Spring Sale 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: save70

ISO 27001 Changed ISO-IEC-27001-Lead-Auditor Questions

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam Questions and Answers

Question 105

You are an ISMS audit team leader who has been assigned by your certification body to carry out a follow-up audit of a client. You are preparing your audit plan for this audit.

Which two of the following statements are true?

Options:

A.

Verification should focus on whether any action undertaken taken has been undertaken efficiently

B.

Corrections should be verified first, followed by corrective actions and finally opportunities for improvement

C.

Verification should focus on whether any action undertaken is complete

D.

Opportunities for improvement should be verified first, followed by corrections and finally corrective actions

E.

Corrective actions should be reviewed first, followed by corrections and finally opportunities for improvement

F.

Verification should focus on whether any action undertaken has been undertaken effectively

Question 106

Which two of the following statements are true?

    The benefits of implementing an ISMS primarily result from a reduction in information security risks

Options:

A.

The benefit of certifying an ISMS is to obtain contracts from governmental institutions

B.

The purpose of an ISMS is to apply a risk management process for preserving information security

C.

The purpose of an ISMS is to demonstrate compliance with regulatory requirements

Question 107

AppFolk, a software development company, is seeking certification against ISO/IEC 27001. In the initial phases of the external audit, the certification body in discussion with the company excluded the marketing division from the audit scope, although they stated in their ISMS scope that the whole company is included. Is this acceptable?

Options:

A.

Yes, audit and ISMS scope do not necessarily need to be the same

B.

No, divisions that are not critical for the industrial sector in which the auditee operates can be excluded from the audit scope

C.

No, audit scope should reflect all of the organization’s divisions covered by the ISMS

Question 108

Which two of the following are examples of audit methods that 'do not' involve human interaction?

    Conducting an interview using a teleconferencing platform

Options:

A.

Performing a review of auditees procedures in preparation for an audit

B.

Reviewing the auditee's response to an audit finding

C.

Analysing data by remotely accessing the auditee's server

D.

Observing work performed by remote surveillance

E.

Confirming the date and time of the audit