ISO-IEC-27001-LEAD-AUDITOR Exam Questions
365 real ISO-IEC-27001-LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 7 of 8.
- Question #304ISO/IEC 27001 Requirements for an ISMS
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
information security objectivesrisk assessmentISMS planningClause 6 - Question #305ISO/IEC 27001 Requirements for an ISMS
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
ISMS scopescope limitationsClause 4.3certification scope - Question #306Risk Assessment and Treatment
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
OCTAVErisk assessment methodologyrisk frameworksISMS risk assessment - Question #307ISO/IEC 27001 Requirements for an ISMS
According to ISO/IEC 27001, Clause 5.1 (Leadership and Commitment), which of the following is NOT a responsibility of top management?
top managementleadership commitmentClause 5.1ISMS governance - Question #308Risk Assessment and Treatment
A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?
risk assessment methodologyISO/IEC 27001 flexibilityrisk managementClause 6.1 - Question #309ISO/IEC 27001 Requirements for an ISMS
Which of the following statements regarding documented information in an organization's ISMS is incorrect?
documented informationClause 7.5ISMS documentationinformation management - Question #310Risk Assessment and Treatment
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
detection riskrisk typesrisk assessmentcontrol effectiveness - Question #311Planning and Conducting an ISO/IEC 27001 Audit
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
audit planningaudit team responsibilitiesaudit preparationISO 19011 - Question #312Planning and Conducting an ISO/IEC 27001 Audit
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
audit confidentialityauditor conductinformation accessaudit ethics - Question #313Planning and Conducting an ISO/IEC 27001 Audit
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
audit scope changecertification bodyaudit managementscope modification - Question #314Planning and Conducting an ISO/IEC 27001 Audit
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
auditor withdrawalcertification agreementaudit teamISO/IEC 17021-1 - Question #315Planning and Conducting an ISO/IEC 27001 Audit
Three auditors were assigned to conduct a certification audit in Company X. Before the audit commenced, the certification body provided the auditors' names and background informati...
auditor independenceconflict of interestauditor replacementaudit impartiality - Question #316Planning and Conducting an ISO/IEC 27001 Audit
What is the main reason for sending an engagement letter before the initial contact with the auditee?
engagement letterinitial contactaudit preparationaudit communication - Question #317Planning and Conducting an ISO/IEC 27001 Audit
In a joint audit involving multiple audit teams, how many audit team leaders are typically designated per audit?
joint auditaudit team leadermulti-team auditaudit management - Question #318Planning and Conducting an ISO/IEC 27001 Audit
Why should materiality be considered during the initial contact?
materialityaudit objectivesinitial contactaudit planning - Question #319Planning and Conducting an ISO/IEC 27001 Audit
During which stage of the audit do auditors identify key processes to be audited and prioritize based on materiality?
Stage 1 auditaudit stageskey processesmateriality - Question #320Planning and Conducting an ISO/IEC 27001 Audit
When multiple offices of a certification body are involved, what must be ensured?
multi-site certificationcertification scopelegally enforceable agreementcertification body - Question #321Planning an ISO/IEC 27001 Audit
An organization is evaluating the materiality of different processes within its ISMS. It is assessing the direct expenses involved with personnel, third-party services, and general...
materialitycost of processISMS operationsaudit criteria - Question #322Conducting an ISO/IEC 27001 Audit
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
audit evidence reliabilityevidence evaluationformer employee testimonyclient evidence - Question #323Conducting an ISO/IEC 27001 Audit
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
fraudnegligenceauditor ethicsnonconformity classification - Question #324Conducting an ISO/IEC 27001 Audit
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
illegal activity reportingcertification body notificationauditor obligationsaudit ethics - Question #325Conducting an ISO/IEC 27001 Audit
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
verbal evidencewritten confirmationaudit evidence typestop management interviews - Question #326Conducting an ISO/IEC 27001 Audit
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
auditor confidentialityaudit report ethicsevidence handlingprofessional conduct - Question #327Conducting an ISO/IEC 27001 Audit
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
auditor diligencesampling methodsemployment contractsaudit judgment - Question #328Conducting an ISO/IEC 27001 Audit
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
audit evidence typesverbal evidencedocumentary evidenceevidence classification - Question #329Initiating an ISO/IEC 27001 Audit
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
audit typessecond-party auditsupplier auditoutsourced services - Question #330Conducting an ISO/IEC 27001 Audit
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
professional skepticismauditing principlesaudit conductISO 19011 - Question #331Managing an ISO/IEC 27001 Audit Program
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
outsourced servicessupplier responsibilityISMS scopeservice monitoring - Question #332Initiating an ISO/IEC 27001 Audit
Prior to initiating the audit activities, the auditors considered the auditee's context, critical processes, and expectations. Which auditing principle has been applied?
