidenceinformation security trainingnonconformity - Question #261Managing an audit program
After drafting the audit conclusions, the work documents of the audit team leader were reviewed by another auditor selected by the certification body. Is this acceptable?
audit document reviewaudit team leadercertification body reviewaudit procedures - Question #262Closing the audit
Which of the options below presents a minor nonconformity?
minor nonconformitynonconformity classificationbackup proceduredocument version control - Question #263Conducting the audit
The responsibilities of a------------ include facilitating audit activities, maintaining logistics, ensuring that health and safety policies are observed, and witnessing the audit...
guide responsibilitiesaudit team rolesauditee representativeaudit logistics - Question #264Initiating and preparing the audit
The audit team leader decided to involve a technical expert as part of the audit team, so they could fill the potential gaps of the audit team members' knowledge. What should the a...
technical expertaudit team rolesaudit findings communicationteam composition - Question #265Conducting the audit
The auditor used sampling to ensure that event logs recording information security events are maintained and regularly reviewed. Sampling was based on the audit objectives, whereas...
statistical samplingaudit sampling techniquesprobability-based samplingaudit evidence collection - Question #266Audit reporting and follow-up
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
action plannonconformity responsecorrective actioncertification process - Question #267Audit reporting and follow-up
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
action plan requirementsroot cause analysisnonconformity correctioncorrective action adequacy - Question #268Audit reporting and follow-up
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
major nonconformityaction plan reviewnonconformity prioritizationcertification decision - Question #269Audit reporting and follow-up
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
action plan evaluationaudit team responsibilitynonconformity verificationcertification follow-up - Question #270Managing an audit program
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
auditor impartialityaudit stage sequencingaudit team leader conductaudit ethics - Question #271Audit reporting and follow-up
After analyzing the audit conclusions, Company X decided to accept the risk related to one of the detected nonconformities. They claimed that no corrective action was necessary; ho...
risk acceptancecorrective action documentationnonconformity responseauditee obligations - Question #272Audit reporting and follow-up
Based on the identified nonconformities. Company A established action plans that included the detected nonconformities, the root causes, and a general statement regarding each acti...
action plan requirementscorrective action detailnonconformity documentationroot cause analysis - Question #273Managing an audit program
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
internal audit independenceadvisory roleaudit objectivityinternal audit function - Question #274ISMS certification and surveillance
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
certification scopeISMS scope misusecertification suspensionscope boundaries - Question #275ISMS certification and surveillance
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
extension auditcertification scope expansionISMS scope changescertification body approval - Question #276Managing an audit program
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
auditor rotationaudit independenceimpartialityinternal audit management - Question #277ISMS certification and surveillance
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
surveillance auditcertification audit typespost-certification auditaudit cycle - Question #278Managing an audit program
How are internal audits and external audits related?
internal auditexternal auditcertification cycleaudit relationship - Question #279Audit reporting and follow-up
After conducting an external audit, the auditor decided that the internal auditor would follow-up on the implementation of corrective actions until the next surveillance audit. Is...
corrective action follow-upinternal auditor rolesurveillance auditfollow-up responsibility - Question #280ISMS certification and surveillance
OrgXY is an ISO/IEC 27001-certified software development company. A year after being certified, OrgXY's top management informed the certification body that the company was not read...
certification suspensionsurveillance auditcertification cyclecertification body - Question #281Information Security Concepts
According to ISO/IEC 27001, an Information Security Management System seeks to protect which two of the following?
CIA triadISMS objectivesconfidentialityintegrity - Question #282Audit Types and Roles
Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?
second-party auditaudit typescertification bodyaccreditation body - Question #283Audit Programme Management
When an organisation needs to determine the resources required for the internal audit programme, which one of the following issues does not impact on the achievement of its intende...
audit programme managementaudit resourcesauditor competenceinternal audit - Question #284Audit Process and Evidence
Which one of the following should be reviewed against the audit criteria to determine audit findings?
audit evidenceaudit criteriaaudit findingsaudit process - Question #285ISMS Performance Evaluation
You are an experienced ISMS Audit Team Leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the importance of...
PDCA cyclemanagement reviewISMS performance evaluationplanned intervals - Question #286ISMS Audit Execution and Nonconformity Management
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the information security...
outsourced processessupplier managementnonconformity identificationsoftware security - Question #287Audit Reporting and Follow-up
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing m...
closing meetingcertification scopeorganizational changeaudit reporting - Question #288ISMS Audit Execution
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementISO/IEC 27035ransomwareaudit evidence collection - Question #289Audit Reporting and Follow-up
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing m...
minor nonconformitycertification recommendationcorrective actionaudit follow-up - Question #290Information Security Incident Management
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
software integrityunauthorized softwarechange managementapplication security - Question #291Supplier Relationships and Third-Party Management
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
confidentiality agreementsupplier relationshipscloud servicesthird-party management - Question #292Information Security Controls
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
detective controlsadministrative controlscontrol classificationsecurity controls - Question #293ISMS Related Standards and Frameworks
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
ISO/IEC 27701privacy information managementPII protectionISMS extensions - Question #294Information Security Concepts
Scenario: After an information security incident, an organization created a comprehensive backup procedure involving regular, automated backups of all critical data to offsite stor...
availabilityCIA triadbackup proceduresbusiness continuity - Question #295Risk Assessment and Vulnerability Management
Scenario: A data processing tool crashed when a user added more data to the buffer than its storage capacity allows. The incident was caused by the tool's inability to bound-check...
buffer overflowintrinsic vulnerabilityvulnerability typessoftware security - Question #296Information Security Controls
Which of the following best defines managerial controls?
managerial controlscontrol typespersonnel managementadministrative controls - Question #297Risk Assessment and Vulnerability Management
What is the objective of penetration testing in the risk assessment process?
penetration testingrisk assessmentICT protectionvulnerability identification - Question #298ISMS Controls and Annex A
Which controls are related to the Annex A controls of ISO/IEC 27001 and are often selected from other guides and standards or defined by the organization to meet its specific needs...
specific controlsAnnex Acontrol selectionISO/IEC 27001 - Question #299Risk Assessment and Vulnerability Management
Which of the following statements regarding threats and vulnerabilities in information security is NOT correct?
threatsvulnerabilitiesrisk assessmentcontrol implementation - Question #300Risk Assessment and Vulnerability Management
Which situation presented below represents a threat?
threat identificationzero-day vulnerabilitythreat vs vulnerabilitycyber attack - Question #301Fundamental Principles and Concepts of an ISMS
A cybersecurity company implemented an access control software that allows only authorized personnel to access sensitive files. Which type of control has the company implemented in...
preventive controlcontrol typesaccess controlinformation security controls - Question #302ISO/IEC 27001 Requirements for an ISMS
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
Statement of ApplicabilityAnnex A controlscontrol exclusionsISMS documentation - Question #303ISO/IEC 27001 Requirements for an ISMS
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
ISMS scopecontext of organizationexternal issuesClause 4