LEAD-AUDITOR Exam Questions
392 real LEAD-AUDITOR exam questions with expert-verified answers and explanations. Page 8 of 8.
- Question #351Conducting an ISO/IEC 27001 Audit
Drag and Drop Question Select the word that best completes the sentence: Answer:
audit observationconformityaudit findingsaudit terminology - Question #352Fundamental Audit Concepts and Principles
Drag and Drop Question Select the words that best complete the sentence to describe an audit finding. Answer:
audit finding definitionaudit evidenceaudit criteriaaudit evaluation - Question #353Information Security Risk Management
Drag and Drop Question You are an experienced ISMS audit team leader providing instruction to a class of auditors in training. The subject of today's lesson is the management of in...
risk management sequenceISO 27001:2022risk assessmentrisk treatment - Question #354ISMS Documentation Requirements
Which document defines the boundaries and applicability of an organization's ISMS?
ISMS scopescope documentISMS documentationISO 27001 - Question #355Information Security Risk Management
What must be documented for each identified information security risk during treatment planning?
risk treatmentrisk documentationtreatment optionsISO 27001 - Question #356Conducting an ISO/IEC 27001 Audit
You find that the backup policy exists but is not reviewed annually. What type of issue is this?
nonconformity classificationminor nonconformitypolicy reviewaudit findings - Question #357ISMS Management Responsibility
Who is responsible for ensuring continual improvement in the ISMS?
continual improvementtop management responsibilityISMS leadershipISO 27001 - Question #358ISMS Documentation Requirements
Which of the following best defines the role of the Statement of Applicability (SoA)?
Statement of Applicabilitycontrol selectionISMS documentationISO 27001 - Question #359Certification and Accreditation
Which of the following entities is responsible for evaluating and certifying an organization's management system compliance?
certification bodymanagement system certificationaccreditationthird-party audit - Question #360Fundamental Principles of Information Security
Which factor can directly affect the availability of information within an organization?
information availabilityCIA triadperformance degradationinformation security principles - Question #361Introduction to ISO and Management Systems
ISO is directly responsible for performing accreditation and certification services.
ISO roleaccreditationcertification bodiesstandards governance - Question #362Information Security Concepts and Principles
A former employee gains unauthorized access to company data. What does this situation represent?
threatunauthorized accessrisk conceptsinsider threat - Question #363Information Security Concepts and Principles
What does the principle of integrity ensure in the context of information security?
integrityCIA triadinformation security principlesdata accuracy - Question #364Audit Planning and Management
What is the impact of emerging technologies like big data on the audit process?
big dataaudit challengesemerging technologiesaudit process - Question #365Managing an Audit Programme
After drafting audit conclusions, another auditor reviews the team leader's documents. Is this permitted?
audit documentationdocument reviewaudit team rolespost-conclusion review - Question #366ISO 27001 Requirements
What is the best definition of an organization's context in ISO 27001?
organizational contextISO 27001 Clause 4internal factorsexternal factors - Question #367Managing an Audit Programme
A technical expert is added to the audit team to address knowledge gaps. How should communication be managed?
technical expertaudit team communicationaudit managementauditee interaction - Question #368Introduction to ISO and Management Systems
What is the standard ISO definition of an ISMS?
ISMS definitionISO 27001information security management systemmanagement system - Question #369Auditor Competence and Ethics
An external auditor discusses previous audit findings with a friend who is an internal auditor at the auditee's organization before accepting a new audit engagement. Is this behavi...
auditor impartialityaudit ethicsconfidentialityengagement acceptance - Question #370ISO 27001 Controls and Implementation
Which of the following is a preventive control related to personnel management in information security?
preventive controlspersonnel securitysecurity awareness trainingAnnex A controls - Question #371Certification Audit Process
Which audit stage is primarily focused on reviewing the organization's documented policies, procedures, and preparedness for a full audit?
Stage 1 auditaudit stagesdocument reviewcertification audit - Question #372ISO 27001 Controls and Implementation
Which Annex A control specifically addresses cryptographic key protection and lifecycle management?
cryptographic key managementAnnex A 8.24key lifecycleISO 27001:2022 - Question #373ISO 27001 Controls and Implementation
During an audit, it was discovered that a department was using outdated antivirus software. Which ISO 27001:2022 control does this situation most directly violate?
technical vulnerability managementAnnex A 8.8antiviruspatch management - Question #374ISO 27001 Controls and Implementation
A retail company stores credit card data in unencrypted Excel sheets. Which two controls are breached according to ISO 27001:2022?
data classificationcryptographyAnnex A 8.24sensitive data protection - Question #375Information Security Concepts and Principles
PayBell, a finance firm, uses a browser-accessible accounting platform that supports collaboration and real-time updates. What type of service is this?
cloud computingSaaSservice modelstechnology concepts - Question #376Audit Evidence and Sampling
An Auditor chooses samples for review based on probability and randomness to support audit objectives. What type of sampling is this?
statistical samplingaudit samplingprobability samplingevidence collection - Question #377Audit Evidence and Sampling
Which of the following quality criteria must audit evidence meet?
audit evidenceevidence qualityverifiabilityaudit standards - Question #378Audit Planning and Management
Which event can lead to a revision of the audit scope?
audit scopescope revisionaudit planninginformation security policy - Question #379ISO 27001 Controls and Implementation
Information or data that are classified as ______ do not require labeling.
information classificationdata labelingpublic informationclassification scheme - Question #380Information Security Concepts and Principles
A property of Information that has the ability to prove occurrence of a claimed event.
non-repudiationintegrityinformation propertiesCIA triad - Question #381Information Security Management
Stages of Information
information lifecycleinformation stagesdata management - Question #382Physical and Environmental Security
A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:
physical securityvisitor managementsocial engineeringaccess control - Question #383Information Security Incident Management
Which of the following is not a type of Information Security attack?
incident classificationsecurity attack typesthreat categories - Question #384Information Security Management
The following are purposes of Information Security, except:
information security objectivesbusiness continuityrisk management - Question #385Access Control
The following are the guidelines to protect your password, except:
password managementauthenticationaccess controlsecurity policies - Question #386Information Security Incident Management
Phishing is what type of Information Security Incident?
phishingsocial engineeringhacker attacksincident classification - Question #387Information Security Management
Information Security is a matter of building and maintaining ________.
information security fundamentalstrustsecurity principles - Question #388Audit Procedures and Evidence Collection
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
audit evidencevirtual auditsdocument handlingauditor ethics - Question #389Audit Reporting
Scenario 7: Webvue. headquartered in Japan, is a technology company specializing in the development, support, and maintenance of computer software. Webvue provides solutions across...
audit reportingaudit findingsaudit scopeauditor responsibilities - Question #390Audit Findings and Conclusions
As an auditor, you have noticed that ABC Inc. has established a procedure to manage removable storage media. The procedure is based on the classification scheme adopted by ABC Inc....
audit findingsconformityISO/IEC 27001removable media controls - Question #391Audit Techniques and Tools
EquiBank is undergoing an external audit of its financial management system. The auditors evaluate the logic of transactions processed by EquiBank's financial software. To ensure a...
CAATcomputer-assisted audit techniquesdata testfinancial auditing - Question #392Audit Planning
What is the purpose of using a combination of audit test plans?
audit test plansaudit methodologycompliance verificationaudit planning