wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Tambahan soal Lead Auditor

Total questions: 25

Worksheet time: 13mins

Name
Class
Date
1.

What step should an auditor follow to ensure the competence of staff in outsourced operations?

a)

Review the service provider’s processes and employees’ contracts

b)

Ensure that disaster recovery processes are in place

c)

Review and evaluate the organization’s plan in case of an unexpected termination of the outsourcing agreement

2.

Which services can be managed by the user when using Platform as a Service (PaaS)?

a)

Virtualization and servers

b)

Runtime and middleware

c)

Application and data

3.

Audit evidence must be:

a)

Verifiable

b)

Physical

c)

Reputable

4.

What type of evidence is an external audit report?

a)

Physical

b)

Confirmative

c)

Analytical

5.

How can an auditor verify conformity to control 5.18 Access rights of ISO/IEC 27001 by using analytical evidence?

a)

By analyzing results of the access rights removal procedure on a sample of users upon the termination of their contracts

b)

By analyzing the removal or adjustment of access rights procedure

c)

By analyzing the access rights removal simulation test

6.

What makes audit evidence appropriate?

a)

Sufficiency

b)

Relevance and reliability

c)

Approval

7.

Which type of audit risk is known as the risk that occurs in the management system despite the internal control mechanisms in an organization?

a)

Inherent risk

b)

Control risk

c)

Detection risk

8.

Which of the following factors should be considered when determining the materiality of a system?

a)

The organizational changes

b)

The conditions of service-level agreements

c)

The audit results

9.

Materiality is taken into account to determine the duration of the audit based on the risks inherent to the organization during:

a)

Initial contact

b)

Stage 1 audit

c)

Stage 2 audit

10.

What does “control risk” mean?

a)

The risk that a significant defect related to the organizations’ internal controls could not be detected by the auditor

b)

The risk that a significant defect could not be prevented by the organization’s internal control mechanisms

c)

The risk that remains after a significant defect of an internal control is detected and corrected

11.

What action is taken during stage 1 audit when evaluating materiality during the audit?

a)

Identifying the key processes to be audited

b)

Determining the audit duration

c)

Adjusting the plan based on the materiality of each process or asset

12.

Which parties are involved in an audit offer?

a)

The auditor and the auditee

b)

The certification body and the auditee

c)

The certification body and the auditor

13.

What can trigger the initiation of a change in the audit scope?

a)

Recent changes in the existing processes

b)

Review of major information security incidents

c)

Modifications in the information security policy

14.

Auditors use the _______________ as a reference to determine conformity.

a)

Audit feasibility

b)

Audit Criteria

c)

Audit objectives

15.

The lead auditor evidences that in the previous audit a nonconformity applicable to information security policies was declared and for this year the same situation is still occurring, which clause of ISO 27001:2022 is being breached with a clear failure to follow up?

a)

5.3.

b)

5.2.

c)

10.2.

d)

5.1.

16.

Reporting to senior management on the performance of the ISMS is an assigned responsibility:

a)
  • Senior Management.

  • 

b)
  1. The leader of each process.

c)

Management of the organization.

d)
  1. The information security leader.

17.

A laptop was stolen from a hotel where the information security officer was lecturing. Which control of ANNEX A of ISO IEC 27001:2022 should or must this PC have had?

a)

A.7.8.

b)

A. 5.10.

c)

A. 5.1.

d)

A. 7.9.

18.

The lead auditor evidences that risk acceptance criteria are not yet established, which clause of ISO 27001:2022 is being breached?

a)

6.1.2.

b)

9.1.

c)

8.3

d)

5.1

19.

The basis for audit impartiality and objectivity of audit findings is:

a)

An element for the presentation of the audit scope.

b)
  1. An element for decision making in information security risks.

c)
  1. An element for the presentation of the audit report.

d)

A principle of auditing.

20.

Once the audit has been carried out, the auditor in charge of the audit must

prepare the Audit Report. This report establishes:

a. Audit objectives

b. Scope of the audit.

c. Auditees and the audit period.

d. Documentation of the contact person.

e. Documentation of the lead auditor and other auditors.

f. Dates and locations where the audit activities took place.

g. Audit criteria.

h. Audit statements.

i. Audit Conclusions.

a)

All are correct.

b)

Only i.

c)

All except d and e.

21.

It establishes that the organization must implement the risk treatment

process:

a)

a) Clause 6.1.2

b)

b) Clause 6.1.3

c)

c) Clause 8.3

d)

d) B and C are valid

22.

According to ISO 19011:2018, audit criteria are:

a)

  • They are related in detail in the audit report.

b)
  • A set of requirements used as a reference against which objective evidence is compared.

c)
  • Detailed by the auditor in conjunction with the Company and the audited process.

d)
  • Only known to the Company's senior management and the auditor.

23.

An auditor should declare a NON-COMPLIANCE, when:

a)
  • The Organization decides to exclude clause 5.3 Roles, Responsibilities and Authorities in the Organization.

b)
  • The Organization decides to exclude control 7.1 Physical security perimeters.

c)
  • The Organization decides to exclude control 6.7 Remote work.

d)
  • The Organization decides to exclude control 8.27 Secure architecture and security principles for information systems.

24.

ISO 19011:2018 defines the need for resource related risk assessment. An example of a resource related risk is:

a)
  • Ineffective external/internal communication processes/channels.

b)
  • Failure to establish the relevant audit objectives and determine the scope, number, duration, locations, and timing of audits.

c)
  • Insufficient overall competence to perform audits effectively.

d)
  • Allowing insufficient time, equipment and/or training to develop the audit program or conduct an audit.

25.

Perceptive, diplomatic, and versatile are:

a)

  • Personal attributes of the person(s) managing the audit program.

b)
  • Personal attributes of the auditors.

c)

Personal capabilities that senior management should have.

d)

Personal attributes of the auditees.