ISO/IEC 27001 LEAD AUDITOR - LATEST VERSION EXAM PREP – 149
VERIFIED QUESTIONS AND ANSWERS - COMPLETE COVERAGE
1. What is the aim of laws about intellectual property rights?
ANSWER : A. Protecting certain intangible assets
2. Which of the following is one of the objectives of the privacy protection policy?
ANSWER : A. To increase awareness regarding the legal requirements for protecting
personal information
3. When does the surveillance audit take place?
ANSWER : C. After obtaining certification
4. According to ISO 9000, what is an asset?
ANSWER : A. Item or entity that has potential or actual value to an organization
5. What is the difference between specifications and records?
ANSWER : A. Specifications are documents that state requirements, whereas records are
documents that state achieved results
6. A former employee of Company A has gained unauthorized access to the company's
sensitive information. What does this present?
ANSWER : A. A threat that has the potential to harm the assets of the organization, such as
information or systems
7. With which of the following principles does an organization comply if it ensures that
only authorized users have access to their sensitive data?
ANSWER : A. Confidentiality
8. What does the integrity principle entail?
ANSWER : B. That information is accurate and safe from unauthorized access
9. Which of the options below represents an example of a vulnerability?
ANSWER : A. Unencrypted data
, 10. What can have an impact on the availability of information?
ANSWER : C. Performance degradation
11. An organization has clearly defined the security procedures and uses an access control
software to avoid unauthorized access of the personnel to its confidential data. What is
the function of these security controls?
ANSWER : A. To prevent the occurrence of incidents
12. To which classification of security controls does the implementation of patches after the
identification of system vulnerabilities belong?
ANSWER : B. Corrective by function and technical by type
13. What is one of the main purposes of implementing an ISMS?
ANSWER : C. To reduce information security risks
14. Which of the statements below regarding the ISMS scope is correct?
ANSWER : C. The ISMS scope must be available as documented information
15. Who is responsible for establishing the information security policy according to
ISO/IEC 27001?
ANSWER : A. The top management
16. What criteria should be considered when selecting a risk assessment methodology?
ANSWER : B. Costs and availability of supporting software tools
17. An organization has decided to move its information-processing facilities to a place
where the risk of flooding is low. What option of risk treatment is this?
ANSWER : A. Risk avoidance
18. Why should an organization draft a Statement of Applicability?
ANSWER : A. To document the justifications for the inclusion and exclusion of Annex A
controls
19. The risk that remains after risk treatment is known as:
ANSWER : C. Residual risk
20. Webos provided an updated version that included migrating to a database to solve
encryption, authentication, and high availability problems. What was one of the issues
they aimed to solve?
VERIFIED QUESTIONS AND ANSWERS - COMPLETE COVERAGE
1. What is the aim of laws about intellectual property rights?
ANSWER : A. Protecting certain intangible assets
2. Which of the following is one of the objectives of the privacy protection policy?
ANSWER : A. To increase awareness regarding the legal requirements for protecting
personal information
3. When does the surveillance audit take place?
ANSWER : C. After obtaining certification
4. According to ISO 9000, what is an asset?
ANSWER : A. Item or entity that has potential or actual value to an organization
5. What is the difference between specifications and records?
ANSWER : A. Specifications are documents that state requirements, whereas records are
documents that state achieved results
6. A former employee of Company A has gained unauthorized access to the company's
sensitive information. What does this present?
ANSWER : A. A threat that has the potential to harm the assets of the organization, such as
information or systems
7. With which of the following principles does an organization comply if it ensures that
only authorized users have access to their sensitive data?
ANSWER : A. Confidentiality
8. What does the integrity principle entail?
ANSWER : B. That information is accurate and safe from unauthorized access
9. Which of the options below represents an example of a vulnerability?
ANSWER : A. Unencrypted data
, 10. What can have an impact on the availability of information?
ANSWER : C. Performance degradation
11. An organization has clearly defined the security procedures and uses an access control
software to avoid unauthorized access of the personnel to its confidential data. What is
the function of these security controls?
ANSWER : A. To prevent the occurrence of incidents
12. To which classification of security controls does the implementation of patches after the
identification of system vulnerabilities belong?
ANSWER : B. Corrective by function and technical by type
13. What is one of the main purposes of implementing an ISMS?
ANSWER : C. To reduce information security risks
14. Which of the statements below regarding the ISMS scope is correct?
ANSWER : C. The ISMS scope must be available as documented information
15. Who is responsible for establishing the information security policy according to
ISO/IEC 27001?
ANSWER : A. The top management
16. What criteria should be considered when selecting a risk assessment methodology?
ANSWER : B. Costs and availability of supporting software tools
17. An organization has decided to move its information-processing facilities to a place
where the risk of flooding is low. What option of risk treatment is this?
ANSWER : A. Risk avoidance
18. Why should an organization draft a Statement of Applicability?
ANSWER : A. To document the justifications for the inclusion and exclusion of Annex A
controls
19. The risk that remains after risk treatment is known as:
ANSWER : C. Residual risk
20. Webos provided an updated version that included migrating to a database to solve
encryption, authentication, and high availability problems. What was one of the issues
they aimed to solve?