ISO-IEC-27001-Lead-Auditor Exam Question 6
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password.
What kind of threat is this?
What kind of threat is this?
ISO-IEC-27001-Lead-Auditor Exam Question 7
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing meeting. During the final audit team meeting, as an audit team leader, you agree to report 2 minor nonconformities and 1 opportunity for improvement as below:

Select one option of the recommendation to the audit programme manager you are going to advise to the auditee at the closing meeting.

Select one option of the recommendation to the audit programme manager you are going to advise to the auditee at the closing meeting.
ISO-IEC-27001-Lead-Auditor Exam Question 8
Which three of the following options are an advantage of using a sampling plan for the audit?
ISO-IEC-27001-Lead-Auditor Exam Question 9
The computer room is protected by a pass reader. Only the System Management department has a pass.
What type of security measure is this?
What type of security measure is this?
ISO-IEC-27001-Lead-Auditor Exam Question 10
As the Information Security Management System audit team leader, you are conducting a second-party audit of an international logistics company on behalf of an online retailer.
During the audit, one of your team members reports a nonconformity relating to control 5.18 (Access rights) of Appendix A of ISO/IEC 27001:2022.
She found evidence that removing the server access protocols of 20 people who left in the last 3 months took up to 1 week whereas the policy required removing access within 24 hours of their departure.
When the auditee was asked why there was a delay in removing access they replied, 'no one was available in the IT department during that period as a result of COVID-19.
As soon as an IT officer became available the rights were removed.
You note that she intends to raise a minor non-conformity against Access rights control (5.18). How should you respond to this?
During the audit, one of your team members reports a nonconformity relating to control 5.18 (Access rights) of Appendix A of ISO/IEC 27001:2022.
She found evidence that removing the server access protocols of 20 people who left in the last 3 months took up to 1 week whereas the policy required removing access within 24 hours of their departure.
When the auditee was asked why there was a delay in removing access they replied, 'no one was available in the IT department during that period as a result of COVID-19.
As soon as an IT officer became available the rights were removed.
You note that she intends to raise a minor non-conformity against Access rights control (5.18). How should you respond to this?
