LEAD-AUDITOR Exam Questions
392 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 5 of 8.
- Question #201Audit Ethics and Professional Conduct
An external auditor received an offer to conduct an ISMS audit at a research development company. Before accepting it, they discussed with the internal auditor of the auditee, who...
auditor independenceobjectivityaudit mandate acceptanceconflict of interest - Question #202ISMS Scope and Context Management
The scope of an organization certified against ISO/IEC 27001 states that they provide editing and web hosting services. However, due to some changes in the organization, the techni...
ISMS scopeoutsourcingscope changeISO/IEC 27001 - Question #203Audit Planning
The auditor should consider (1)-------when determining the (2)--------
audit risksaudit objectivesaudit planningmateriality - Question #204Audit Planning and Initiation
Why should materiality be considered during the initial contact?
materialityinitial contactaudit assurancedetection risk - Question #205Audit Execution and Management
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
documentation reviewon-site auditauditee rightsconfidentiality - Question #206Audit Execution and Findings
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
access rights controlinformation security policyaudit scopeaudit findings - Question #207Certification Audit Process
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
stage 1 auditnonconformity correctioncertification auditaudit stages - Question #208Certification Audit Process - Stage 1
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
stage 1 auditdocumented information reviewdocument formataudit objectives - Question #209ISMS Controls Verification
Scenario 6: Sinvestment is an insurance company that offers home, commercial, and life insurance. The company was founded in North Carolina, but have recently expanded in other loc...
event logsISO/IEC 27001 Annex Alogging requirementsaudit evidence - Question #210Audit Findings Classification
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
nonconformityaudit finding classificationISMS auditISO/IEC 27001 - Question #211Audit Documentation and Records
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
audit recordsdocumented informationevidence retentionaudit documentation - Question #212Certification Audit Process
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
stage 2 audit preparationaudit plan confirmationcertification bodyinter-stage activities - Question #213Audit Methodology and Sampling
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
samplingsample sizeaudit reliabilityaudit methodology - Question #214Audit Execution and Evidence Collection
Scenario 7: Lawsy is a leading law firm with offices in New Jersey and New York City. It has over 50 attorneys offering sophisticated legal services to clients in business and comm...
audit evidence collectiondocument copyingauditee consentauditor authority - Question #215Audit Findings Classification
As an auditor, you have noticed that ABC Inc. has established a procedure to manage the removable storage media. The procedure is based on the classification scheme adopted by ABC...
conformityaudit finding classificationremovable storage mediaISO/IEC 27001 controls - Question #216Audit Procedures and Techniques
To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team verified a sample of server logs to determine if they can be edited or deleted. Which audit pr...
audit proceduresanalysis techniquelogging controlsISO/IEC 27001 Annex A 8.15 - Question #217Audit Findings Classification
The auditor discovered that two out of 15 employees of the IT Department have not received adequate information security training. What does this represent?
audit findinginformation security trainingawarenesscompliance gap - Question #218Audit Quality Management
After drafting the audit conclusions, the work documents of the audit team leader were reviewed by another auditor selected by the certification body. Is this acceptable?
quality reviewaudit team leaderaudit quality assurancework documents - Question #219Audit Findings Classification
Which of the options below presents a minor nonconformity?
minor nonconformitybackup procedurenonconformity severityaudit findings - Question #220Audit Team Roles and Responsibilities
The responsibilities of a------------ include facilitating audit activities, maintaining logistics, ensuring that health and safety policies are observed, and witnessing the audit...
guide roleaudit rolesauditee representativeaudit facilitation - Question #221Conducting an ISMS Audit
The audit team leader decided to involve a technical expert as part of the audit team, so they could fill the potential gaps of the audit team members' knowledge. What should the a...
audit team compositiontechnical expert roleaudit team managementauditor responsibilities - Question #222Conducting an ISMS Audit
The auditor used sampling to ensure that event logs recording information security events are maintained and regularly reviewed. Sampling was based on the audit objectives, whereas...
