LEAD-AUDITOR Exam Questions
392 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 3 of 8.
- Question #101Risk Assessment and Treatment
You are an experienced ISMS audit team leader conducting a third-party surveillance audit of an internet services provider. You are reviewing the organization's risk assessment pro...
risk assessmentnonconformity identificationISO 27001:2022risk criteria - Question #102Information Security Incident Management
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementnonconformity reportingresidual risk acceptancerisk treatment plan - Question #103Physical and Environmental Security
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team....
physical securityaccess controlcontractor managementsecure areas - Question #104Audit Management
You are an ISMS audit team leader assigned by your certification body to carry out a follow-up audit of a Data Centre client. According to ISO 19011:2018, the purpose of a follow-u...
follow-up auditISO 19011:2018corrective actionsaudit types - Question #105Audit Reporting and Follow-up
You are an experienced ISMS audit team leader guiding an auditor in training. She asks you about the grading of nonconformities in audit reports. You decide to test her knowledge b...
nonconformity gradingmajor nonconformityminor nonconformityaudit reporting - Question #106Audit Reporting
Which two of the following are valid audit conclusions?
audit conclusionsaudit findingsISMS conformityaudit terminology - Question #107Risk Assessment and Treatment
You are the audit team leader conducting a third-party audit of an online insurance organisation. During Stage 1, you found that the organisation took a very cautious risk approach...
Statement of Applicabilityrisk treatmentcontrols implementationAnnex A - Question #108Context of the Organization
Which one of the following options is the definition of the context of an organisation?
organizational contextISO 27001 clause 4internal external issuesISMS scope - Question #109Audit Planning
Which two of the following phrases would apply to "audit objectives"?
audit objectivesconformity assessmentaudit planningopportunities for improvement - Question #110Auditor Competence
Auditor competence is a combination of knowledge and skills. Which two of the following activities are predominately related to "knowledge"?
auditor competenceknowledge vs skillschecklist designevidence gathering - Question #111Audit Conduct
Review the following statements and determine which two are false:
virtual auditsaudit methodsauditor trainingaudit day calculation - Question #112Risk Assessment and Treatment
You are an experienced audit team leader conducting a third-party surveillance audit of an organisation that designs websites for its clients. You are currently reviewing the organ...
Statement of ApplicabilityAnnex A controlsISO 27001 requirementsSoA ownership - Question #113Support - Competence
You are an experienced ISMS audit team leader providing guidance to an auditor in training. The auditor in training appears to be confused about the interpretation of competence in...
competenceISO 27001 clause 7.2training and awarenesspersonnel competence - Question #114Information Security Fundamentals
You are an experienced ISMS audit team leader. You are providing an introduction to ISO/IEC 27001:2022 to a class of Quality Management System Auditors who are seeking to retrain t...
CIA triadconfidentiality integrity availabilityISMS objectivesinformation security fundamentals - Question #115Information Security Controls
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
threat intelligenceISO 27001:2022 control 5.7new controls 2022audit checklist - Question #116Audit Conduct
You are an ISMS audit team leader preparing to chair a closing meeting following a third-party surveillance audit. You are drafting a closing meeting agenda setting out the topics...
closing meetingaudit conductsampling disclaimeraudit reporting - Question #117Audit Reporting
Which four of the following statements about audit reports are true?
audit reportsaudit documentationreport contentconfidentiality - Question #118Auditor Competence
Auditors should have certain knowledge and skills; while audit team leaders should have some additional knowledge and skills. From the following list, select two that only apply to...
audit team leaderauditor competenceresource managementaudit planning - Question #119Audit Ethics and Conduct
An auditor of organisation A performs an audit of supplier B. Which two of the following actions is likely to represent a breach of confidentiality by the auditor after having iden...
auditor confidentialityaudit ethicssupplier auditfindings disclosure - Question #120Audit Planning
Which two of the following options for information are not required for audit planning of a certification audit?
audit planningcertification auditaudit documentationrequired information - Question #121Conducting the Audit / Physical and Environmental Security
You are carrying out a third-party surveillance audit of a client's ISMS. You are currently in the secure storage area of the data centre where the organisation's customers are abl...
physical securityrisk treatmentincident managementbusiness continuity - Question #122Audit Types and Objectives
Which one of the following options best describes the main purpose of a Stage 2 third-party audit?
Stage 2 auditcertification auditaudit purposenonconformances - Question #123Audit Planning and Programme Management
Which two of the following statements are true?
audit programmeaudit planaudit definitionsISO 19011 - Question #124Audit Evidence and Findings
An audit finding is the result of the evaluation of the collected audit evidence against audit criteria. Evaluate the following potential formats of audit evidence and select the t...
audit evidenceevidence formatsaudit findingsdocumented information - Question #125Audit Criteria and Standards
Which two of the following standards are used as ISMS third-party certification audit criteria?
