NEW
Font size
WorksheetsDay#3A LA Certiprof
Total questions: 20
Worksheet time: 15mins
What is the main objective of stage 2 audit?
To review the internal audit activities
To evaluate the implementation of the ISMS
To verify the information security objectives of the ISMS
Which of the following is a step in audit planning?
Conducting risk assessment
Determining the audit criteria
Preparing the audit test plans
How does the audit team select processes and systems to be tested?
Based on the technical experts’ advice
Based on audit procedures
Based on materiality
During the audit, documented information involving proprietary information was protected at all times. Which principle of maintaining audit work documents has been followed?
Confidentiality
Authorship
Conciseness
What is the main purpose of the opening meeting in an audit?
To obtain detailed information about management system-related processes
To verify audit evidence and obtain a reasonable level of assurance
To ensure that planned audit activities can be performed
The opening meeting agenda can include information on:
The availability of the resources
The examination of documented information
The creation of audit test plans
The auditor has accessed logs to the server room. What source of information was collected?
Documents
Observations
Records
How is audit evidence evaluated?
By conducting quality review
By comparing it against the audit criteria
By utilizing audit tests
How often should audit team meetings be held?
A meeting held in the morning and another at the end of the day
A meeting per day held in the morning
A meeting per day held in the evening
What is the role of an observer?
To assist the audit team
To accompany the audit team
To help the auditor with the audit procedures
A guide’s responsibilities include maintaining logistics, ensuring that health and safety policies are observed, and facilitating audit activities.
True
False
What should an auditor do to evaluate the top management’s commitment to the information security management system?
Interview the auditee’s top management
Demonstrate commitment to audit procedures
Ask all of the auditee’s employees for their opinion
What must an auditor collect to ensure the relevance of an audit procedure?
Archives
Backup
Evidence
Which of the options below is NOT necessary to have in mind when conducting effective interviews?
Ensuring the interviewee does not leave out important information
Asking for specifics
Using complex and abstract terminology
An auditor takes notes of the serial numbers of the audited equipment and the locations where certain processes take place. Why would an auditor take such actions?
To document their observations
To keep notes for similar future cases
To keep track in case they forget something
To verify conformity to clause 7.5.3 Control of documented information of ISO/IEC 27001, the audit team has validated the electronic structure for classifying and storing documented information. What type of audit procedure has been used?
Technical verification
Analysis
Documented information review
Which of the following is considered as audit evidence when verifying conformity to clause 5.1 Leadership and commitment of ISO/IEC 27001?
Risk treatment results
The scope of the organization’s certification
Information security objectives
Establishing the organization's context and security policies, to which stage of the PDCA cycle do they belong?
A. Act.
D. Plan.
C. Do.
B. Check.
The risk management process involves the systematic application of policies, procedures and practices to the activities of communication and consultation, setting the context and assessment, treatment, monitoring, review, recording and reporting of risk. What does an ISMS contribute to the organization through the risk management process?
A. Determine the probability of a certain risk occurring.
D. Establish the threats to which IT resources are exposed
C. Determine the damage caused by possible security-related incidents.
B. Determine appropriate controls to achieve acceptable levels of risk.
What is Information Security Risk Analysis?
Select the best answer.
A. The process for determining only the controls required to avoid compromising an information asset.
D. It is the process that includes the possible consequences that certain situations may bring with them and the probability that these will occur with the objective of measuring the level of risk.
C. Establishes the environmental safety risk of an organization.
B. It is the process to eliminate the risks of an information asset.
