Scenario Based Lead Auditor Day#3

Scenario Based Lead Auditor Day#3

1st Grade

5 Qs

quiz-placeholder

Similar activities

Quiz Inspektorat ke-2

Quiz Inspektorat ke-2

1st - 5th Grade

10 Qs

Kode Etik dan Standar Audit Intern

Kode Etik dan Standar Audit Intern

KG - Professional Development

10 Qs

PKS 26 Juni 2020

PKS 26 Juni 2020

1st - 3rd Grade

10 Qs

post test perencanaan Probity audit

post test perencanaan Probity audit

1st - 3rd Grade

10 Qs

măsurarea temperaturilor

măsurarea temperaturilor

1st Grade

9 Qs

1. POST TEST: PENGENALAN PEMERKASAAN AUDITEE

1. POST TEST: PENGENALAN PEMERKASAAN AUDITEE

1st Grade

10 Qs

Evaluación sobre EVA

Evaluación sobre EVA

1st - 5th Grade

10 Qs

Lab Audit

Lab Audit

1st - 3rd Grade

10 Qs

Scenario Based Lead Auditor Day#3

Scenario Based Lead Auditor Day#3

Assessment

Quiz

Professional Development

1st Grade

Medium

Created by

sudiyuwono wowo

Used 1+ times

FREE Resource

5 questions

Show all answers

1.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

DeeCorp, established in 1989, is one of the first companies to offer wireless technology services in South America. With more than 400 employees, they specialize in providing innovative engineering services, including network planning, deployment, integration, and optimization. Complying with ISO/IEC 27001 is very important to DeeCorp. They hope to finally gain their certification this year.

 

Eva was appointed to be the audit team leader for DeeCorp’s audit. Her job was to evaluate the current state of DeeCorp’s information security management system and present the audit findings in a comprehensive report. This would allow her to determine whether she should issue a recommendation for certification to DeeCorp.

 

Eva has thorough theoretical and practical knowledge of the audit principles and procedures. She is also experienced in information security. Her team consisted of two other auditors, Tom and Ben. Eva has already worked with Tom and Ben previously, so a socializing event (e.g., audit opening meeting) was deemed unnecessary.

 

Eva, Tom, and Ben decided to structure an audit test plan before proceeding. Eva’s job was to verify DeeCorp’s conformity to Annex A 5.1 Policies for information security of ISO/IEC 27001. To do so, she used individual interviews as an evidence collection procedure and audit sampling as a tool. She chose a statistically reliable and easy-to-use sampling method. Ben and Tom, on the other hand, were responsible for the sampling procedure. They selected a sample size of 10 employees based on a fixed interval.

 

Based on the scenario above, answer the following questions:

According to the general principles for determining the sample size, did Tom and Ben select a valid sample size of 10 employees based on a fixed interval?

No, the determined sample size is significantly low compared to DeeCorp’s population, as according to the general principles, for a population lower than 366 the minimum number of the sample size should be 25

Yes, the determined sample size is on proportion with DeeCorp’s overall population

No, the determined sample size is significantly low compared to DeeCorp’s population, as according to the general principles, for a population higher than 366, the minimum number of the sample size should be 25

Answer explanation

The sampling population in this case is higher than 400. According to the general principles for determining the sample size, for a population higher than 366, the minimum number of selections should be at least 25.

2.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

According to the scenario, Eva wanted an easy-to-use and statistically reliable sampling method. Which method fits that description?

Random sampling

Systematic sampling

Block selection sampling

Answer explanation

Systematic sampling is the most statistically reliable and easy-to-use method. Additionally, the scenario states that the sample size is selected based on a fixed interval, which is also a characteristic of systematic sampling.

3.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

The scenario states that there is no need for a socializing event. Is “socializing” the main purpose of an audit opening meeting?

No, the main purpose of an audit opening meeting is to gain a level of understanding of the team members’ background

Yes, the main purpose of an audit opening meeting is to allow the audit members to socialize

No, the main purpose of an audit opening meeting is to introduce and agree on the audit plan, audit team, and roles and responsibilities of each auditor

Answer explanation

According to ISO 19011, clause 6.4.3 Conducting opening meeting, the purpose of the opening meeting is to confirm the agreement of all participants (e.g. auditee, audit team) to the audit plan, introduce the audit team and their roles, and ensure that all planned audit activities can be performed.

4.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

What important information could Eva gather from the individual interviews that would be of help for her final audit report?

Detailed information that helps her evaluate and determine if a set of policies for information security is defined, approved, published, and communicated to employees and external parties

Detailed information on when the organization implemented the information security policies control and the persons responsible for its implementation and maintenance

Detailed information on the expertise level of DeeCorp employees and their level of understanding and attitude to the organization’s policies

Answer explanation

Individual interviews can help Eva gain detailed information on whether the controls operate effectively and continuously and are error-free.

5.

MULTIPLE CHOICE QUESTION

30 sec • 1 pt

Eva’s team structured an audit test plan in order to:

Test whether the controls are error-free

Determine a nonconformity

Validate conformity to requirements

Answer explanation

An audit test plan based on audit procedures used for evidence collection helps validate conformity to requirements.