I think it's E, G, and H for this one. These aren't really audit trails for info sec incident management, just more about policy content or audit criteria. Pretty sure that's the logic, but would be good to double-check with ISO 27001 wording if anyone disagrees!

Pretty sure I ran into a similar one in exam, in practice dumps. Third-party auditor handles the independent assessment and submits findings, but the certification body alone decides if your org gets the ISO 27001 certificate (certification decision). This split ensures impartiality per ISO 19011. Pretty sure that's what they're looking for-auditor assesses, certification body certifies. Someone disagree?
Typical split: auditor does the assessment, certification body actually grants or withdraws the certificate based on that report. That’s in the official guide and practice tests I’ve seen. Let me know if you’ve seen different wording.

Pretty sure the correct completion is "ensure effectiveness and suitability of the management system". That's what ISO 27001 clause 5.2 expects for regulatory compliance parts. Seen this phrasing on official guides, but let me know if you got something else from training materials.

evaluation → collected audit evidence is the way to go here. Had something like this in a mock before, and "evaluation" plus "evidence" match ISO 19011 definition exactly. Terms like "assessment" might look similar but aren't what's used in the standard. Pretty sure that's what they're looking for, unless they've changed terminology since last update.


Yeah, it's about the competence of the audit team and the decision made by the certification body. That's what accredited certification really guarantees under ISO/IEC 17021-1. Pretty sure that's what they're looking for here, unless anyone sees it differently?
I think this fits if you interpret the standard a bit literally, as impartiality's often highlighted. But based on some practice questions, process might be oversold here. Anyone see issues with that logic?


Establish management system → plan audit programme → internal audits → management review → certification body (stage 1 & 2) → corrective actions. This matches the standard ISMS certification flow per PECB. Pretty sure that's correct, but open to tweaks if someone spots an exception here.

Yeah, order matters here for audit trails. It should go: Determine source of information, Collect by sampling, Reviewing, Audit evidence, Evaluating against audit criteria, Audit findings, then Audit conclusions. Pretty sure that matches typical ISO 27001 audit flow from planning through reporting but if someone disagrees let me know since I've seen similar orders in practice questions.