Weekend Sale 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sale65best

Free PECB ISO-IEC-27001-Lead-Auditor Practice Exam with Questions & Answers | Set: 8

Questions 71

Select a word from the following options that best completes the sentence:

To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

ISO-IEC-27001-Lead-Auditor Question 71

Options:
PECB ISO-IEC-27001-Lead-Auditor Premium Access
Questions 72

You are performing an ISMS audit at a residential nursing home (ABC) that provides healthcare services. The next

step in your audit plan is to verify the information security of ABC's healthcare mobile app development, support,

and lifecycle process. During the audit, you learned the organization outsourced the mobile app development to a

professional software development company with CMMI Level 5, ITSM (ISO/IEC 20000-1), BCMS (ISO 22301) and

ISMS (ISO/IEC 27001) certified.

The IT Manager presented the software security management procedure and summarised the process as following:

The mobile app development shall adopt "security-by-design" and "security-by-default" principles, as a minimum.

The following security functions for personal data protection shall be available:

Access control.

Personal data encryption, i.e., Advanced Encryption Standard (AES) algorithm, key lengths: 256 bits; and

Personal data pseudonymization.

Vulnerability checked and no security backdoor

You sample the latest Mobile App Test report, details as follows:

ISO-IEC-27001-Lead-Auditor Question 72

The IT Manager explains the test results should be approved by him according to the software security management procedure. The reason why the encryption and pseudonymisation functions failed is that these functions heavily slowed down the system and service performance. An extra 150% of resources are needed to cover this. The Service Manager agreed that access control is good enough and acceptable. That's why the Service Manager signed the approval.

You are preparing the audit findings. Select the correct option.

Options:
A.

There is a nonconformity (NC). The organisation and developer do not perform acceptance tests. (Relevant to clause 8.1, control A.8.29)

B.

There is a nonconformity (NC). The organisation and developer perform security tests that fail. (Relevant to clause 8.1, control A.8.29)

C.

There is a nonconformity (NC). The Service Manager does not comply with the software security management procedure. (Relevant to clause 8.1, control A.8.30)

D.

There is NO nonconformity (NC). The Service Manager makes a good decision to continue the service. (Relevant to clause 8.1, control A.8.30)

Questions 73

Select the word that best completes the sentence:

ISO-IEC-27001-Lead-Auditor Question 73

Options:
Questions 74

Which two of the following standards are used as ISMS third-party certification audit criteria?

Options:
A.

ISO/IEC 27002

B.

ISO/IEC 20000-1

C.

ISO 19011

D.

ISO/IEC 27001

E.

Relavent legal, statutory, and regulatory requirements

F.

ISO/IEC 17021-1

Questions 75

How does the use of new technologies such as big data impact auditing?

Options:
A.

It presents new challenges, for example, combining structured and unstructured data

B.

It enhances the audit quality by enabling auditors to collect higher quality audit evidence

C.

It causes significant disruptions, for example, introducing data that is too large or complex for processing by traditional database management tools

Questions 76

You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the company's risk management process.

He is attempting to update the current documentation to make it easier for other managers to understand, however, it is clear from your discussion he is confusing several key terms.

You ask him to match each of the descriptions with the appropriate risk term. What should the correct answers be?

ISO-IEC-27001-Lead-Auditor Question 76

Options:
Questions 77

You are the audit team leader conducting a third-party audit of an online insurance organisation. During Stage 1, you found that the organisation took a very cautious risk approach and included all the information security controls in ISO/IEC 27001:2022 Appendix A in their Statement of Applicability.

During the Stage 2 audit, your audit team found that there was no evidence of the implementation of the three controls (5.3 Segregation of duties, 6.1 Screening, 7.12 Cabling security) shown in the extract from the Statement of Applicability. No risk treatment plan was found.

ISO-IEC-27001-Lead-Auditor Question 77

Select three options for the actions you would expect the auditee to take in response to a

nonconformity against clause 6.1.3.e of ISO/IEC 27001:2022.

Options:
A.

Allocate responsibility for producing evidence to prove to auditors that the controls are implemented.

B.

Compile plans for the periodic assessment of the risks associated with the controls.

C.

Implement the appropriate risk treatment for each of the applicable controls.

D.

Incorporate written procedures for the controls into the organisation's Security Manual.

E.

Remove the three controls from the Statement of Applicability.

F.

Revise the relevant content in the Statement of Applicability to justify their exclusion.

G.

Revisit the risk assessment process relating to the three controls.

Questions 78

To verify conformity to control 8.15 Logging of ISO/IEC 27001 Annex A, the audit team verified a sample of server logs to determine if they can be edited or deleted. Which audit procedure was used?

Options:
A.

Analysis

B.

Sampling

C.

Observation

Questions 79

PayBell, a finance corporation, is using an accounting software to track financial transactions. The software can be accessed from anywhere with an internet connection. It also enables PayBell's employees to easily collaborate with each other to ensure accurate financial reporting. What type of services is PayBell using?

Options:
A.

Machine learning

B.

Cloud computing

C.

Artificial intelligence

Questions 80

You are performing an ISMS audit at a nursing home where residents always wear an electronic wristband for monitoring their location, heartbeat, and blood pressure. The wristband automatically uploads this data to a cloud server for healthcare monitoring and analysis by staff.

You now wish to verify that the information security policy and objectives have been established by top management. You are sampling the mobile device policy and identify a security objective of this policy is "to ensure the security of teleworking and use of mobile devices" The policy states the following controls will be applied in order to achieve this.

Personal mobile devices are prohibited from connecting to the nursing home network, processing, and storing residents'

data.

The company's mobile devices within the ISMS scope shall be registered in the asset register.

The company's mobile devices shall implement or enable physical protection, i.e., pin-code protected screen lock/unlock,

facial or fingerprint to unlock the device.

The company's mobile devices shall have a regular backup.

To verify that the mobile device policy and objectives are implemented and effective, select three options for your audit trail.

Options:
A.

Interview the reception personnel to make sure all visitor and employee bags are checked before entering the nursing home

B.

Review visitors' register book to make sure no visitor can have their personal mobile phone in the nursing home

C.

Review the internal audit report to make sure the IT department has been audited

D.

Review the asset register to make sure all personal mobile devices are registered

E.

Sampling some mobile devices from on-duty medical staff and validate the mobile device information with the asset register

F.

Review the asset register to make sure all company's mobile devices are registered

G.

Interview the supplier of the devices to make sure they are aware of the ISMS policy