ISO-IEC-27001-Lead-Auditor PECB
Rate this post

[Jan-2025] ISO-IEC-27001-Lead-Auditor PDF Dumps Extremely Quick Way Of Preparation

Download ISO-IEC-27001-Lead-Auditor Dumps (2025) – Free PDF Exam Demo

NO.118 You are an experienced ISMS audit team leader. You are currently conducting a third-party surveillance audit of an international haulage organisation. You have sampled four internal audit reports which state:
Report 1 – Auditor: Mr James.
Over the year the organisation has failed to meet its promised delivery dates on 23 occasions out of 100. This is against a target of ‘95% of deliveries on time’.
Grading – Minor
Corrective Action due: Within 9 months.
Report 2 – Auditor: Mr James.
Between January and March, it was noted 125 complaints were received about the Service Desk Team. Clients accused them of being rude and unresponsive.
Grading – Minor
Corrective Action due: Within 12 months.
Report 3 – Auditor: Mr James.
Of the 40 customer orders received last month, 38 were correctly processed. Of the remaining 2, one was missing a signature and one was missing a date.
Grading –
Corrections due: Within 3 weeks
Report 4 – Auditor: Mr Rogers.
Of the 30 personnel records examined, 26 were found to be fully completed whilst the remaining 4 were all missing the individual’s start date.
Grading – Major
Corrections due: Within 1 week
Which four of the options demonstrate the concerns you would have about these reports?

 
 
 
 
 
 
 
 

NO.119 You are an ISMS audit team leader preparing to chair a closing meeting following a third-party surveillance audit. You are drafting a closing meeting agenda setting out the topics you wish to discuss with your auditee.
Which one of the following would be appropriate for inclusion?

 
 
 
 

NO.120 In the event of an Information security incident, system users’ roles and responsibilities are to be observed, except:

 
 
 
 

NO.121 Please match the roles to the following descriptions:

To complete the table click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable test from the options below. Alternatively, you may drag and drop each option to the appropriate blank section.

NO.122 Information Security is a matter of building and maintaining ________ .

 
 
 
 

NO.123 Which one of the following options best describes the purpose of a Stage 2 audit?

 
 
 
 

NO.124 Which one of the following options is the definition of an interested party?

 
 
 
 

NO.125 You are an ISMS audit team leader assigned by your certification body to carry out a follow-up audit of a Data Centre client.
According to ISO 19011:2018, the purpose of a follow-up audit is to verify which one of the following?

 
 
 
 

NO.126 You are performing an ISMS audit at a residential nursing home that provides healthcare services and are reviewing the Software Code Management (SCM) system. You found a total of 10 user accounts on the SCM.
You confirm that one of the users, Scott, resigned 9-months
ago. The SCM System Administrator confirmed Scott’s last check-out of the source code was found 1 month ago. He was using one of the uthorized desktops from the local network in a secure area.
You check with the user de-registration procedure which states “Managers have to make sure of deregistration of the user account and authorisation immediately from the relevant ICT system and/or equipment after resignation approval.” There was no deregistration record for user Scott.
The IT Security Manager explains that Scott still comes back to the office every month after he resigned to provide support on source code maintenance. That’s why his account on SCM still exists.
You would like to investigate other areas further to collect more audit evidence. Select three options that would not be valid audit trails.

 
 
 
 
 
 
 
 

NO.127 Integrity of data means

 
 
 

NO.128 Objectives, criteria, and scope are critical features of a third-party ISMS audit. Which two issues are audit objectives?

 
 
 
 
 
 

NO.129 Which two of the following statements are true?

 
 
 

NO.130 Which of the following is not a type of Information Security attack?

 
 
 
 

NO.131 You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services.
The next step in your audit plan is to verify the information security of ABC’s healthcare mobile app development, support, and lifecycle process. During the audit, you learned the organisation outsourced the mobile app development to a professional software development organisation with CMMI Level 5, ITSM (ISO/IEC 20000-1), BCMS (ISO 22301) and ISMS (ISO/IEC 27001) certified.
The IT Manager presents the software security management procedure and summarises the process as follows:
The mobile app development shall adopt “security-by-design” and “security-by-default” principles, as a minimum. The following security functions for personal data protection shall be available:
Access control.
Personal data encryption, i.e., Advanced Encryption Standard (AES) algorithm, key lengths: 256 bits; and Personal data pseudonymization.
Vulnerability checked and no security backdoor
You sample the latest Mobile App Test report – Reference ID: 0098, details as follows:


You would like to investigate other areas further to collect more audit evidence. Select three options that will not be in your audit trail.

 
 
 
 
 
 
 
 

NO.132 Select the words that best complete the sentence:
To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

NO.133 Select the word that best completes the sentence:

NO.134 You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services.
You find all nursing home residents wear an electronic wristband for monitoring their location, heartbeat, and blood pressure always. You learned that he electronic wristband automatically uploads all data to the artificial intelligence (AI) cloud server for healthcare monitoring and analysis by healthcare staff.
To verify the scope of ISMS, you interview the management system representative (MSR) who explains that the ISMS scope covers an outsourced data center.
Select four options for the clauses and/or controls of ISO/IEC 27001:2022 that are directly relevant to the verification of the scope of the ISMS.

 
 
 
 
 
 
 
 

Enhance your career with ISO-IEC-27001-Lead-Auditor PDF Dumps – True PECB Exam Questions: https://www.examstorrent.com/ISO-IEC-27001-Lead-Auditor-exam-dumps-torrent.html

         

Related Links: myportal.utt.edu.tt justpaste.me scalar.usc.edu myportal.utt.edu.tt www.qualitydigest.com myportal.utt.edu.tt

admin

Leave a Reply

Your email address will not be published. Required fields are marked *

Enter the text from the image below