wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Trial CertiProf Lead Auditor#2

Total questions: 40

Worksheet time: 21mins

Name
Class
Date
1.

The results of the audit:

a) Are the evaluation results of the audit evidence gathered against the audit criteria.

b) They are considered findings and can be classified as conformity or nonconformity.

c) It is an audit method to reach reliable conclusions.

d) If the audit criteria are selected from legal requirements or regulatory requirements, the audit finding is referred to as compliance or noncompliance.

a)

B and C only

b)

A and C only

c)

All of the above

2.

It establishes that the organization must define a risk assessment process:

a)

Clause 6.1.1

b)

Clause 6.1.2

c)

Clause 8.1

d)

B and C are valid

3.

It establishes that the organization must implement the risk treatment

process:

a)

Clause 6.1.2

b)

Clause 6.1.3

c)

Clause 8.3

d)

B and C are valid

4.

These are risk management strategies except:

a)

Mitigate

b)

Transfer

c)

Assume

d)

Retain

e)

Control

5.

Type of strategy where the implementation of a control to reduce the level of risk is defined:

a)

Mitigate

b)

Transfer

c)

Assume

d)

Retain

6.

The “Statement of Applicability” must contain:

a)

Controls necessary to reduce the level of risk.

b)

The justification for the inclusion of the controls considered necessary.

c)

Whether or not the necessary controls are implemented.

d)

Justification for exclusions from any of the controls in annex A.

e)

All are valid

7.

According to ISO 19011:2018 audit is defined as a systematic, independent, documented process for obtaining evidence and evaluating it objectively, in order to determine the extent to which the audit criteria are met.

a)

True

b)

False

8.

ISO 19011:2018 establishes as methods for assessing auditors:

a)

A. Observation

b)

B. Examination

c)

C. Interview

d)

D. Telephone call

e)

E. All except D

9.

During the audit, professional behavior by the auditor is desired, e.g., the auditor is expected to be open-minded, i.e., willing to consider alternative ideas or points of view.

a)

True

b)

False

10.

 Defining objectives, scope and criteria for each individual audit, Selecting audit methods, and Defining and implementing the necessary operational controls for the supervision of the audit program are part of the activities for:

a)

Define the scope of the ISMS.

b)

Correctly create the ISMS policy.

c)

Define the audit program.

11.

They are responsible for assigning responsibilities to the audit Team Leader:

a)

Top Management

b)

The person responsible for the management system.

c)

Senior management.

d)

The person(s) managing the audit program.

12.

They should ensure that the following activities are carried out as part of the management of the results of the audit program:

1. Evaluation of the achievement of the objectives for each audit within the audit program.

2. Review and approval of audit reports on compliance with the scope and objectives of the audit.

3. Reviewing the effectiveness of actions taken to address audit findings.

4. Distribution of audit reports to relevant stakeholders.

5. Determination of the need for any follow-up audits.

a)

Members of the audit team.

b)

Everyone in the organization.

c)

The person(s) managing the audit program.

13.

The audit plan describes:

a)

The activities and arrangements for each planned audit.

b)

A planning over a given period of time of one or more audits.

c)

Both are valid since there is a relation between the program and the audit plan.

14.

The audit program describes:

a)

The activities and arrangements for each planned audit

b)

A planning over a given period of time of one or more audits.

c)

Both are valid since there is a relation between the program and the audit plan.

15.

In relation to requirement 4.2 of ISO IEC 27001: 2022, it is established that the organization shall determine:

a)
  • Which of these requirements will be addressed through the Information Security
    Management System.

b)

Stakeholders that are relevant to the Information Security Management System.

c)
  • The relevant requirements of these stakeholders.

d)

All of the above.

16.

 During an audit the auditee provides little information and constantly rephrases the auditor's questions:

a)

Considered difficult situations that the auditor must be able to handle.

b)

Issues that the lead auditor must resolve.

c)

Conditions for termination of the audit.

17.

When trying to retrieve a "BACKUP" it did not restore the information, therefore no ISMS information was found. Which control of Annex A of ISO IEC 27001:2022 was not adequately complied with?

a)

8.14.

b)

8.13.

c)

5.1.

d)

8.20.

18.

An opportunity for improvement is not considered a nonconformity but may be reviewed by the organization, when deemed appropriate, to improve the effectiveness of the process.

a)

True

b)

False

19.

The following are methods for performing audits.

1. On site.

2. Remote.

3. With human interaction

4. No human interaction.

a)

Only 1 and 2

b)

All except 4

c)

Only 3 and 4

d)

All of above

20.

The audit team leader, in consultation with the audit team, assigns each team member responsibility for:

1. Auditing processes.

2. Activities.

3. Functions.

4. Developing the audit program.

a)

Only 1 and 2

b)

All except 4

c)

Only 3 and 4

d)

All

21.

A retired employee of the Organizations remain active on the access platform after one month.

Which control in Annex A of ISO/IEC 27001:2022 is not meet

a)

a) 5.18

b)

b) 5.15

c)

c) 5.16

d)

a and c

22.

