PECB
LEAD-AUDITOR · Question #198
The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?
The correct answer is C. Detection. Detection risk refers to the risk that the auditor will not detect a material misstatement or significant issue within the organization's ISMS. In this case, the auditor's inability to identify Company A's insecure network architecture is a detection risk.
Conducting an ISO/IEC 27001 Audit
Question
The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?
Options
- AInherent
- BControl
- CDetection
How the community answered
(28 responses)- A4% (1)
- B4% (1)
- C93% (26)
Explanation
Detection risk refers to the risk that the auditor will not detect a material misstatement or significant issue within the organization's ISMS. In this case, the auditor's inability to identify Company A's insecure network architecture is a detection risk.
Topics
#detection risk#audit risk#risk types#audit limitations
Community Discussion
No community discussion yet for this question.