LEAD-AUDITOR Exam Questions
392 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 1 of 8.
- Question #1Information Classification
What is the difference between a restricted and confidential document?
document classificationdata sensitivityrestricted vs confidentialinformation handling - Question #2Information Classification
CEO sends a mail giving his views on the status of the company and the company's future strategy and the CEO's vision and the employee's part in it. The mail should be classified a...
data classificationinternal communicationemail classificationinformation sensitivity - Question #3Asset Management
You see a blue color sticker on certain physical assets. What does this signify?
asset classificationasset labelingcriticality levelsphysical asset management - Question #4Information Security Concepts
Integrity of data means
data integrityCIA triadaccuracy and completenessinformation security fundamentals - Question #5Asset Management
You have a hard copy of a customer design document that you want to dispose off. What would you do
secure disposaldocument destructionphysical securityinformation handling - Question #6Incident Management and Response
You receive the following mail from the IT support team: Dear User,Starting next week, we will be deleting all inactive email accounts in order to create spaceshare the below detai...
phishingsocial engineeringincident reportingsecurity awareness - Question #7Information Security Concepts
The following are definitions of Information, except:
information definitiondata vs informationknowledge managementinformation concepts - Question #8Incident Management and Response
In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:
incident managementroles and responsibilitiesevidence preservationsecurity incidents - Question #9ISMS Fundamentals
What is the standard definition of ISMS?
ISMSISO 27001information security management systemsystematic approach - Question #10Access Control and Acceptable Use
All are prohibited in acceptable use of information assets, except:
acceptable use policyemail policyinformation assetsprohibited activities - Question #11Access Control and Acceptable Use
In acceptable use of Information Assets, which is the best practice?
acceptable use policybusiness purposeinformation systemsuser responsibilities - Question #12Quality and Process Management
CMM stands for?
CMMCapability Maturity Modelprocess maturityquality management - Question #13Human Resource Security
Which is not a requirement of HR prior to hiring?
HR securitypre-employment screeningbackground verificationhiring process - Question #14Access Control and Acceptable Use
Who are allowed to access highly confidential files?
access controlneed-to-know principleconfidential informationauthorization - Question #15Information Security Concepts
Which is the glue that ties the triad together
CIA triadsecurity componentstechnologyinformation security framework - Question #16ISMS Continual Improvement
Implement plan on a test basis - this comes under which section of PDCA
PDCA cycleDo phaseISMS implementationpilot testing - Question #17ISMS Continual Improvement
What is we do in ACT - From PDCA cycle
PDCA cycleAct phasecontinual improvementprocess performance - Question #18Asset Management
-------------------------is an asset like other important business assets has value to an organization and consequently needs to be protected.
information assetasset valueinformation protectionISO 27001 - Question #19Information Security Concepts
Below is Purpose of "Integrity", which is one of the Basic Components of Information Security
integrityCIA triadaccuracy and completenessinformation security fundamentals - Question #20Audit Principles and Processes
Which one of the following options best describes the main purpose of a Stage 1 third-party audit?
Stage 1 auditthird-party auditaudit readinessISO 27001 certification audit - Question #21Audit Types and Roles
Which two of the following statements are true?
certification body auditthird-party auditauditor responsibilitiesaudit types - Question #22Managing an Audit Programme
Which two activities align with the "Check'' stage of the Plan-Do-Check-Act cycle when applied to the process of managing an internal audit program as described in ISO 19011?
PDCA cycleaudit programme managementISO 19011internal audit - Question #23Audit Methods and Techniques
Which two of the following are examples of audit methods that 'do' involve human interaction?
audit methodshuman interactionremote auditaudit techniques - Question #24Audit Principles and Ethics
In the context of a third-party certification audit, confidentiality is an issue in an audit programme. Select two options which correctly state the function of confidentiality in...
audit confidentialityaudit principlesthird-party certification auditrecording equipment - Question #25Audit Objectives, Scope and Criteria
Which three of the following phrases are objectives' in relation to an audit?
audit objectivesimprovement opportunitiesaudit scoperegulatory requirements - Question #26Managing an Audit Programme
Which six of the following actions are the individual(s) managing the audit programme responsible for?
audit programme managementaudit programme responsibilitiesaudit team selectionISO 19011 - Question #27Audit Preparation and Planning
Which three of the following work documents are not required for audit planning by an auditor conducting a certification audit?
