LEAD-AUDITOR Exam Questions
392 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 6 of 8.
- Question #251Information Security Fundamentals
Scenario: After an information security incident, an organization created a comprehensive backup procedure involving regular, automated backups of all critical data to offsite stor...
CIA triadavailabilitybackup proceduresdata recovery - Question #252Threats, Vulnerabilities, and Risk
Scenario: A data processing tool crashed when a user added more data to the buffer than its storage capacity allows. The incident was caused by the tool's inability to bound-check...
buffer overflowintrinsic vulnerabilitysoftware vulnerabilityasset characteristics - Question #253Information Security Controls
Which of the following best defines managerial controls?
managerial controlspersonnel managementcontrol typessecurity training - Question #254Threats, Vulnerabilities, and Risk
What is the objective of penetration testing in the risk assessment process?
penetration testingrisk assessmentICT protectionvulnerability identification - Question #255Information Security Controls
Which controls are related to the Annex A controls of ISO/IEC 27001 and are often selected from other guides and standards or defined by the organization to meet its specific needs...
specific controlsAnnex AISO/IEC 27001control selection - Question #256Threats, Vulnerabilities, and Risk
Which of the following statements regarding threats and vulnerabilities in information security is NOT correct?
threats vs vulnerabilitiesrisk conceptscontrol implementationCIA triad - Question #257Threats, Vulnerabilities, and Risk
Which situation presented below represents a threat?
threat definitionzero-day vulnerabilitythreat vs vulnerabilitycyber attack - Question #258Information Security Controls
A cybersecurity company implemented an access control software that allows only authorized personnel to access sensitive files. Which type of control has the company implemented in...
access controlpreventive controlcontrol classificationauthorization - Question #259ISMS Planning and Documentation
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
Statement of ApplicabilityAnnex A controlscontrol justificationISO/IEC 27001 clause 6.1.3 - Question #260ISMS Planning and Documentation
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
ISMS scopeexternal issuescontext of organizationISO/IEC 27001 clause 4 - Question #261Planning the ISMS (ISO/IEC 27001 Clause 6)
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
information security objectivesrisk assessmentISMS planningISO/IEC 27001 Clause 6 - Question #262Context of the Organization (ISO/IEC 27001 Clause 4)
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
ISMS scopescope definitionscope exclusionsISO/IEC 27001 Clause 4 - Question #263Risk Assessment Methodology
Scenario 2: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart- related conditions and complex surgical interventions. Based in Euro...
risk assessment methodologyOCTAVEMEHARIEBIOS - Question #264Leadership and Commitment (ISO/IEC 27001 Clause 5)
According to ISO/IEC 27001, Clause 5.1 (Leadership and Commitment), which of the following is NOT a responsibility of top management?
top management responsibilitiesleadership commitmentISO/IEC 27001 Clause 5.1ISMS governance - Question #265Risk Assessment and Treatment
A marketing agency has developed its risk assessment approach as part of the ISMS implementation. Is this acceptable?
risk assessment methodologyISO/IEC 27001 complianceISMS flexibilityrisk management - Question #266Support and Documented Information (ISO/IEC 27001 Clause 7)
Which of the following statements regarding documented information in an organization's ISMS is incorrect?
documented informationISMS documentationISO/IEC 27001 Clause 7information management - Question #267Audit Risk Management
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
detection riskaudit risk typescontrol riskinherent risk - Question #268Audit Planning and Preparation
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
audit team responsibilitiesaudit planningaudit preparationcertification audit - Question #269Auditor Conduct and Professional Ethics
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
auditor conductaudit confidentialitysensitive information accessaudit ethics - Question #270Managing and Conducting the Audit
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
audit scope changesaudit schedule modificationcertification body approvalaudit management - Question #271Managing and Conducting the Audit
Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased e...
auditor withdrawalcertification agreementaudit team managementaudit independence - Question #272Auditor Independence and Ethics
Three auditors were assigned to conduct a certification audit in Company X. Before the audit commenced, the certification body provided the auditors' names and background informati...
conflict of interestauditor replacementaudit independenceauditee rights - Question #273Audit Initiation
What is the main reason for sending an engagement letter before the initial contact with the auditee?
engagement letteraudit initiationinitial contactaudit communication - Question #274Audit Team Structure and Management
In a joint audit involving multiple audit teams, how many audit team leaders are typically designated per audit?
joint auditaudit team leaderaudit structuremulti-team audits - Question #275Audit Planning and Materiality Assessment
Why should materiality be considered during the initial contact?
materialityaudit objectivesinitial contactaudit scope definition - Question #276Audit Stages and Process
During which stage of the audit do auditors identify key processes to be audited and prioritize based on materiality?
