Font size
WorksheetsTrial CertiProf Lead Auditor#2
Total questions: 40
Worksheet time: 21mins
The results of the audit:
a) Are the evaluation results of the audit evidence gathered against the audit criteria.
b) They are considered findings and can be classified as conformity or nonconformity.
c) It is an audit method to reach reliable conclusions.
d) If the audit criteria are selected from legal requirements or regulatory requirements, the audit finding is referred to as compliance or noncompliance.
B and C only
A and C only
All of the above
It establishes that the organization must define a risk assessment process:
Clause 6.1.1
Clause 6.1.2
Clause 8.1
B and C are valid
It establishes that the organization must implement the risk treatment
process:
Clause 6.1.2
Clause 6.1.3
Clause 8.3
B and C are valid
These are risk management strategies except:
Mitigate
Transfer
Assume
Retain
Control
Type of strategy where the implementation of a control to reduce the level of risk is defined:
Mitigate
Transfer
Assume
Retain
The “Statement of Applicability” must contain:
Controls necessary to reduce the level of risk.
The justification for the inclusion of the controls considered necessary.
Whether or not the necessary controls are implemented.
Justification for exclusions from any of the controls in annex A.
All are valid
According to ISO 19011:2018 audit is defined as a systematic, independent, documented process for obtaining evidence and evaluating it objectively, in order to determine the extent to which the audit criteria are met.
True
False
ISO 19011:2018 establishes as methods for assessing auditors:
A. Observation
B. Examination
C. Interview
D. Telephone call
E. All except D
During the audit, professional behavior by the auditor is desired, e.g., the auditor is expected to be open-minded, i.e., willing to consider alternative ideas or points of view.
True
False
Defining objectives, scope and criteria for each individual audit, Selecting audit methods, and Defining and implementing the necessary operational controls for the supervision of the audit program are part of the activities for:
Define the scope of the ISMS.
Correctly create the ISMS policy.
Define the audit program.
They are responsible for assigning responsibilities to the audit Team Leader:
Top Management
The person responsible for the management system.
Senior management.
The person(s) managing the audit program.
They should ensure that the following activities are carried out as part of the management of the results of the audit program:
1. Evaluation of the achievement of the objectives for each audit within the audit program.
2. Review and approval of audit reports on compliance with the scope and objectives of the audit.
3. Reviewing the effectiveness of actions taken to address audit findings.
4. Distribution of audit reports to relevant stakeholders.
5. Determination of the need for any follow-up audits.
Members of the audit team.
Everyone in the organization.
The person(s) managing the audit program.
The audit plan describes:
The activities and arrangements for each planned audit.
A planning over a given period of time of one or more audits.
Both are valid since there is a relation between the program and the audit plan.
The audit program describes:
The activities and arrangements for each planned audit
A planning over a given period of time of one or more audits.
Both are valid since there is a relation between the program and the audit plan.
In relation to requirement 4.2 of ISO IEC 27001: 2022, it is established that the organization shall determine:
Which of these requirements will be addressed through the Information Security
Management System.
Stakeholders that are relevant to the Information Security Management System.
The relevant requirements of these stakeholders.
All of the above.
During an audit the auditee provides little information and constantly rephrases the auditor's questions:
Considered difficult situations that the auditor must be able to handle.
Issues that the lead auditor must resolve.
Conditions for termination of the audit.
When trying to retrieve a "BACKUP" it did not restore the information, therefore no ISMS information was found. Which control of Annex A of ISO IEC 27001:2022 was not adequately complied with?
8.14.
8.13.
5.1.
8.20.
An opportunity for improvement is not considered a nonconformity but may be reviewed by the organization, when deemed appropriate, to improve the effectiveness of the process.
True
False
The following are methods for performing audits.
1. On site.
2. Remote.
3. With human interaction
4. No human interaction.
Only 1 and 2
All except 4
Only 3 and 4
All of above
The audit team leader, in consultation with the audit team, assigns each team member responsibility for:
1. Auditing processes.
2. Activities.
3. Functions.
4. Developing the audit program.
Only 1 and 2
All except 4
Only 3 and 4
All
A retired employee of the Organizations remain active on the access platform after one month.
Which control in Annex A of ISO/IEC 27001:2022 is not meet
a) 5.18
b) 5.15
c) 5.16
a and c
A laptop was stolen from a hotel where the Information security officer was lecturing.
