LEAD-AUDITOR Exam Questions
392 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 4 of 8.
- Question #151Audit Principles and Methodology
The purpose of a management system audit is to? Select 1
management system auditaudit purposeISO 19011 - Question #152Audit Planning and Preparation
When preparing for an audit, which of the following statements is false?
audit preparationaudit checklistauditee communicationISO 19011 - Question #153Audit Findings and Nonconformities
You are an ISMS auditor conducting a third-party surveillance audit of a telecom's provider. You are in the equipment staging room where network switches are pre-programmed before...
operational planningdocumented informationISMS clause mappingnonconformity - Question #154Audit Execution
You are carrying out your first third-party ISMS surveillance audit as an audit team leader. You are presently in the auditee's data centre with another member of your audit team a...
physical securitysupporting utilitiesfire suppressionAnnex A controls - Question #155Audit Execution
You are an experienced ISMS auditor conducting a third-party surveillance audit at an organisation which offers ICT reclamation services. ICT equipment which companies no longer re...
ICT disposalinformation classificationaudit findingsincident management - Question #156Internal Audit Management
You are an experienced ISMS audit team leader. You are currently conducting a third-party surveillance audit of an international haulage organisation. You have sampled four interna...
nonconformity gradingcorrective actioninternal audit reportsaudit quality - Question #157Audit Findings and Nonconformities
As the Information Security Management System audit team leader, you are conducting a second- party audit of an international logistics company on behalf of an online retailer. Dur...
access rightsISO 27001 Annex A 5.18nonconformity classificationsecond-party audit - Question #158Information Security Concepts and Emerging Technologies
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
machine learningAI technologyfraud detectioninformation security - Question #159Information Security Concepts and Risk Management
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
vulnerabilityrisk conceptsthreat vs vulnerabilityinformation security - Question #160Information Security Concepts and Risk Management
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
data integrityCIA triadinformation security principlesPII protection - Question #161Information Security Controls
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
control typespreventive controlstechnical controlsinformation security controls - Question #162Information Security Risk Management
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers service...
risk impactreputation riskbusiness impactinformation security risk - Question #163Information Security Concepts
Which situation presented below represents a threat?
threat identificationthreat vs vulnerabilityunauthorized accesspassword compromise - Question #164Information Security Concepts
An organization does not check the source code of the updated version of an application when it is updated automatically. Thus, the application may be open to unauthorized modifica...
vulnerabilityintegrityCIA triadrisk concepts - Question #165Information Security Controls
A telecommunications company uses the AES method for ensuring that confidential information is protected. This means that they use a single key to encrypt and decrypt the informati...
symmetric encryptionAESpreventive controlscryptography - Question #166Information Security Threats
You received an email requiring you to send information such as name, email, and password in order to continue using your email account. If you do not send such information, your e...
phishingsocial engineeringthreat typesunauthorized action - Question #167Information Security Concepts
Which statement below best describes the relationship between information security aspects?
threat-vulnerability relationshipassetsrisk modelinformation security concepts - Question #168Information Security Controls
Which of the options below is a control related to the management of personnel that aims to avoid the occurrence of incidents?
personnel securitysecurity awareness trainingpreventive controlshuman resources security - Question #169Vulnerability Management
A data processing tool crashed when a user added more data in the buffer than its storage capacity allows. The incident was caused by the tool's inability to bound check arrays. Wh...
buffer overflowintrinsic vulnerabilitysoftware vulnerabilitiestechnical vulnerabilities - Question #170Information Security Concepts
PayBell, a finance corporation, is using an accounting software to track financial transactions. The software can be accessed from anywhere with an internet connection. It also ena...
cloud computingSaaScloud servicesremote access - Question #171Information Security Risk Assessment
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
vulnerability identificationrisk assessmentISMSscenario analysis - Question #172Information Security Risk Management
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
risk treatmentrisk modificationrisk management optionsISO 27001 - Question #173ISMS Scope and Context
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
ISMS scopeISO 27001scope definitionISMS implementation - Question #174ISO/IEC 27001 Documentation Requirements
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
Statement of ApplicabilitySoAcontrols documentationISO 27001 documentation - Question #175Information Security Risk Management
Scenario 2: Knight is an electronics company from Northern California, US that develops video game consoles. Knight has more than 300 employees worldwide. On the fifth anniversary...
residual riskrisk treatmenttop management approvalrisk acceptance - Question #176ISO/IEC 27001 Risk Assessment
A marketing agency has developed its own risk assessment approach as part of the ISMS implementation. Is this acceptable?
risk assessment methodologyISO 27001 requirementsISMS implementationrisk management - Question #177ISMS Performance Evaluation
ISMS (1)---------------helps determine (2)--------------,
management reviewcontinual improvementISMS performanceISO 27001 - Question #178ISO/IEC 27001 Documentation Requirements
Which option below about the ISMS scope is correct?