A laptop was stolen from a hotel where the Information security officer was lecturing.

Which control of Annex-A ISO/IEC 27001 should or must this PC have had?

a)

7.9

b)

5.10

c)

5.1

d)

7.8

23.

Which control of Annex-A ISO/IEC 27001:2022 ensure that information system are designed, implemented and operated securely within the development life cycle

a)

5.1

b)

8.20

c)

8.27

d)

8.25

24.

During a visit to the physical security facilities, the Auditor find that the PC has different date and time.

Which control in Annex-A ISO/IEC 27001:2022 has not been properly implemented?

a)

8.14

b)

5.1

c)

8.17

d)

5.4

25.

The results of previous internal or external audits should be considered to establish:

a)
  • A. The objectives of the audit program.

b)

• D. The documents that the audited process must have.

c)

C. A and B.

d)
  • B. The scope of the audit program.

26.

In the morning hours people were asked to work from home by connecting from a secure VPN, since there was no electricity supply in the Company. Unfortunately, the DATACENTER where sensitive information is stored was connected to a UPS that failed within two hours of being turned on and mission critical activities could not be carried out.

The company's penalties were large because it had ensured that the availability was 99.7%.

What is the control of ANNEX A of ISO IEC 27001:2022 that most applies to this case?

a)

8.14.

b)
  • 5.1.

c)
  • 6.3.

d)
  • 7.2.

27.

Verifying the relevance and accuracy of the information collected is a mandatory activity of:

a)

The auditee to provide accurate information to the auditor.

b)

The person(s) managing the audit program to carry out the audit program.

c)

The Auditor as a skill and ability to ensure that audits are performed in a consistent and systematic manner.

d)

The internal auditor to carry out the audit plan.

28.

When an employee is to be terminated, which of the following should be done?

a)

Disabled the employee’s network access just as they are informed of the termination

b)

Inform the employee a few hours before they are officially terminated.

c)

Send out a broadcast email informing everyone that a specific employee is to be terminated

d)

Wait until you and the employee are the only people remaining in the building before announcing termination

29.

What is performance evaluation?

a)

Process of determining the status of a system, process, or activity

b)

Process of determining measurable results

c)

Process of determining a value

d)

Process of determining an IT Objectives

30.

They help to provide audit continuity, plan and effective audit, identify the most critical aspectsof the system, control the depth, continuity and pace of the audit

a)

Audit team

b)

Checklists

c)

Audit plans

d)

Audit program

31.

Conflict with the Auditee could be occurs during Audit process, such like... (choose four)

a)

Antagonism or lack of cooperations

b)

Budgeting

c)

Difference of opinions

d)

Work attitude

e)

Time wasted

32.

Which one is not the purpose of Opening Meeting?

a)

Confirmed the agreement of all participants

b)

Determine of Lead Auditor

c)

Introduce the Audit teams and their rules

d)

Ensure that all planned audit activities can be performed

33.

Audit Planning activities are..... (choose four)

a)

Learns about the Auditee's mission, objective and process

b)

Define Audit objective and scope

c)

Develop Audit strategy

d)

Conclusion of Audit

e)

Conduct risk Assessment

34.

The responsibilities of Audit Guide are:

a)

Facilitating of Audit activities

b)

Maintaning logistics

c)

Ensurethatsafetypoliciesare observed

d)

Witnessing the audit process on behalf of the auditee

e)

All of above are TRUE

35.

The "Bank X" has a Business Continuity Plan, but there is NO Evidence that is has been regularly evaluated through exercises and test.

Which control of Annex-A of ISO/IEC 27001:2022 did not generate objective evidence?

a)

8.12

b)

5.30

c)

7.3

d)

8.20

36.

Which of the statement do you agree with?

a)

An Audit Team should be selected, considering the academic knowledge required to achieve the objectives

b)

An Audit Team should be selected, considering degree of commitment to achieve the objectives

c)

An Audit Team should be selected, considering competency required to achieve the objectives

d)

An Audit Team should be selected, considering the skill needed to achieve the objectives

37.

The Auditor identifies that the Organization has not defined the process for conducting information security risk assessment / appraisal against information loss of confidentiality, integrity and availability.

Which clause of ISO/IEC 27001:2022 is being breached?

a)

8.16

b)

8.3

c)

6.1.3

d)

6.1.2

38.

The basis for audit impartiality and objectivity of audit findings is:

a)

an element for decision making in information security risk

b)

a principle of auditing

c)

an element for the presentation of the audit report

d)

an element for the presentation of the audit scope

39.

The assignment of functions of the audit team is a responsibility of:

a)
  1. The audit manager of the Organization.

b)
  1. The person(s) managing the audit program.

c)
  1. The top management of the Organization.

d)

The assigned lead auditor.

40.

According to ISO 19011:2018, third party audits:

a)

They are carried out by independent auditing organizations, such as those

providing certification/registration of conformity or government agencies.

b)
  • These are carried out exclusively by internal audit.

c)
  • These are carried by parties that have an interest in the organization, such as customers, or by others on their behalf.

d)

They are carried out by or on behalf of the organization itself.