LEAD-AUDITOR Exam Questions
392 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 2 of 8.
- Question #51ISMS Framework – Plan-Do-Check-Act Model
Which two of the following phrases would apply to "plan" in relation to the Plan-Do-Check-Act cycle for a business process?
PDCA cyclePlan phasemanagement system objectivescontinual improvement - Question #52Audit Types and Objectives – First-Party Audit
Which two of the following phrases are 'objectives' in relation to a first-party audit?
first-party auditaudit objectivesinternal auditmanagement system scope - Question #53Certification Audit Process – Stage 1 Purpose
Which one of the following options describes the main purpose of a Stage 1 audit?
Stage 1 auditcertification readinessinitial certification auditaudit stages - Question #54Audit Objectives, Criteria, and Scope – Third-Party Audit
Objectives, criteria, and scope are critical features of a third-party ISMS audit. Which two issues are audit objectives?
audit objectivesthird-party auditISO 27001 conformityISMS scope - Question #55Audit Methods and Techniques
Which two of the following are examples of audit methods that 'do not' involve human interaction?
audit methodsremote audit techniquesdocument reviewnon-interactive audit methods - Question #56Audit Tools and Techniques – Checklists
Select two options that describe an advantage of using a checklist.
audit checklistaudit planningaudit trailaudit plan implementation - Question #57Audit Methods – Document and Record Review
Which one of the following statements best describes the purpose of conducting a document review?
document reviewaudit criteriamanagement system documentationconformity determination - Question #58Audit Scope Management and Certification Body Procedures
During a Stage 1 audit opening meeting, the Management System Representative (MSR) asks to extend the audit scope to include a new site overseas which they have expanded into since...
audit scope extensionStage 1 auditcertification body processscope change management - Question #59Remote and Virtual Audit Procedures
You have to carry out a third-party virtual audit. Which two of the following issues would you need to inform the auditee about before you start conducting the audit ?
virtual auditremote auditauditee notificationonline audit conduct - Question #60Information Security Controls – Nonconformity Assessment and Audit Judgment
You ask the IT Manager why the organisation still uses the mobile app while personal data encryption and pseudonymisation tests failed. Also, whether the Service Manager is authori...
software security testingnonconformity determinationacceptance testingsecurity procedure compliance - Question #61Operations - Secure Development and Support
You ask the IT Manager why the organisation still uses the mobile app while personal data encryption and pseudonymization tests failed. Also, whether the Service Manager is authori...
software security managementencryptionpseudonymizationnonconformity identification - Question #62Context of the Organization
During a third-party certification audit, you are presented with a list of issues by an auditee. Which four of the following constitute 'internal' issues in the context of a manage...
internal issuesexternal issuescontext of organizationISO 27001 clause 4 - Question #63Planning - Information Security Risk Management
You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee's knowledge of ISO/IEC 27001's risk manage...
risk assessmentrisk treatment planrisk managementISO 27001 clause 6 - Question #64Context of the Organization - ISMS Scope
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for mo...
ISMS scopeinterested partiesexternal providershealthcare data protection - Question #65Supplier Relationships - Audit of External Providers
You are an experienced ISMS audit team leader providing guidance to an ISMS auditor in training. They have been asked to carry out an assessment of external providers and have prep...
external providerssupplier auditthird-party surveillanceaudit checklist - Question #66Audit Conduct - Collecting and Verifying Audit Evidence
You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer re...
audit findingsasset managementinformation security incidentphysical security - Question #67Compliance and Continual Improvement
You are performing an ISMS audit at a residential nursing home railed ABC that provides healthcare services. The next step in your audit plan is to verify the effectiveness of the...
personal data protectioncorrective actioncontinual improvementregulatory compliance - Question #68Follow-up Audit
You are an ISMS audit team leader who has been assigned by your certification body to carry out a follow-up audit of a client. You are preparing your audit plan for this audit. Whi...
follow-up auditcorrective action verificationaudit planningnonconformity closure - Question #69Follow-up Audit - Managing Unresolved Nonconformities
During a follow-up audit, you notice that a nonconformity identified for completion before the follow-up audit is still outstanding. Which four of the following actions should you...
outstanding nonconformityfollow-up auditcorrective actionaudit programme management - Question #70Corrective Action and Supplier Relationships
You are performing an ISO 27001 ISMS surveillance audit at a residential nursing home, ABC Healthcare Services. ABC uses a healthcare mobile app designed and maintained by a suppli...
corrective action evidencesupplier managementpersonal data breachaudit evidence - Question #71Context of the Organization - Interested Parties
Which one of the following options is the definition of an interested party?
interested partyISO 27001 terminologystakeholder definition - Question #72ISMS Fundamentals
Which two of the following statements are true?
ISMS purposerisk managementcertification benefitsinformation security - Question #73ISMS Fundamentals - Plan-Do-Check-Act
Which two of the following phrases would apply to 'check' in the Plan-Do-Check-Act cycle for a business process?