audit planningaudit documentationcertification auditwork documents - Question #28Audit Preparation and Planning
Which three of the following options are an advantage of using a sampling plan for the audit?
audit samplingsampling planISMS auditaudit planning - Question #29Certification Audit Process
After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include...
certification audit stagesaudit scope extensionStage 1 auditscope change - Question #30Managing an Audit Programme
During discussions with the individual(s) managing the audit programme of a certification body, the Management System Representative of the client organisation asks for a specific...
audit team selectionauditor independencecertification bodyaudit programme management - Question #31Audit Conduct
During an opening meeting of a Stage 2 audit, the Managing Director of the client organisation invites the audit team to view a new company video lasting 45 minutes. Which two of t...
audit opening meetingaudit scheduleStage 2 auditaudit team leader - Question #32ISO/IEC 27001 Requirements
You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before...
ISO 27001 Clause 8.1operational planning and controlISMS surveillance auditdocumented information - Question #33ISO/IEC 27001 Context and Scope
During a third-party certification audit you are presented with a list of issues by an auditee. Which four of the following constitute 'external' issues in the context of a managem...
ISO 27001 Clause 4.1external issuescontext of the organizationISMS - Question #34ISMS Audit - Incident Management
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementISO 27001 Clause 6.6audit evidence collectionhealthcare ISMS - Question #35ISO/IEC 27001 Controls
You are an experienced audit team leader guiding an auditor in training, Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
ISO 27001 Annex Atechnological controlsStatement of ApplicabilityISMS controls - Question #36Audit Findings and Reporting
You are preparing the audit findings. Select two options that are correct.
audit findingsnonconformityopportunity for improvementaudit reporting - Question #37ISO/IEC 27001 Planning Requirements
You are an experienced ISMS auditor, currently providing support to an ISMS auditor in training who is carrying out her first initial certification audit. She asks you what she sho...
ISO 27001 Clause 6.2information security objectivesaudit checklistISMS planning - Question #38Information Security Incident Management
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team....
information security incidentsinformation security eventsincident classificationISO 27035 - Question #39ISMS Audit - Policy and Controls
You are performing an ISMS audit at a nursing home where residents always wear an electronic wristband for monitoring their location, heartbeat, and blood pressure. The wristband a...
mobile device policyISMS policy verificationaudit evidenceISO 27001 Annex A - Question #40Internal Audit and Management Review
The data center at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit a number of internal audits have been ca...
internal audit programmeISO 27001 Clause 9.2audit programme conformityaudit programme review - Question #41ISO/IEC 27001 Annex A Controls – Information Security Controls Auditing
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
threat intelligenceISO 27001:2022 new controlsAnnex A 5.7surveillance audit - Question #42Business Continuity and ISMS Audit Evidence Collection
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security of the busi...
business continuity managementBCP testingISMS audit evidenceinformation security during disruption - Question #43Physical and Environmental Security – Audit Findings and Nonconformity Grading
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team....
physical entry controlscontractor access managementsecure areasnonconformity classification - Question #44Audit Reporting and Certification Recommendation
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing m...
closing meetingminor nonconformitycertification recommendationcorrective action plan - Question #45Audit Follow-up and Corrective Action Verification
You are an ISMS audit team leader tasked with conducting a follow-up audit at a client's data centre. Following two days on-site you conclude that of the original 12 minor and 1 ma...
follow-up auditnonconformity resolutionaudit programme managementcertification status - Question #46Audit Closing Meeting Planning and Conduct
You are an experienced ISMS audit team leader guiding an auditor in training. Your team has just completed a third-party surveillance audit of a mobile telecom provider. The audito...
closing meeting preparationaudit team leaderaudit conclusionssurveillance audit - Question #47Audit Process – Follow-up Audit Rules and Outcomes
You are an experienced ISMS audit team leader guiding an auditor in training. You are testing her understanding of follow-up audits by asking her a series of questions to which the...
follow-up audit proceduresnonconformity typesaudit outcomesaudit programme reporting - Question #48ISO/IEC 27001 Annex A Controls Mapping to Audit Scenarios
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospit...
data leakage protectioninformation labellingstorage mediaaccess restriction - Question #49Auditor Conduct, Ethics, and Nonconformity Management
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospit...
nonconformity disputeauditor conductaudit evidence integrityaudit ethics - Question #50ISMS Fundamentals and Purpose
Which two of the following statements are true?
ISMS purposerisk managementcertification benefitsinformation security objectives