Spring Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: buysanta

Exact2Pass Menu

PECB Certified ISO/IEC 27001 2022 Lead Auditor exam

Last Update 19 hours ago Total Questions : 418

The PECB Certified ISO/IEC 27001 2022 Lead Auditor exam content is now fully updated, with all current exam questions added 19 hours ago. Deciding to include ISO-IEC-27001-Lead-Auditor practice exam questions in your study plan goes far beyond basic test preparation.

You'll find that our ISO-IEC-27001-Lead-Auditor exam questions frequently feature detailed scenarios and practical problem-solving exercises that directly mirror industry challenges. Engaging with these ISO-IEC-27001-Lead-Auditor sample sets allows you to effectively manage your time and pace yourself, giving you the ability to finish any PECB Certified ISO/IEC 27001 2022 Lead Auditor exam practice test comfortably within the allotted time.

Question # 41

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their location, heartbeat, and blood pressure always. You learned that the electronic wristband automatically uploads all data to the artificial intelligence (AI) cloud server for healthcare monitoring and analysis by healthcare staff.

To verify the scope of ISMS, you interview the management system representative (MSR) who explains that the ISMS scope covers an outsourced data center.

Select three options for the audit evidence you need to find to verify the scope of the ISMS.

A.

The auditee has identified the resident ' s needs and expectations on the facility and environmental safety

B.

The auditee has ISO 9001 certification

C.

The auditee has identified the governmental authorities ' needs and expectations on healthcare services and patient data handling

D.

The auditee has identified the resident ' s needs and expectations on how they should protect the resident ' s personal data

E.

The auditee has identified the resident ' s needs and expectations on the comfort facility, medical professional ' s competence, and clean environment

F.

The auditee has identified the resident ' s needs and expectations on healthcare medical treatment services

G.

The IT service agreement with the data center where the artificial intelligence (AI) cloud server is located

Question # 42

You are an experienced ISMS audit team leader. You are providing an introduction to ISO/IEC 27001:2022 to a class of Quality Management System Auditors who are seeking to retrain to enable them to carry out information security management system audits.

You ask them which of the following characteristics of information does an information security management system seek to preserve?

Which three answers should they provide?

A.

Clarity

B.

Accessibility

C.

Completeness

D.

Importance

E.

Availability

F.

Confidentiality

G.

Integrity

Question # 43

ISMS (1)---------------helps determine (2)--------------,

A.

(1) Continual improvement, (2) the effectiveness of corrective actions

B.

Q (1) Management review, (2) opportunities for continual improvement

C.

(1) Internal audit, (2) the ISMS scope

Question # 44

You ask the IT Manager why the organisation still uses the mobile app while personal data

encryption and pseudonymisation tests failed. Also, whether the Service Manager is authorised to approve the test.

The IT Manager explains the test results should be approved by him according to the software security management procedure. The reason why the encryption and pseudonymisation functions failed is that these functions heavily slowed down the system and service performance. An extra 150% of resources are needed to cover this. The Service Manager agreed that access control is good enough and acceptable. That ' s why the Service Manager signed the approval.

You are preparing the audit findings. Select the correct option.

    There is a nonconformity (NC). The organisation and developer do not perform acceptance tests. (Relevant to clause 8.1, control A.8.29)

A.

There is a nonconformity (NC). The Service Manager does not comply with the software security management procedure. (Relevant to clause 8.1, control A.8.30)

B.

There is a nonconformity (NC). The organisation and developer perform security tests that fail. (Relevant to clause 8.1, control A.8.29)

C.

There is NO nonconformity (NC). The Service Manager makes a good decision to continue the service. (Relevant to clause 8.1, control A.8.30)

Question # 45

PayBell, a finance corporation, is using an accounting software to track financial transactions. The software can be accessed from anywhere with an internet connection. It also enables PayBell ' s employees to easily collaborate with each other to ensure accurate financial reporting. What type of services is PayBell using?

A.

Machine learning

B.

Cloud computing

C.

Artificial intelligence

Question # 46

Question

During an ISO/IEC 27001 certification audit, the audit team leader failed to follow established best practices for conducting the audit. In addition, they lacked the necessary expertise to assess some of the complex areas of the ISMS, leading to suboptimal results. While the audit findings were still reported, some areas of the audit are considered weak and the audit does not fully adhere to the required procedures.

Which level of responsibility does this scenario represent in the case of tortious acts?

A.

Ordinary negligence

B.

Gross negligence

C.

No negligence

Question # 47

Question

A certification body decided to conduct an on-site evaluation of one of its auditors while they perform an ISO/IEC 27001 certification audit for a client.

Is this permitted?

A.

Yes, but the certification body must minimize disturbance to the normal processes of certification.

B.

Yes, but the client must temporarily suspend business operations until the on-site evaluation is completed.

C.

No, the evaluation must be conducted remotely to prevent disturbance to the normal processes of certification.

Question # 48

During an opening meeting of a Stage 2 audit, the Managing Director of the client organisation invites the audit team to view a new organisation video lasting 45 minutes.

Which two of the following responses should the audit team leader make?

A.

State that the audit team leader will stay behind after the opening meeting to view the video on behalf of the team

B.

Advise the Managing Director that the audit team agrees to his request

C.

Advise the Managing Director that the audit team has to keep to the planned schedule

D.

Invite the Managing Director to the auditors ' hotel for a viewing that evening.

E.

Suggest that the last five minutes of the video could be viewed to provide a flavour of its content

F.

Suggest that the video could be viewed during a refreshment break

Question # 49

Question

Which statement regarding the evaluation of materiality is NOT correct?

A.

During the initial contact phase, materiality is taken into account to determine the duration of the audit based on the inherent risks to the organization.

B.

Auditors may evaluate the materiality of processes or assets during the stage 2 audit, but they cannot adjust the audit plan based on the results.

C.

During the stage 1 audit, auditors identify key processes and determine which processes to emphasize during the on-site audit.

Question # 50

You are performing an ISMS audit at a residential nursing home called ABC that provides healthcare services. You find all nursing home residents wear an electronic wristband for monitoring their location, heartbeat, and blood pressure always. You learned that the electronic wristband automatically uploads all data to the artificial intelligence (AI) cloud server for healthcare monitoring and analysis by healthcare staff.

To verify the scope of ISMS, you interview the management system representative (MSR) who explains that the ISMS scope covers an outsourced data center.

Select one option of the correct statement which defines the content of the scope of the ISMS.

A.

The ISMS scope should not cover external service providers because they can have compliance difficulties with the information security policy and requirements

B.

The ISMS scope should take any information security issues that have occurred and any interested parties ' requirements into consideration

C.

The most likely ISMS scope is to cover the IT department and the outsourced data centre

D.

The organisation should only follow the government ' s recommendation, i.e., legal and legislation to define the ISMS scope

Go to page: