LEAD-AUDITOR Exam Questions
359 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 7 of 8.
- Question #301
Which type of audit requires that the auditee and audit team agree on remote access protocols before conducting the audit?
- Question #302
What is the purpose of audit test plans in the audit process?
- Question #303
What type of sampling was used when the auditor used probability-based sampling for event log reviews?
- Question #304
Which option below is correct about the audit plan?
- Question #305
Which of the following can be considered a minor nonconformity?
- Question #306
Scenario 8: Tessa. Malik, and Michael are an audit team of independent and qualified experts in the field of security, compliance, and business planning and strategies. They are as...
- Question #307
Scenario 8: Tessa. Malik, and Michael are an audit team of independent and qualified experts in the field of security, compliance, and business planning and strategies. They are as...
- Question #308
Scenario 8: Tessa. Malik, and Michael are an audit team of independent and qualified experts in the field of security, compliance, and business planning and strategies. They are as...
- Question #309
Scenario 8: Tessa. Malik, and Michael are an audit team of independent and qualified experts in the field of security, compliance, and business planning and strategies. They are as...
- Question #310
Scenario 8: Tessa. Malik, and Michael are an audit team of independent and qualified experts in the field of security, compliance, and business planning and strategies. They are as...
- Question #311
Scenario 8: Tess. Malik, and Michael are an audit team of independent and qualified experts in the field of security, compliance, and business planning and strategies. They are ass...
- Question #312
Scenario 8: Tessa. Malik, and Michael are an audit team of independent and qualified experts in the field of security, compliance, and business planning and strategies. They are as...
- Question #313
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #314
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #315
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #316
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #317
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #318
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #319
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #320
Scenario 9: Techmanic is a Belgian company founded in 1995 and currently operating in Brussels. It provides IT consultancy, software design, and hardware/software services, includi...
- Question #354
Which document defines the boundaries and applicability of an organization's ISMS?
- Question #355
What must be documented for each identified information security risk during treatment planning?
- Question #356
You find that the backup policy exists but is not reviewed annually. What type of issue is this?
- Question #357
Who is responsible for ensuring continual improvement in the ISMS?
- Question #358
Which of the following best defines the role of the Statement of Applicability (SoA)?
- Question #359
Which of the following entities is responsible for evaluating and certifying an organization's management system compliance?
- Question #360
Which factor can directly affect the availability of information within an organization?
- Question #361
ISO is directly responsible for performing accreditation and certification services.
- Question #362
A former employee gains unauthorized access to company data. What does this situation represent?
- Question #363
What does the principle of integrity ensure in the context of information security?
- Question #364
What is the impact of emerging technologies like big data on the audit process?
- Question #365
After drafting audit conclusions, another auditor reviews the team leader's documents. Is this permitted?
- Question #366
What is the best definition of an organization's context in ISO 27001?
- Question #367
A technical expert is added to the audit team to address knowledge gaps. How should communication be managed?
- Question #368
What is the standard ISO definition of an ISMS?
- Question #369
An external auditor discusses previous audit findings with a friend who is an internal auditor at the auditee's organization before accepting a new audit engagement. Is this behavi...
- Question #370
Which of the following is a preventive control related to personnel management in information security?
- Question #371
Which audit stage is primarily focused on reviewing the organization's documented policies, procedures, and preparedness for a full audit?
- Question #372
Which Annex A control specifically addresses cryptographic key protection and lifecycle management?
- Question #373
During an audit, it was discovered that a department was using outdated antivirus software. Which ISO 27001:2022 control does this situation most directly violate?
- Question #374
A retail company stores credit card data in unencrypted Excel sheets. Which two controls are breached according to ISO 27001:2022?
- Question #375
PayBell, a finance firm, uses a browser-accessible accounting platform that supports collaboration and real-time updates. What type of service is this?
- Question #376
An Auditor chooses samples for review based on probability and randomness to support audit objectives. What type of sampling is this?
- Question #377
Which of the following quality criteria must audit evidence meet?
- Question #378
Which event can lead to a revision of the audit scope?
- Question #379
Information or data that are classified as ______ do not require labeling.
- Question #380
A property of Information that has the ability to prove occurrence of a claimed event.
- Question #381
Stages of Information
- Question #382
A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:
- Question #383
Which of the following is not a type of Information Security attack?