ISO/IEC 27001 Lead Auditor UPDATED ACTUAL Questions
and CORRECT Answers
1. What does the ISO/IEC 27001 standard provide? B. Requirements for an information security management system
A. Requirements for organizations certifying an
information security management system
B. Requirements for an information security management
system
C. Guidance for auditing an information security
management system
1. Organizations can obtain certification against the A. False
ISO/IEC 27002 standard if they implement all of its
information security controls.
1. The implementation of ISO/IEC 27001 is a legal A. False
requirement in most countries.
, 1. What is the aim of laws with regard to intellectual A. Protecting certain intangible assets
property rights?
A. Protecting certain intangible assets
B. Ensuring that certain assets are regularly reviewed
C. Providing asset management reports for legal
purposes
1. Which of the following is one of the objectives of the A. To increase awareness regarding the legal requirements for protecting
privacy protection policy? personal information
A. To increase awareness regarding the legal
requirements for protecting personal information
B. To increase awareness regarding cybercrimes that
target an organization's computer network
C. To increase awareness regarding the validity of digital
signatures in electronic documents
1. When does the surveillance audit take place? C. After obtaining certification
A. After conducting stage 2 audit
B. After conducting the audit follow-up
C. After obtaining certification
1. ISO performs accreditation and certification activities. False
A. True
B. False
1. Which of the statements holds true? A. Certification bodies are accredited by accreditation bodies
A. Certification bodies are accredited by accreditation
bodies
B. Certification bodies are certified by accreditation
bodies
C. Certification bodies are hired by accreditation bodies
1. A third party that performs the assessment of C. A certification body
conformity of management systems is:
A. An international standard
B. An accreditation body
C. A certification body
1. Your Market is a market research company which helps C. An auditee
its customers determine which products and services are
on demand. The company is currently evaluating the
effectiveness of its information security controls through
an ISMS audit. What is Your Market in this case?
A. An accreditation body
B. A certification body
C. An auditee
1. According to ISO 9000, what is an asset? A. Item or entity that has potential or actual value to an organization
A. Item or entity that has potential or actual value to an
organization
B. Meaningful data for an organization
C. Document which states requirements for an
organization
and CORRECT Answers
1. What does the ISO/IEC 27001 standard provide? B. Requirements for an information security management system
A. Requirements for organizations certifying an
information security management system
B. Requirements for an information security management
system
C. Guidance for auditing an information security
management system
1. Organizations can obtain certification against the A. False
ISO/IEC 27002 standard if they implement all of its
information security controls.
1. The implementation of ISO/IEC 27001 is a legal A. False
requirement in most countries.
, 1. What is the aim of laws with regard to intellectual A. Protecting certain intangible assets
property rights?
A. Protecting certain intangible assets
B. Ensuring that certain assets are regularly reviewed
C. Providing asset management reports for legal
purposes
1. Which of the following is one of the objectives of the A. To increase awareness regarding the legal requirements for protecting
privacy protection policy? personal information
A. To increase awareness regarding the legal
requirements for protecting personal information
B. To increase awareness regarding cybercrimes that
target an organization's computer network
C. To increase awareness regarding the validity of digital
signatures in electronic documents
1. When does the surveillance audit take place? C. After obtaining certification
A. After conducting stage 2 audit
B. After conducting the audit follow-up
C. After obtaining certification
1. ISO performs accreditation and certification activities. False
A. True
B. False
1. Which of the statements holds true? A. Certification bodies are accredited by accreditation bodies
A. Certification bodies are accredited by accreditation
bodies
B. Certification bodies are certified by accreditation
bodies
C. Certification bodies are hired by accreditation bodies
1. A third party that performs the assessment of C. A certification body
conformity of management systems is:
A. An international standard
B. An accreditation body
C. A certification body
1. Your Market is a market research company which helps C. An auditee
its customers determine which products and services are
on demand. The company is currently evaluating the
effectiveness of its information security controls through
an ISMS audit. What is Your Market in this case?
A. An accreditation body
B. A certification body
C. An auditee
1. According to ISO 9000, what is an asset? A. Item or entity that has potential or actual value to an organization
A. Item or entity that has potential or actual value to an
organization
B. Meaningful data for an organization
C. Document which states requirements for an
organization