nerdexam
PECB

LEAD-AUDITOR · Question #144

You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external cl

The correct answer is B. How access to source code and development tools are managed D. How protection against malware is implemented E. How the organisation evaluates its exposure to technical vulnerabilities G. The organisation's arrangements for information deletion. You've hit your limit · resets 4am (America/New_York)

Audit Execution

Question

You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on behalf of external clients. The auditor in training has been tasked with reviewing the TECHNOLOGICAL controls listed in the Statement of Applicability (SoA) and implemented at the site. Select four controls from the following that would you expect the auditor in training to review.

Options

  • AConfidentiality and nondisclosure agreements
  • BHow access to source code and development tools are managed
  • CHow power and data cables enter the building
  • DHow protection against malware is implemented
  • EHow the organisation evaluates its exposure to technical vulnerabilities
  • FInformation security awareness, education and training
  • GThe organisation's arrangements for information deletion
  • HThe organisation's business continuity arrangements

How the community answered

(53 responses)
  • A
    2% (1)
  • B
    94% (50)
  • C
    2% (1)
  • H
    2% (1)

Explanation

You've hit your limit · resets 4am (America/New_York)

Topics

#technological controls#ISO 27002#Statement of Applicability#access control

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice