NEWEST ISO 27001 LEAD AUDITOR
EXAM | Q&A WITH RATIONALES
1. In ISO/IEC 27001, what is the primary
purpose of the Statement of Applicability (SoA)?
A. To list all assets owned by the organization
B. To document the risk assessment
methodology
C. To identify which Annex A controls are
selected and justify inclusions or exclusions
D. To define the scope of the ISMS
Correct answer: C
Rationale: The SoA records the controls chosen
from Annex A, along with justification for any
exclusions .
2. Which of the following best defines the
"confidentiality" component of the CIA triad?
A. Ensuring data is accurate and unaltered
B. Preventing unauthorized disclosure of
information
,C. Guaranteeing information is available when
needed
D. Monitoring system performance
Correct answer: B
Rationale: Confidentiality protects information
from being disclosed to unauthorized
individuals .
3. Which clause of ISO/IEC 27001 requires top
management to demonstrate leadership and
commitment?
A. Clause 4
B. Clause 5
C. Clause 6
D. Clause 7
Correct answer: B
Rationale: Clause 5 (Leadership) mandates top
management's accountability and active
support for the ISMS .
,4. According to ISO 19011, what is the primary
purpose of an audit opening meeting?
A. To assign nonconformities
B. To introduce and agree on the audit plan,
audit team, and roles and responsibilities of
each auditor
C. To begin the evidence collection process
D. To issue the final audit report
Correct answer: B
Rationale: The purpose is to confirm agreement
to the audit plan, introduce the audit team and
their roles, and ensure that all participants are
aligned .
5. What should an auditor review to verify
conformity to clause 10.1 of ISO/IEC 27001?
A. The organization's marketing strategy
B. Management review results, corrective
actions, and monitoring and measurement
results
C. The employee vacation schedule
, D. The financial budget
Correct answer: B
Rationale: Documented information such as the
results of management reviews, corrective
actions, and monitoring and measurement
results may present audit evidence for clause
10.1 .
6. In risk assessment terminology, which
relationship is correct?
A. Threat × Asset = Vulnerability
B. Asset + Threat = Risk
C. Threat + Vulnerability = Risk
D. Risk = Control – Asset
Correct answer: C
Rationale: Risk arises when a threat exploits a
vulnerability .
7. What does "risk appetite" refer to in
information security risk management?
EXAM | Q&A WITH RATIONALES
1. In ISO/IEC 27001, what is the primary
purpose of the Statement of Applicability (SoA)?
A. To list all assets owned by the organization
B. To document the risk assessment
methodology
C. To identify which Annex A controls are
selected and justify inclusions or exclusions
D. To define the scope of the ISMS
Correct answer: C
Rationale: The SoA records the controls chosen
from Annex A, along with justification for any
exclusions .
2. Which of the following best defines the
"confidentiality" component of the CIA triad?
A. Ensuring data is accurate and unaltered
B. Preventing unauthorized disclosure of
information
,C. Guaranteeing information is available when
needed
D. Monitoring system performance
Correct answer: B
Rationale: Confidentiality protects information
from being disclosed to unauthorized
individuals .
3. Which clause of ISO/IEC 27001 requires top
management to demonstrate leadership and
commitment?
A. Clause 4
B. Clause 5
C. Clause 6
D. Clause 7
Correct answer: B
Rationale: Clause 5 (Leadership) mandates top
management's accountability and active
support for the ISMS .
,4. According to ISO 19011, what is the primary
purpose of an audit opening meeting?
A. To assign nonconformities
B. To introduce and agree on the audit plan,
audit team, and roles and responsibilities of
each auditor
C. To begin the evidence collection process
D. To issue the final audit report
Correct answer: B
Rationale: The purpose is to confirm agreement
to the audit plan, introduce the audit team and
their roles, and ensure that all participants are
aligned .
5. What should an auditor review to verify
conformity to clause 10.1 of ISO/IEC 27001?
A. The organization's marketing strategy
B. Management review results, corrective
actions, and monitoring and measurement
results
C. The employee vacation schedule
, D. The financial budget
Correct answer: B
Rationale: Documented information such as the
results of management reviews, corrective
actions, and monitoring and measurement
results may present audit evidence for clause
10.1 .
6. In risk assessment terminology, which
relationship is correct?
A. Threat × Asset = Vulnerability
B. Asset + Threat = Risk
C. Threat + Vulnerability = Risk
D. Risk = Control – Asset
Correct answer: C
Rationale: Risk arises when a threat exploits a
vulnerability .
7. What does "risk appetite" refer to in
information security risk management?