ISO/IEC 27001audit criteriacertification standardslegal requirements - Question #126Conducting the Audit / Supplier Relationships
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the information security...
outsourced developmentsupply chain securitypersonal data handlingevidence collection - Question #127Auditing ISMS Controls (ISO/IEC 27001:2022)
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation's ap...
threat intelligenceISO/IEC 27001:2022ISMS controlsaudit checklist - Question #128Conducting the Audit / Asset Management
You are carrying out your first third-party ISMS surveillance audit as an audit team leader. You are presently in the auditee's data centre with another member of your audit team a...
storage media disposalphysical securityasset lifecycleaudit trail - Question #129Audit Follow-up and Corrective Actions
You are an ISMS audit team leader tasked with conducting a follow-up audit at a client's data centre. Following two days on-site you conclude that of the original 12 minor and 1 ma...
follow-up auditnonconformity closurecorrective actionsaudit programme management - Question #130Audit Planning and Scope Management
After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include...
audit scopeStage 2 auditscope changeaudit programme management - Question #131Audit Methods and Planning
Review the following statements and determine which two are false:
virtual auditremote auditaudit methodsaudit duration - Question #132Audit Findings and Nonconformities
You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next step in your audit plan is to verify the information security of AB...
nonconformity identificationoutsourced servicessoftware securitycompliance - Question #133Auditing ISMS Controls (ISO/IEC 27001:2022)
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
organizational controlsStatement of ApplicabilityISO 27001:2022 control categoriesISMS audit - Question #134Audit Findings and Corrective Actions
An audit team leader is planning a follow-up audit after the completion of a third-party surveillance audit earlier in the year. They have decided they will verify the nonconformit...
correctionscorrective actionsnonconformityfollow-up audit - Question #135Certification and Accreditation Benefits
Which two options are benefits of third-party accredited certification of information security management systems to ISO/IEC 27001:2022 for organisations and interested parties?
accredited certificationISO/IEC 27001:2022certification benefitsISMS - Question #136Certification and Accreditation Benefits
An organisation has ISO/IEC 27001 Information Security Management System (ISMS) certification from a third-party certification body. Which one of the following represents an advant...
accredited certificationISO 27001credibilitycertification body - Question #137ISMS Documentation Requirements
Which one option best describes the purpose of retaining documented information related to the Information Security Management System (ISMS) of an organisation?
documented informationISMSISO 27001process evidence - Question #138Audit Communication and Reporting
In the context of a third-party certification audit, it is very important to have effective communication. Select an option that contains the correct answer about communication in...
audit communicationaudit team leaderformal communication channelsaudit process - Question #139Audit Types and Objectives
Which one of the following options best describes the purpose of a Stage 2 audit?
Stage 2 auditmanagement system evaluationaudit purposeimplementation - Question #140Audit Team Management and Leadership
In the context of a third-party certification audit, which two options state the management responsibilities of the audit team leader in managing the audit and the audit team?
audit team leaderaudit management responsibilitiesrisk-based approachauditee contact - Question #141Audit Reporting and Follow-up
Which one of the following conclusions in the audit report is not required by the certification body when deciding to grant certification?
certification auditnonconformityaudit reportISO 27001 - Question #142ISMS Scope and Context
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for mo...
ISMS scopeoutsourced servicescloud computinghealthcare data - Question #143Audit Execution
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
people controlsISO 27002Statement of Applicabilitypersonnel security - Question #144Audit Execution
You are an experienced audit team leader guiding an auditor in training. Your team is currently conducting a third-party surveillance audit of an organisation that stores data on b...
technological controlsISO 27002Statement of Applicabilityaccess control - Question #145Internal Audit Management
The data centre at which you work is currently seeking ISO/IEC27001:2022 certification. In preparation for your initial certification visit, several internal audits have been carri...
internal auditaudit programmeISO 27001 Clause 9.2conformity - Question #146Audit Findings and Nonconformities
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementISO 27035nonconformity classificationaudit findings - Question #147Audit Execution and Reporting
You are an experience ISMS audit team leader carrying out a third-party certification audit of an organization specialising in the secure disposal of confidential documents and rem...
audit team leaderclosing meetingaudit integritynonconformity - Question #148Audit Execution
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security of the busi...
business continuityinformation security controlsISO 27001 Annex Amobile devices - Question #149Audit Findings and Nonconformities
You are conducting an Information Security Management System audit in the despatch department of an international logistics organisation that provides shipping services to large or...
process effectivenessoperational controlsaudit findingslogistics security - Question #150Audit Principles and Methodology
Select the option which best describes how Information Security Management System audits should be conducted:
audit methodologyobjective evidenceaudit findingsISO 19011