PDCA cyclecheck phaseperformance evaluationcontinual improvement - Question #74Audit Programme Management
Which two of the following actions are the individual(s) managing the audit programme responsible for?
audit programme managementaudit resourcesaccreditation bodyroles and responsibilities - Question #75Audit Planning - Team Selection
You are the person responsible for managing the audit programme and deciding the size and composition of the audit team for a specific audit. Select the two factors that should be...
audit team compositionaudit scopeteam competenceaudit planning - Question #76Audit Team Roles - Technical Experts
Select two of the following options that are the responsibility of a legal technical expert on the audit team during a certification audit.
technical expertlegal complianceaudit team rolescertification audit - Question #77Audit Planning - Certification Audit
The audit team leader prepares the audit plan for an initial certification stage 2 audit to ISO/IEC 27001:2022. Which one of the following statements is true?
audit planstage 2 certification auditinitial certificationaudit preparation - Question #78Operations - Secure Development and Supplier Management
You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next step in your audit plan is to verify the information security of AB...
software development outsourcingsecurity testingacceptance testingnonconformity identification - Question #79ISO 27001 Annex A - People Controls
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
people controlsAnnex A controlsStatement of Applicabilitysecurity awareness and training - Question #80Planning - Information Security Objectives
You are an audit team leader conducting a third-party surveillance audit of a telecom services provider. You have assigned responsibility for auditing the organisation's informatio...
information security objectivesdocumented informationIS policy alignmentISO 27001 clause 6.2 - Question #81ISMS Scope and Context
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for mo...
ISMS scopeISO 27001 clausesinterested partiesorganizational context - Question #82Information Security Controls Audit
You are performing an ISMS audit at a residential nursing home that provides healthcare services and are reviewing the Software Code Management (SCM) system. You found a total of 1...
access controluser deregistrationaudit evidenceSCM security - Question #83Information Security Controls Audit
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify that the Statement of Applicability...
Statement of Applicabilityaccess controlnonconformity identificationsource code security - Question #84Physical and Environmental Security Audit
You are a certification body auditor, conducting a surveillance audit to ISO/IEC 27001:2022 of a data centre operated by a client who provides hosting services for ICT facilities....
physical securitydata cabinetCCTV monitoringaudit findings - Question #85Audit Management and Planning
You are an experienced ISMS audit team leader who is currently conducting a third party initial certification audit of a new client, using ISO/IEC 27001:2022 as your criteria. It i...
certification auditaudit team managementleadership assessmentaudit reporting - Question #86Audit Principles and Terminology
You are an experienced ISMS audit team leader providing guidance to an auditor in training. She asks you why it is important to have specific criteria relating to the grading of no...
nonconformity gradingaudit criteriaauditor guidance - Question #87Audit Follow-up and Corrective Actions
You are an experienced ISMS audit team leader guiding an auditor in training. You decide to test her knowledge of follow-up audits by asking her a series of questions. Here are you...
follow-up auditscorrective actionsaudit processnonconformity closure - Question #88Audit Ethics and Confidentiality
You are an audit team leader who has just completed a third-party audit of a mobile telecommunication provider. You are preparing your audit report and are just about to complete a...
audit confidentialityreport disclosurethird-party accessaudit ethics - Question #89Audit Reporting and Nonconformity Management
You are the audit team leader conducting a third-party audit of an online insurance company. During Stage 1, you found that the organization took a very cautious risk approach and...
nonconformity managementclosing meetingrisk treatment planStatement of Applicability - Question #90Supplier Relationships and Privacy
You are performing an ISO 27001 ISMS surveillance audit at a residential nursing home, ABC Healthcare Services. ABC uses a healthcare mobile app designed and maintained by a suppli...
supplier managementpersonal data protectionservice agreementprivacy controls - Question #91Information Security Controls
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospit...
information labelingPII protectionsecurity awareness traininglogistics security - Question #92Audit Principles and Terminology
What is meant by the term 'Corrective Action'? Select one
corrective actionnonconformityaudit terminology - Question #93Audit Types and Roles
Which two of the following options do not participate in a first-party audit?
first-party auditaudit typesaudit participantsaudit roles - Question #94Management System Concepts
Which two of the following phrases would apply to "act" in relation to the Plan-Do-Check-Act cycle for a business process?
PDCA cycleAct phasecontinual improvementmanagement system - Question #95Auditor Competence and Personal Attributes
During an audit, the audit team leader reached timely conclusions based on logical reasoning and analysis. What professional behaviour was displayed by the audit team leader?
auditor competenceprofessional behaviordecisiveaudit conduct - Question #96Audit Methods and Techniques
Audit methods can be either with or without interaction with individuals representing the auditee. Which two of the following methods are with interaction?
audit methodsinteraction methodsinterviewsaudit techniques - Question #97Audit Planning and Sampling
Which two of the following options are an advantage of using a sampling plan for the audit?
sampling planaudit efficiencyaudit confidenceaudit planning - Question #98Audit Reporting and Nonconformity Management
You are an experienced ISMS audit team leader conducting a third-party surveillance visit. You notice that although the auditee is claiming conformity with ISO/IEC 27001:2022 they...
ISO 27001:2022opportunity for improvementclause referencedocumented information - Question #99Physical and Environmental Security Audit
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
physical controlsSoA reviewdata center securityequipment maintenance - Question #100ISMS Documentation and Compliance
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organ...
Statement of ApplicabilityAnnex A controlsISO 27001 requirementsjustification