ISMS scopedocumented informationISO 27001 requirementsdocumentation - Question #179ISO/IEC 27001 Compliance and Legal Requirements
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
legal complianceISO 27001 requirementsregulatory requirementsinterested parties - Question #180ISMS Audit and Certification
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
audit evidenceevidence typesmathematical evidenceISO 27001 audit - Question #181ISO/IEC 27001 ISMS Controls and Requirements
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
Annex A controlsintellectual property rightsISO 27001 controlsinformation asset management - Question #182Fundamental Audit Concepts and Principles
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
audit principlesauditor ethicsconfidentialityauditor conduct - Question #183Conducting an ISO/IEC 27001 Audit
Scenario 3: NightCore is a multinational technology company based in the United States that focuses on e-commerce, cloud computing, digital streaming, and artificial intelligence....
auditor responsibilitiesfinancial crime reportingaudit ethicsaudit conduct - Question #184ISO/IEC 27001 ISMS Requirements
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
business continuityrecovery plansupplier managementISMS requirements - Question #185Conducting an ISO/IEC 27001 Audit
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
business continuity planningISMS nonconformityoutsourcing riskaudit finding analysis - Question #186Conducting an ISO/IEC 27001 Audit
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
audit evidenceevidence reliabilityverbal evidenceoutsourced operations - Question #187Conducting an ISO/IEC 27001 Audit
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
audit evidencetechnical testingfirewall configurationevidence collection - Question #188Fundamental Audit Concepts and Principles
Scenario 4: SendPay is a financial company that provides its services through a network of agents and financial institutions. One of their main services is transferring money world...
professional skepticismauditor conductevidence evaluationaudit principles - Question #189Conducting an ISO/IEC 27001 Audit
Which is an example of a qualitative evidence?
audit evidence typesqualitative evidenceinterviewsevidence collection - Question #190Fundamental Audit Concepts and Principles
Finnco, a subsidiary of a certification body, provided ISMS consultancy services to an organization. Considering this scenario, when can the certification body certify the organiza...
conflict of interestcertification bodyauditor independenceISMS consultancy - Question #191Managing an ISO/IEC 27001 Audit Program
Which option below is NOT a role of the audit team leader?
audit team leaderaudit rolesaudit team managementaudit responsibilities - Question #192Fundamental Audit Concepts and Principles
How does the use of new technologies such as big data impact auditing?
big dataemerging technologiesaudit challengesdata analysis - Question #193Managing an ISO/IEC 27001 Audit Program
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
certification bodyaudit team appointmentaudit program managementISO 27001 certification - Question #194Planning an ISO/IEC 27001 Audit
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
audit mandateaudit durationauditor rightsaudit planning - Question #195Conducting an ISO/IEC 27001 Audit
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
audit riskcontrol riskrisk typesISMS risk assessment - Question #196Conducting an ISO/IEC 27001 Audit
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
reasonable assuranceaudit conclusionsevidence sufficiencyISMS conformity - Question #197Managing an ISO/IEC 27001 Audit Program
Scenario 5: Data Grid Inc. is a well-known company that delivers security services across the entire information technology infrastructure. It provides cybersecurity software, incl...
certification processcertification agreementaudit stagesISO 27001 certification - Question #198Conducting an ISO/IEC 27001 Audit
The auditor was unable to identify that Company A hid their insecure network architecture. What type of audit risk is this?
detection riskaudit riskrisk typesaudit limitations - Question #199Planning an ISO/IEC 27001 Audit
Costs related to nonconformities and failures to comply with legal and contractual requirements are assessed when defining:
materialityaudit risknonconformity costsaudit planning - Question #200Planning an ISO/IEC 27001 Audit
AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the...
audit scopeISMS scopecertification scopescope alignment