Which control of Annex-A ISO/IEC 27001 should or must this PC have had?
7.9
5.10
5.1
7.8
Which control of Annex-A ISO/IEC 27001:2022 ensure that information system are designed, implemented and operated securely within the development life cycle
5.1
8.20
8.27
8.25
During a visit to the physical security facilities, the Auditor find that the PC has different date and time.
Which control in Annex-A ISO/IEC 27001:2022 has not been properly implemented?
8.14
5.1
8.17
5.4
The results of previous internal or external audits should be considered to establish:
A. The objectives of the audit program.
• D. The documents that the audited process must have.
C. A and B.
B. The scope of the audit program.
In the morning hours people were asked to work from home by connecting from a secure VPN, since there was no electricity supply in the Company. Unfortunately, the DATACENTER where sensitive information is stored was connected to a UPS that failed within two hours of being turned on and mission critical activities could not be carried out.
The company's penalties were large because it had ensured that the availability was 99.7%.
What is the control of ANNEX A of ISO IEC 27001:2022 that most applies to this case?
8.14.
5.1.
6.3.
7.2.
Verifying the relevance and accuracy of the information collected is a mandatory activity of:
The auditee to provide accurate information to the auditor.
The person(s) managing the audit program to carry out the audit program.
The Auditor as a skill and ability to ensure that audits are performed in a consistent and systematic manner.
The internal auditor to carry out the audit plan.
When an employee is to be terminated, which of the following should be done?
Disabled the employee’s network access just as they are informed of the termination
Inform the employee a few hours before they are officially terminated.
Send out a broadcast email informing everyone that a specific employee is to be terminated
Wait until you and the employee are the only people remaining in the building before announcing termination
What is performance evaluation?
Process of determining the status of a system, process, or activity
Process of determining measurable results
Process of determining a value
Process of determining an IT Objectives
They help to provide audit continuity, plan and effective audit, identify the most critical aspectsof the system, control the depth, continuity and pace of the audit
Audit team
Checklists
Audit plans
Audit program
Conflict with the Auditee could be occurs during Audit process, such like... (choose four)
Antagonism or lack of cooperations
Budgeting
Difference of opinions
Work attitude
Time wasted
Which one is not the purpose of Opening Meeting?
Confirmed the agreement of all participants
Determine of Lead Auditor
Introduce the Audit teams and their rules
Ensure that all planned audit activities can be performed
Audit Planning activities are..... (choose four)
Learns about the Auditee's mission, objective and process
Define Audit objective and scope
Develop Audit strategy
Conclusion of Audit
Conduct risk Assessment
The responsibilities of Audit Guide are:
Facilitating of Audit activities
Maintaning logistics
Ensurethatsafetypoliciesare observed
Witnessing the audit process on behalf of the auditee
All of above are TRUE
The "Bank X" has a Business Continuity Plan, but there is NO Evidence that is has been regularly evaluated through exercises and test.
Which control of Annex-A of ISO/IEC 27001:2022 did not generate objective evidence?
8.12
5.30
7.3
8.20
Which of the statement do you agree with?
An Audit Team should be selected, considering the academic knowledge required to achieve the objectives
An Audit Team should be selected, considering degree of commitment to achieve the objectives
An Audit Team should be selected, considering competency required to achieve the objectives
An Audit Team should be selected, considering the skill needed to achieve the objectives
The Auditor identifies that the Organization has not defined the process for conducting information security risk assessment / appraisal against information loss of confidentiality, integrity and availability.
Which clause of ISO/IEC 27001:2022 is being breached?
8.16
8.3
6.1.3
6.1.2
The basis for audit impartiality and objectivity of audit findings is:
an element for decision making in information security risk
a principle of auditing
an element for the presentation of the audit report
an element for the presentation of the audit scope
The assignment of functions of the audit team is a responsibility of:
The audit manager of the Organization.
The person(s) managing the audit program.
The top management of the Organization.
The assigned lead auditor.
According to ISO 19011:2018, third party audits:
They are carried out by independent auditing organizations, such as those
providing certification/registration of conformity or government agencies.
These are carried out exclusively by internal audit.
These are carried by parties that have an interest in the organization, such as customers, or by others on their behalf.
They are carried out by or on behalf of the organization itself.