Stage 1 auditmaterialitykey process identificationaudit stages - Question #277Certification Body Requirements and Management
When multiple offices of a certification body are involved, what must be ensured?
certification bodylegal agreementsmulti-site certificationcertification scope - Question #278Audit Planning and Materiality Assessment
An organization is evaluating the materiality of different processes within its ISMS. It is assessing the direct expenses involved with personnel, third-party services, and general...
materiality factorscost of processdirect expensesprocess evaluation - Question #279Audit Evidence Collection and Evaluation
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
audit evidence reliabilityevidence sourcesevidence evaluationaudit methodology - Question #280Auditor Ethics and Professional Conduct
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
fraudauditor misconductprofessional ethicsgross negligence - Question #281Audit Process and Principles
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
audit ethicscertification body reportingillegal activityauditor conduct - Question #282Audit Evidence Collection
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
audit evidenceverbal evidencewritten confirmationtop management interviews - Question #283Audit Process and Principles
Scenario 3: Rebuildy is a construction company located in Bangkok.. Thailand, that specializes in designing, building, and maintaining residential buildings. To ensure the security...
auditor confidentialityaudit reportingethical conductinformation disclosure - Question #284Audit Planning and Execution
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
audit diligenceemployment contractssamplingauditor judgment - Question #285Audit Evidence Collection
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
types of evidenceverbal evidencedocumentary evidenceaudit evidence - Question #286Types of Audits
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
audit typessecond-party auditsupplier auditoutsourcing - Question #287Audit Process and Principles
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
professional skepticismauditing principlesauditor objectivityISO 19011 - Question #288ISMS Scope and Context
Scenario 4: Branding is a marketing company that works with some of the most famous companies in the US. To reduce internal costs. Branding has outsourced the software development...
outsourced processessupplier responsibilityISO 27001 clause 8third-party management - Question #289Audit Process and Principles
Prior to initiating the audit activities, the auditors considered the auditee's context, critical processes, and expectations. Which auditing principle has been applied?
due professional careaudit preparationauditing principlesauditee context - Question #290Audit Evidence Collection
What is the main difference between qualitative and quantitative evidence?
qualitative evidencequantitative evidenceaudit evidence typesdata analysis - Question #291Certification and Accreditation
Finnco, a subsidiary of a certification body, provided ISMS consultancy services to an organization. Considering this scenario, when can the certification body certify the organiza...
certification body independenceconsultancy conflict of interestISO 17021impartiality - Question #292Audit Techniques and Tools
How does predictive analytics help auditors in identifying potential risks?
predictive analyticsrisk identificationdata analyticsaudit technology - Question #293Audit Reporting and Follow-up
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
Stage 1 audit outputsaudit documentationnonconformity evidenceaudit reporting - Question #294Certification Audit Process
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
SoA modificationsStage 2 auditmajor nonconformityISMS policy changes - Question #295Audit Process and Principles
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
technical expert objectivityauditor skepticismaudit team managementISO 19011 - Question #296Audit Evidence Collection
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
interview objectivesaudit evidencemanagement system validationaudit techniques - Question #297ISMS Documentation and Controls
Scenario 6: Cyber ACrypt is a cybersecurity company that provides endpoint protection by offering anti-malware and device security, asset life cycle management, and device encrypti...
documented informationISO 27001 clause 7.5document management procedureISMS documentation - Question #298Audit Techniques and Tools
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
process simulationencryption testingaudit verification techniquestechnical testing - Question #299Audit Evidence Collection
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
corroborationaudit evidence techniquesevidence validationISO 19011 - Question #300Audit Techniques and Tools
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
technical verificationcloud computing controlsaudit testing methodsISO 27001 Annex A