nerdexam
PECB

LEAD-AUDITOR · Question #348

Drag and Drop Question Select the words that best complete the sentence below to describe a third-party audit plan. To complete the sentence with the best word(s), click on the blank section you want

The correct answer is assess; recommendation. Third-Party Audit Plan - Drag-and-Drop Explanation The sentence almost certainly reads: > "A third-party audit plan is designed to [assess] [the organization/controls/processes] and provide a [recommendation]." --- Placement 1: assess Why "assess" fits here: An audit's core purpo

Preparing an ISO/IEC 27001 Audit

Question

Drag and Drop Question Select the words that best complete the sentence below to describe a third-party audit plan. To complete the sentence with the best word(s), click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. Answer:

Exhibit

LEAD-AUDITOR question #348 exhibit

Answer Area

Drag items

Recommendationpermitreportassessinspectquestion

Correct arrangement

  • assess
  • recommendation

Explanation

Third-Party Audit Plan - Drag-and-Drop Explanation

The sentence almost certainly reads:

"A third-party audit plan is designed to [assess] [the organization/controls/processes] and provide a [recommendation]."


Placement 1: assess

Why "assess" fits here: An audit's core purpose is evaluation - systematically measuring controls, processes, or compliance against a standard. "Assess" is the precise audit term for this activity (e.g., risk assessment, control assessment).

Why the alternatives fail:

WordWhy it's wrong
inspectToo narrow - implies physical/visual checking, not holistic evaluation
questionInterviews are one tool within an audit, not its overall purpose
permitCompletely wrong context - permits are authorizations, not audit functions
reportA report is the output, not the action being performed

Placement 2: recommendation

Why "recommendation" fits here: A third-party audit concludes with actionable guidance - findings are meaningless without telling the client what to do next. "Recommendation" is the standard term for this deliverable in audit frameworks (ISO 27001, SOC 2, etc.).

Why "report" is the common mistake: Audits do produce reports, but a report is the container - the recommendation is the valuable output the plan is designed to deliver. The question asks what describes the purpose, not the document format.


Key Takeaway

Think of a third-party audit as a two-step process:

  1. Assess → gather evidence and evaluate current state
  2. Recommend → provide actionable guidance based on findings

Topics

#third-party audit#audit objectives#audit plan#certification audit

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice