EXAMINATION WITH QUESTIONS AND
VERIFIED ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
1.
During an ISO 28000 audit of a multinational logistics organization, the
audit team discovers that the organization has documented its security
management system boundaries as covering warehouses, transportation
operations, and customs interfaces. However, the organization excludes
a contracted cross-docking facility that handles approximately 35% of its
international shipments. Management argues that the facility is
externally controlled and therefore outside the SMS scope. What should
the lead auditor do FIRST?
A. Accept the exclusion because outsourced facilities cannot be included
in the SMS scope
B. Determine whether the cross-docking facility can affect the
organization's ability to achieve the intended security outcomes and
whether its exclusion is justified
C. Issue an automatic major nonconformity because all outsourced
facilities must be included
D. Require the organization to purchase a separate ISO 28000 certificate
for the facility
Answer: B
Rationale: The auditor must evaluate whether the excluded facility is
relevant to the organization's security management system and
1
,whether the scope determination is justified. External provision does
not automatically remove an activity from consideration. The
organization must understand the boundaries and applicability of its
SMS in relation to activities that can affect supply-chain security
outcomes.
2.
An organization has established a supply-chain security policy stating
that it will "maintain secure and resilient logistics operations." During
interviews, senior management can explain the policy, but warehouse
personnel are unable to describe how the policy affects their daily
activities. Security objectives are documented but have not been
communicated below management level. What is the strongest audit
conclusion?
A. The policy is invalid because every employee must memorize it
word-for-word
B. There is potential evidence of inadequate communication and
implementation of the security policy
C. The organization must immediately suspend its certification
D. The policy should be replaced with a longer document
Answer: B
Rationale: Effective policy implementation requires more than
management approval. Relevant personnel should understand the
policy sufficiently to perform activities contributing to security
objectives. The auditor should obtain additional objective evidence
before determining the severity of any nonconformity.
3.
2
,While auditing a freight forwarding company, the auditor discovers that
the organization identifies cargo theft as a significant security risk. The
risk treatment plan requires GPS tracking, driver authentication, route
monitoring, and exception reporting. Records show that GPS devices
have been nonfunctional on 18% of vehicles for the last four months, yet
the risk register continues to show the risk as "controlled." What should
the auditor primarily evaluate?
A. Whether the organization's actual controls remain capable of
achieving the intended risk treatment
B. Whether GPS technology is mandatory under ISO 28000
C. Whether the organization should purchase more vehicles
D. Whether the risk register contains sufficient colors and graphical
indicators
Answer: A
Rationale: Auditing risk management requires assessing whether
implemented controls actually address identified risks. A documented
treatment plan alone does not demonstrate effective implementation.
The persistent failure of a key control should be evaluated for
operational significance, monitoring, corrective action, and residual
risk.
4.
During an audit, an organization provides a comprehensive security risk
assessment conducted three years ago. Since then, it has entered two
new countries, introduced autonomous warehouse equipment, changed
several logistics providers, and experienced a significant cargo diversion
incident. Management states that the original assessment remains valid
because "the risks are essentially the same." What is the auditor's most
appropriate response?
3
, A. Accept the assessment because risk assessments only need to be
performed once
B. Determine whether significant changes and incidents should have
triggered review or reassessment of security risks
C. Require the organization to perform risk assessments every month
regardless of circumstances
D. Ignore the assessment and audit only physical security controls
Answer: B
Rationale: Security risks should be evaluated in a manner that
remains appropriate to changing circumstances. Significant
organizational, technological, geographic, supplier, and incident
changes can alter threats, vulnerabilities, consequences, and risk
levels.
5.
An organization has established security objectives including reducing
unauthorized access, improving incident response, and increasing
supply-chain resilience. The objectives have assigned responsibilities
and deadlines, but there are no measurable indicators or criteria for
determining whether they have been achieved. What should the auditor
conclude?
A. The objectives are automatically conforming because they have
deadlines
B. The objectives should be evaluated for whether they are measurable
or otherwise capable of determining achievement
C. Objectives are optional under an ISO management system
D. The auditor should create the organization's indicators
Answer: B
4