audit samplingstatistical samplingevent logsaudit evidence - Question #223Closing an ISMS Audit
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
nonconformity managementaction planscorrective actionsISMS certification - Question #224Closing an ISMS Audit
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
action plan requirementsnonconformity correctioncorrective actionsroot cause analysis - Question #225Closing an ISMS Audit
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
major nonconformityaudit conclusionsremovable mediaISMS controls - Question #226Closing an ISMS Audit
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
action plan verificationcorrective actionaudit follow-upnonconformity - Question #227Conducting an ISMS Audit
Scenario 8: EsBank provides banking and financial solutions to the Estonian banking sector since September 2010. The company has a network of 30 branches with over 100 ATMs across...
auditor conductaudit impartialityaudit team leadernonconformity classification - Question #228Closing an ISMS Audit
After analyzing the audit conclusions, Company X decided to accept the risk related to one of the detected nonconformities. They claimed that no corrective action was necessary; ho...
risk acceptancecorrective actionnonconformity documentationaudit conclusions - Question #229Closing an ISMS Audit
Based on the identified nonconformities. Company A established action plans that included the detected nonconformities, the root causes, and a general statement regarding each acti...
action plan requirementsnonconformity corrective actionroot cause analysisISMS - Question #230ISMS Audit Programme Management
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
internal auditaudit independenceadvisory roleISMS - Question #231ISMS Audit Programme Management
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
certification scopeISO 27001 certificationISMS scopecertification body - Question #232ISMS Audit Programme Management
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
extension auditscope changecertification bodysurveillance audit - Question #233ISMS Audit Programme Management
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
audit independenceauditor rotationimpartialityinternal audit - Question #234ISMS Audit Programme Management
Scenario 9: UpNet, a networking company, has been certified against ISO/IEC 27001. It provides network security, virtualization, cloud computing, network hardware, network manageme...
surveillance auditcertification cycleISO 27001audit types - Question #235ISMS Audit Programme Management
How are internal audits and external audits related?
internal auditexternal auditcertification cycleaudit relationship - Question #236Closing an ISMS Audit
After conducting an external audit, the auditor decided that the internal auditor would follow-up on the implementation of corrective actions until the next surveillance audit. Is...
corrective action follow-upinternal auditorsurveillance auditexternal audit - Question #237ISMS Audit Programme Management
OrgXY is an ISO/IEC 27001-certified software development company. A year after being certified, OrgXY's top management informed the certification body that the company was not read...
surveillance auditcertification suspensionISO 27001 certificationcertification body - Question #238Fundamental Concepts and Principles of an ISMS
According to ISO/IEC 27001, an Information Security Management System seeks to protect which two of the following?
CIA triadconfidentialityintegrityISMS objectives - Question #239Fundamental Concepts and Principles of an ISMS
Which two of the following options do not participate in a second-party audit to ISO/IEC 27001?
second-party auditaudit typesauditor rolesaccreditation body - Question #240ISMS Audit Programme Management
When an organisation needs to determine the resources required for the internal audit programme, which one of the following issues does not impact on the achievement of its intende...
audit programme resourcesaudit competenceaudit planninginternal audit - Question #241Audit Principles and Processes
Which one of the following should be reviewed against the audit criteria to determine audit findings?
audit findingsaudit evidenceaudit criteriaISO 19011 - Question #242ISMS Monitoring and Review
You are an experienced ISMS Audit Team Leader, talking to an Auditor in training who has been assigned to your audit team. You want to ensure that they understand the importance of...
PDCA cyclemanagement reviewISMS operationISO/IEC 27001 clause 9 - Question #243ISMS Audit Execution
You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the information security...
outsourced servicessoftware securitychange managementnonconformity identification - Question #244Audit Reporting and Follow-up
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing m...
closing meetingcertification scopeorganizational changeaudit reporting - Question #245ISMS Audit Execution
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident ma...
incident managementISO/IEC 27035ransomware responseevidence collection - Question #246Audit Reporting and Follow-up
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing m...
closing meetingminor nonconformitycorrective actioncertification recommendation - Question #247Information Security Controls
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
software integritychange managementapplication legitimacyISO/IEC 27001 Annex A - Question #248Information Security Controls
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
preventive controlsconfidentiality agreementsupplier relationshipscontrol classification - Question #249Information Security Controls
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
detective controlsadministrative controlscontrol classificationISO/IEC 27001 - Question #250Information Security Standards and Frameworks
Scenario: Northstorm is an online retail shop offering unique vintage and modern accessories. It initially entered a small market but gradually grew thanks to the development of th...
privacy information managementISO/IEC 27701ISMS extensionPII protection