4.2/5 - (4 votes)

Study HIGH Quality ISO-IEC-27001-Lead-Auditor  Free Study Guides and Exams Tutorials

Download PECB ISO-IEC-27001-Lead-Auditor Exam Dumps to Pass Exam Easily

NEW QUESTION 50
An employee caught with offense of abusing the internet, such as P2P file sharing or video/audio streaming, will not receive a warning for committing such act but will directly receive an IR.

 
 

NEW QUESTION 51
You are the audit team leader conducting a third-party audit of an online insurance company. During Stage 1, you found that the organization took a very cautious risk approach and included all the information security controls in ISO/IEC 27001:2022 Appendix A in their Statement of Applicability.
During the Stage 2 audit, your audit team found that there was no evidence of a risk treatment plan for the implementation of the three controls (5.3 Segregation of duties, 6.1 Screening, 7.12 Cabling security). You raise a nonconformity against clause 6.1.3.e of ISO 27001:2022.
At the closing meeting, the Technical Director issues an extract from an amended Statement of Applicability (as shown) and asks for the nonconformity to be withdrawn.

Select three options of the correct responses of an audit team leader to the request of the Technical Director.

 
 
 
 
 
 
 
 

NEW QUESTION 52
During a Stage 1 audit opening meeting, the Management System Representative (MSR) asks to extend the audit scope to include a new site overseas which they have expanded into since the certification application was made.
Select two options for how the auditor should respond.

 
 
 
 
 
 

NEW QUESTION 53
What type of legislation requires a proper controlled purchase process?

 
 
 
 

NEW QUESTION 54
You are an experienced ISMS audit team leader guiding an auditor in training. She asks you about the grading of nonconformities in audit reports. You decide to test her knowledge by asking her which four of the following statements are true.

 
 
 
 
 
 
 
 

NEW QUESTION 55
What is a repressive measure in case of a fire?

 
 
 

NEW QUESTION 56
Which of the following statements are correct for Clean Desk Policy?

 
 
 
 

NEW QUESTION 57
CEO sends a mail giving his views on the status of the company and the company’s future strategy and the CEO’s vision and the employee’s part in it. The mail should be classified as

 
 
 
 

NEW QUESTION 58
How is the purpose of information security policy best described?

 
 
 
 

NEW QUESTION 59
You are an experienced ISMS audit team leader. During the conducting of a third-party surveillance audit, you decide to test your auditee’s knowledge of ISO/IEC 27001’s risk management requirements.
You ask her a series of questions to which the answer is either ‘that is true’ or ‘that is false’. Which four of the following should she answer ‘that is true’?

 
 
 
 
 
 
 
 

NEW QUESTION 60
You are an ISMS audit team leader who has been assigned by your certification body to carry out a follow-up audit of a client. You are preparing your audit plan for this audit.
Which two of the following statements are true?

 
 
 
 
 
 

NEW QUESTION 61
You are conducting a third-party surveillance audit when another member of the audit team approaches you seeking clarification. They have been asked to assess the organisation’s application of control 5.7 – Threat Intelligence. They are aware that this is one of the new controls introduced in the 2022 edition of ISO/IEC
27001, and they want to make sure they audit the control correctly.
They have prepared a checklist to assist them with their audit and want you to confirm that their planned activities are aligned with the control’s requirements.
Which three of the following options represent valid audit trails?

 
 
 
 
 
 
 
 

NEW QUESTION 62
In acceptable use of Information Assets, which is the best practice?

 
 
 
 

NEW QUESTION 63
You receive an E-mail from some unknown person claiming to be representative of your bank and asking for your account number and password so that they can fix your account. Such an attempt of social engineering is called

 
 
 
 

NEW QUESTION 64
The following are the guidelines to protect your password, except:

 
 
 
 

NEW QUESTION 65
You are performing an ISMS audit at a residential nursing home that provides healthcare services and are reviewing the Software Code Management (SCM) system. You found a total of 10 user accounts on the SCM.
You confirm that one of the users, Scott, resigned 9-months
ago. The SCM System Administrator confirmed Scott’s last check-out of the source code was found 1 month ago. He was using one of the uthorized desktops from the local network in a secure area.
You check with the user de-registration procedure which states “Managers have to make sure of deregistration of the user account and authorisation immediately from the relevant ICT system and/or equipment after resignation approval.” There was no deregistration record for user Scott.
The IT Security Manager explains that Scott still comes back to the office every month after he resigned to provide support on source code maintenance. That’s why his account on SCM still exists.
You would like to investigate other areas further to collect more audit evidence. Select three options that would not be valid audit trails.

 
 
 
 
 
 
 
 

NEW QUESTION 66
Which two of the following phrases are ‘objectives’ in relation to a first-party audit?

 
 
 
 
 
 

NEW QUESTION 67
In the context of a management system audit, please identify the sequence of a typical process of collecting and verifying information. The first one has been done for you.

NEW QUESTION 68
Objectives, criteria, and scope are critical features of a third-party ISMS audit. Which two issues are audit objectives?

 
 
 
 
 
 

NEW QUESTION 69
What is the relationship between data and information?

 
 

NEW QUESTION 70
CMM stands for?

 
 
 
 

NEW QUESTION 71
What is the worst possible action that an employee may receive for sharing his or her password or access with others?

 
 
 
 

NEW QUESTION 72
Select the words that best complete the sentence below to describe audit resources:

NEW QUESTION 73
What is the name of the system that guarantees the coherence of information security in the organization?

 
 
 
 

NEW QUESTION 74
What is the goal of classification of information?

 
 
 

Get 100% Real Free ISO 27001 ISO-IEC-27001-Lead-Auditor Sample Questions: https://www.testkingit.com/PECB/latest-ISO-IEC-27001-Lead-Auditor-exam-dumps.html

Related Links: www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw www.stes.tyc.edu.tw scalar.usc.edu www.stes.tyc.edu.tw