ISO 27001 CORRECT TEST PAPER QUESTIONS AND
ANSWERS SURE A+
✔✔1. Which auditing principle has AuditOrg applied in this case, "The findings helped
the auditors support their conclusions and report all audit activities truthfully and
accurately?"
A. Independence
B. Fair presentation
C. Confidentiality - ✔✔B. Fair presentation
✔✔1. How would you evaluate the level of responsibility demonstrated by AuditOrg's
auditors?
A. Ordinary negligence, since the auditors have demonstrated lack of diligence during
the audit
B. Gross negligence, since the auditors have demonstrated a total lack of diligence
during the audit
C. No negligence, since the auditors have demonstrated due diligence during the audit -
✔✔C. No negligence, since the auditors have demonstrated due diligence during the
audit
✔✔1. What is the main objective of stage 2 audit?
A. To review the internal audit activities
B. To evaluate the implementation of the ISMS
C. To verify the information security objectives of the ISMS - ✔✔B. To evaluate the
implementation of the ISMS
✔✔1. Which of the following is a step in audit planning?
A. Conducting risk assessment
B. Determining the audit criteria
C. Preparing the audit test plans - ✔✔A. Conducting risk assessment
✔✔1. How does the audit team select processes and systems to be tested?
, A. Based on the technical experts' advice
B. Based on audit procedures
C. Based on materiality - ✔✔C. Based on materiality
✔✔1. During the audit, documented information involving proprietary information was
protected at all times. Which principle of maintaining audit work documents has been
followed?
A. Confidentiality
B. Authorship
C. Conciseness - ✔✔A. Confidentiality
✔✔1. A well-designed documentation standard improves the overall quality of the audit.
A. True
B. False - ✔✔A. True
✔✔1. What is the main purpose of the opening meeting in an audit?
A. To obtain detailed information about management system-related processes
B. To verify audit evidence and obtain a reasonable level of assurance
C. To ensure that planned audit activities can be performed - ✔✔C. To ensure that
planned audit activities can be performed
✔✔1. The opening meeting agenda can include information on:
A. The availability of resources
B. The examination of documented information
C. The creation of audit test plans - ✔✔A. The availability of resources
✔✔1. The auditor has accessed logs to the server room. What source of information
was collected?
A. Documents
B. Observations
C. Records - ✔✔C. Records
✔✔1. How is audit evidence evaluated?
A. By comparing it against the audit criteria
B. By conducting quality review
C. By utilizing audit tests - ✔✔A. By comparing it against the audit criteria
✔✔1. The quality review of audit evidence will assure that the audit findings are reliable
and valid.
A. True
B. False - ✔✔B. False
✔✔1. How often should audit team meetings be held?
A. A meeting held in the morning and another at the end of the day
ANSWERS SURE A+
✔✔1. Which auditing principle has AuditOrg applied in this case, "The findings helped
the auditors support their conclusions and report all audit activities truthfully and
accurately?"
A. Independence
B. Fair presentation
C. Confidentiality - ✔✔B. Fair presentation
✔✔1. How would you evaluate the level of responsibility demonstrated by AuditOrg's
auditors?
A. Ordinary negligence, since the auditors have demonstrated lack of diligence during
the audit
B. Gross negligence, since the auditors have demonstrated a total lack of diligence
during the audit
C. No negligence, since the auditors have demonstrated due diligence during the audit -
✔✔C. No negligence, since the auditors have demonstrated due diligence during the
audit
✔✔1. What is the main objective of stage 2 audit?
A. To review the internal audit activities
B. To evaluate the implementation of the ISMS
C. To verify the information security objectives of the ISMS - ✔✔B. To evaluate the
implementation of the ISMS
✔✔1. Which of the following is a step in audit planning?
A. Conducting risk assessment
B. Determining the audit criteria
C. Preparing the audit test plans - ✔✔A. Conducting risk assessment
✔✔1. How does the audit team select processes and systems to be tested?
, A. Based on the technical experts' advice
B. Based on audit procedures
C. Based on materiality - ✔✔C. Based on materiality
✔✔1. During the audit, documented information involving proprietary information was
protected at all times. Which principle of maintaining audit work documents has been
followed?
A. Confidentiality
B. Authorship
C. Conciseness - ✔✔A. Confidentiality
✔✔1. A well-designed documentation standard improves the overall quality of the audit.
A. True
B. False - ✔✔A. True
✔✔1. What is the main purpose of the opening meeting in an audit?
A. To obtain detailed information about management system-related processes
B. To verify audit evidence and obtain a reasonable level of assurance
C. To ensure that planned audit activities can be performed - ✔✔C. To ensure that
planned audit activities can be performed
✔✔1. The opening meeting agenda can include information on:
A. The availability of resources
B. The examination of documented information
C. The creation of audit test plans - ✔✔A. The availability of resources
✔✔1. The auditor has accessed logs to the server room. What source of information
was collected?
A. Documents
B. Observations
C. Records - ✔✔C. Records
✔✔1. How is audit evidence evaluated?
A. By comparing it against the audit criteria
B. By conducting quality review
C. By utilizing audit tests - ✔✔A. By comparing it against the audit criteria
✔✔1. The quality review of audit evidence will assure that the audit findings are reliable
and valid.
A. True
B. False - ✔✔B. False
✔✔1. How often should audit team meetings be held?
A. A meeting held in the morning and another at the end of the day