PRACTICE EXAMINATION WITH
QUESTIONS AND VERIFIED ANSWERS,
PLUS DETAILED RATIONALES/EXPERT
VERIFIED FOR GUARANTEED PASS
2026/LATEST UPDATE/INSTANT
DOWNLOAD PDF
1.
An organization operating an international logistics network is
implementing ISO 28000:2022. During the initial audit, senior
management states that supply-chain security is solely the responsibility
of the security department because operational departments are primarily
concerned with service delivery and cost efficiency. What is the
auditor’s most appropriate conclusion?
A. The approach is acceptable because security specialists should own
all security-related activities.
B. The approach is acceptable if the security department has sufficient
personnel and budget.
C. The organization has failed to establish security as an organizational
responsibility integrated into its management system.
D. The approach is acceptable provided that external security contractors
are used.
Answer: C. The organization has failed to establish security as an
organizational responsibility integrated into its management system.
Rationale: ISO 28000 requires security management to be integrated
into the organization’s processes rather than isolated within a single
department. Senior leadership, operational functions, procurement,
human resources, information technology, transport, warehousing,
1
,and other relevant functions can influence supply-chain security. A
mature management system establishes responsibilities and
accountabilities throughout the organization.
2.
During a Stage 1 audit, the auditor determines that a company has
defined its organizational context but has not identified several external
issues that could affect supply-chain security, including geopolitical
instability, border restrictions, cyber threats, and changing regulatory
requirements. What should the lead auditor do?
A. Ignore the issues because they are outside the organization’s direct
control.
B. Determine whether the omission prevents an adequate understanding
of the context relevant to the security management system.
C. Immediately issue a major nonconformity without further
investigation.
D. Require the organization to eliminate all identified external threats.
Answer: B. Determine whether the omission prevents an adequate
understanding of the context relevant to the security management
system.
Rationale: Context determination should consider internal and
external issues that can affect the intended outcomes of the security
management system. The auditor should evaluate whether the
organization has adequately identified relevant circumstances rather
than demanding that every external threat be eliminated. Stage 1 is
particularly concerned with readiness and adequacy of the
management-system framework for Stage 2.
3.
2
,A multinational freight company has identified terrorism, cargo theft,
unauthorized access, cyber intrusion, insider threats, and document fraud
as security concerns. However, it evaluates them only according to
financial loss and does not consider impacts on personnel, customers,
regulatory compliance, continuity, or supply-chain integrity. What is the
principal audit concern?
A. The organization has used too many security threats.
B. The organization’s security risk assessment may not adequately
reflect the full consequences of security incidents.
C. Financial impact must never be included in security risk assessment.
D. The auditor must independently calculate every organizational risk.
Answer: B. The organization’s security risk assessment may not
adequately reflect the full consequences of security incidents.
Rationale: A robust security risk assessment should consider the
nature of threats, vulnerabilities, consequences, likelihood, and
relevant security objectives and requirements. Financial loss may be
important, but limiting assessment solely to financial consequences
can overlook injury, reputational damage, regulatory consequences,
operational disruption, loss of confidentiality, and compromise of
supply-chain integrity.
4.
An organization has established a security risk assessment methodology,
but the methodology has not been applied to a newly acquired
warehouse that handles high-value goods. The warehouse has been
operating for six months. What should the auditor primarily verify?
A. Whether the warehouse has received a security certificate from the
police.
B. Whether the organization has determined and assessed relevant
3
, security risks associated with the warehouse and incorporated
appropriate controls.
C. Whether the warehouse manager has personally inspected every
shipment.
D. Whether the warehouse has experienced a security incident.
Answer: B. Whether the organization has determined and assessed
relevant security risks associated with the warehouse and
incorporated appropriate controls.
Rationale: Changes to facilities, activities, assets, locations, suppliers,
technology, and supply-chain arrangements can introduce new
security risks. The absence of a prior incident does not demonstrate
that risks are controlled. The auditor should examine the
organization’s systematic process for identifying and assessing risks
associated with the newly acquired operation.
5.
A company identifies cargo theft as a significant security risk and
installs additional surveillance cameras. However, there is no evidence
that the organization assessed whether the cameras actually reduce the
identified risk. What would be the strongest audit approach?
A. Accept the control because surveillance cameras are generally
considered good security practice.
B. Determine whether the control was selected based on risk and
whether its effectiveness is evaluated.
C. Reject the control because cameras cannot prevent cargo theft.
D. Require armed guards instead.
Answer: B. Determine whether the control was selected based on
risk and whether its effectiveness is evaluated.
4