View Mode
Q: 11
During a third-party certification audit you are presented with a list of issues by an auditee. Which four of the following constitute 'external' issues in the context of a management system to ISO/IEC 27001:2022?
Options
Q: 12
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process. The IT Security Manager presents the information security incident management procedure (Document reference ID: ISMS_L2_16, version 4). You review the document and notice a statement "Any information security weakness, event, and incident should be reported to the Point of Contact (PoC) within 1 hour after identification". When interviewing staff, you found that there were differences in the understanding of the meaning of the phrase "weakness, event, and incident". The IT Security Manager explained that an online "information security handling" training seminar was conducted 6 months ago. All the people interviewed participated in and passed the reporting exercise and course assessment. You would like to investigate other areas further to collect more audit evidence. Select three options that would not be valid audit trails.
Options
Q: 13
DRAG DROP Select the words that best complete the sentence: ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Q: 14
DRAG DROP Select the words that best complete the sentence: "The purpose of maintaining regulatory compliance in a management system is to To complete the sentence with the best word(s), click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Q: 15
DRAG DROP Select the words that best complete the sentence to describe an audit finding. ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Q: 16
DRAG DROP You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services. The next step in your audit plan is to verify the effectiveness of the continual improvement process. During the audit, you learned most of the residents' family members (90%) receive WeCare medical devices promotion advertisements through email and SMS once a week via ABC's healthcare mobile app. All of them do not agree on the use of the collected personal data for marketing or any other purposes than nursing and medical care on the signed service agreement with ABC. They have very strong reason to believe that ABC is leaking residents' and family members' personal information to a non-relevant third party and they have filed complaints. The Service Manager says that, after investigation, all these complaints have been treated as nonconformities. The corrective actions have been planned and implemented according to the nonconformity and corrective management procedure (Document reference ID: ISMS_L2_10.1, version 1). You write a nonconformity which you will follow up on later. Select the words that best complete the sentence: ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Q: 17
DRAG DROP Select the words that best complete the sentence: To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section. ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Q: 18
DRAG DROP Auditors need to communicate effectively with auditees. Therefore, their personal behaviour is a key characteristic needed to ensure a successful audit. Below there are the characteristics and a brief related description. Match the characteristics to the descriptions. ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Q: 19
DRAG DROP An organisation is looking for management system initial certification. Please identify the sequence of the activities to be undertaken by the organisation. To complete the sequence click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the options to the appropriate blank section. ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Q: 20
DRAG DROP A key audit process is the way auditors gather information and determine the findings' characteristics. Put the actions listed in the correct order to complete this process. The last one has been done for you. ISO-IEC-27001-LEAD-AUDITOR question
Your Answer
Question 11 of 20 · Page 2 / 2

Premium Access Includes

  • Quiz Simulator
  • Exam Mode
  • Progress Tracking
  • Question Saving
  • Flash Cards
  • Drag & Drops
  • 3 Months Access
  • PDF Downloads
Get Premium Access
Scroll to Top

FLASH OFFER

Days
Hours
Minutes
Seconds

avail 10% DISCOUNT on YOUR PURCHASE