wayground logo

Free Printable Worksheets

NEW

Font size

S
M
L
XL
Worksheets

Day#3A LA Certiprof

Total questions: 20

Worksheet time: 15mins

Name
Class
Date
1.

What is the main objective of stage 2 audit?

a)

To review the internal audit activities

b)

To evaluate the implementation of the ISMS

c)

To verify the information security objectives of the ISMS

2.

Which of the following is a step in audit planning?

a)

Conducting risk assessment

b)

Determining the audit criteria

c)

Preparing the audit test plans

3.

How does the audit team select processes and systems to be tested?

a)

Based on the technical experts’ advice

b)

Based on audit procedures

c)

Based on materiality

4.

During the audit, documented information involving proprietary information was protected at all times. Which principle of maintaining audit work documents has been followed?

a)

Confidentiality

b)

Authorship

c)

Conciseness

5.

What is the main purpose of the opening meeting in an audit?

a)

To obtain detailed information about management system-related processes

b)

To verify audit evidence and obtain a reasonable level of assurance

c)

To ensure that planned audit activities can be performed

6.

The opening meeting agenda can include information on:

a)

The availability of the resources

b)

The examination of documented information

c)

The creation of audit test plans

7.

The auditor has accessed logs to the server room. What source of information was collected?

a)

Documents

b)

Observations

c)

Records

8.

How is audit evidence evaluated?

a)

By conducting quality review

b)

By comparing it against the audit criteria

c)

By utilizing audit tests

9.

How often should audit team meetings be held?

a)

A meeting held in the morning and another at the end of the day

b)

A meeting per day held in the morning

c)

A meeting per day held in the evening

10.

What is the role of an observer?

a)

To assist the audit team

b)

To accompany the audit team

c)

To help the auditor with the audit procedures

11.

A guide’s responsibilities include maintaining logistics, ensuring that health and safety policies are observed, and facilitating audit activities.

a)

True

b)

False

12.

What should an auditor do to evaluate the top management’s commitment to the information security management system?

a)

Interview the auditee’s top management

b)

Demonstrate commitment to audit procedures

c)

Ask all of the auditee’s employees for their opinion

13.

What must an auditor collect to ensure the relevance of an audit procedure?

a)

Archives

b)

Backup

c)

Evidence

14.

Which of the options below is NOT necessary to have in mind when conducting effective interviews?

a)

Ensuring the interviewee does not leave out important information

b)

Asking for specifics

c)

Using complex and abstract terminology

15.

An auditor takes notes of the serial numbers of the audited equipment and the locations where certain processes take place. Why would an auditor take such actions?

a)

To document their observations

b)

To keep notes for similar future cases

c)

To keep track in case they forget something

16.

To verify conformity to clause 7.5.3 Control of documented information of ISO/IEC 27001, the audit team has validated the electronic structure for classifying and storing documented information. What type of audit procedure has been used?

a)

Technical verification

b)

Analysis

c)

Documented information review

17.

Which of the following is considered as audit evidence when verifying conformity to clause 5.1 Leadership and commitment of ISO/IEC 27001?

a)

Risk treatment results

b)

The scope of the organization’s certification

c)

Information security objectives

18.

Establishing the organization's context and security policies, to which stage of the PDCA cycle do they belong?

a)

A. Act.

b)

D. Plan.

c)

C. Do.

d)

B. Check.

19.

The risk management process involves the systematic application of policies, procedures and practices to the activities of communication and consultation, setting the context and assessment, treatment, monitoring, review, recording and reporting of risk. What does an ISMS contribute to the organization through the risk management process?

a)

A. Determine the probability of a certain risk occurring.

b)

D. Establish the threats to which IT resources are exposed

c)

C. Determine the damage caused by possible security-related incidents.

d)

B. Determine appropriate controls to achieve acceptable levels of risk.

20.

What is Information Security Risk Analysis?

Select the best answer.

a)

A. The process for determining only the controls required to avoid compromising an information asset.

b)

D. It is the process that includes the possible consequences that certain situations may bring with them and the probability that these will occur with the objective of measuring the level of risk.

c)

C. Establishes the environmental safety risk of an organization.

d)

B. It is the process to eliminate the risks of an information asset.