due professional careauditing principlesaudit planningauditee context - Question #333Conducting an ISO/IEC 27001 Audit
What is the main difference between qualitative and quantitative evidence?
qualitative evidencequantitative evidenceaudit evidence typescontrol compliance - Question #334Managing an ISO/IEC 27001 Audit Program
Finnco, a subsidiary of a certification body, provided ISMS consultancy services to an organization. Considering this scenario, when can the certification body certify the organiza...
certification body independenceconsulting conflict of interestISO/IEC 17021impartiality - Question #335Conducting an ISO/IEC 27001 Audit
How does predictive analytics help auditors in identifying potential risks?
predictive analyticsrisk identificationaudit techniquesdata analysis - Question #336Conducting an ISO/IEC 27001 Audit
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
Stage 1 audit outputsdocumented evidenceaudit documentationnonconformity reporting - Question #337Conducting an ISO/IEC 27001 Audit
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
Stage 1 to Stage 2 transitionSoA modificationsmajor nonconformityISMS policy changes - Question #338Managing an ISO/IEC 27001 Audit Program
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
technical expert objectivityauditor skepticismaudit team managementimpartiality - Question #339Conducting an ISO/IEC 27001 Audit
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
interview objectivesaudit evidence collectionmanagement system validationISMS audit - Question #340Conducting an ISO/IEC 27001 Audit
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
documented informationdocument control proceduresISO/IEC 27001 clause 7.5ISMS documentation - Question #341Audit Procedures and Techniques
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
audit simulationtechnical testingcontrol verificationauditor competence - Question #342Audit Procedures and Techniques
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
audit evidencecorroborationinformation gatheringaudit techniques - Question #343Audit Procedures and Techniques
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
technical verificationCAATaudit techniquescontrol testing - Question #344Audit Planning and Execution
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
virtual auditdocument handlingaudit permissionsremote audit protocols - Question #345Audit Reporting
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
audit reportingaudit scopeorganizational unitsaudit findings - Question #346Audit Findings and Conclusions
As an auditor, you have noticed that ABC Inc. has established a procedure to manage removable storage media. The procedure is based on the classification scheme adopted by ABC Inc....
audit findingsconformityinformation classificationmedia controls - Question #347Audit Procedures and Techniques
EquiBank is undergoing an external audit of its financial management system. The auditors evaluate the logic of transactions processed by EquiBank's financial software. To ensure a...
CAATdata testaudit softwarefinancial controls - Question #348Audit Planning and Execution
What is the purpose of using a combination of audit test plans?
audit test plansaudit methodscompliance verificationaudit procedures - Question #349Audit Planning and Execution
Which type of audit requires that the auditee and audit team agree on remote access protocols before conducting the audit?
virtual auditremote accessaudit typesaudit protocols - Question #350Audit Planning and Execution
What is the purpose of audit test plans in the audit process?
audit test plansaudit proceduresobservationinterviews - Question #351Audit Procedures and Techniques
What type of sampling was used when the auditor used probability-based sampling for event log reviews?
statistical samplingprobability samplingaudit samplingevent log review - Question #352Audit Planning and Execution
Which option below is correct about the audit plan?
audit planaudit flexibilityaudit planningplan modifications - Question #353Audit Findings and Conclusions
Which of the following can be considered a minor nonconformity?
minor nonconformitynonconformity classificationISMS policyaudit findings