ISO 27001 UPDATED EXAMS SCRIPT QUESTIONS
AND ANSWERS SURE A+
✔✔1. Linear regression and logistic regression are algorithms utilized by:
A. Machine learning
B. Outsourced operations
C. Cloud computing - ✔✔A. Machine learning
✔✔1. Artificial general intelligence (AGI) is also known as:
A. Strong artificial intelligence
B. Weak artificial intelligence
C. Supervised artificial intelligence - ✔✔A. Strong artificial intelligence
✔✔1. Audit evidence must be:
A. Verifiable
B. Physical
C. Refutable - ✔✔A. Verifiable
✔✔1. A piece of audit evidence can be a combination of several types of evidence.
A. True
B. False - ✔✔A. True
✔✔1. What type of evidence is an external audit report?
A. Physical
B. Confirmative
C. Analytical - ✔✔B. Confirmative
✔✔1. How can an auditor verify conformity to control A.9.2.6 Removal or adjustment of
access rights of ISO/IEC 27001 by using analytical evidence?
A. By analyzing results of the access rights removal procedure on a sample of users
upon the termination of their contracts
B. By analyzing the removal or adjustment of access rights procedure
,C. By analyzing the access rights removal simulation test - ✔✔A. By analyzing results of
the access rights removal procedure on a sample of users upon the termination of their
contracts
✔✔1. What makes audit evidence appropriate?
A. Sufficiency
B. Relevance and reliability
C. Approval - ✔✔B. Relevance and reliability
✔✔1. Which type of audit evidence is considered the least reliable?
A. Verbal
B. Confirmative
C. Physical - ✔✔A. Verbal
✔✔1. What type of evidence is the observation of a firewall configuration?
A. Analytical
B. Mathematical
C. Technical - ✔✔C. Technical
✔✔1. Which type of audit risk is known as the risk that occurs in the management
system despite the internal control mechanisms in an organization?
A. Inherent risk
B. Control risk
C. Detection risk - ✔✔A. Inherent risk
✔✔1. Which of the following factors should be considered when determining the
materiality of a system?
A. The organizational changes
B. The conditions of service-level agreements
C. The audit results - ✔✔B. The conditions of service-level agreements
✔✔1. During an ISO/IEC 27001 audit, auditors must obtain absolute assurance that
every single process is effective and conforms to the standard requirements.
A. True
B. False - ✔✔B. False
✔✔1. Materiality is taken into account to determine the duration of the audit based on
the risks inherent to the organization during:
A. Initial contact
B. Stage 1 audit
C. Stage 2 audit - ✔✔A. Initial contact
✔✔1. What does "control risk" mean?
, A. The risk that a significant defect related to the organizations' internal controls could
not be detected by the auditor
B. The risk that a significant defect could not be prevented by the organization's internal
control mechanisms
C. The risk that remains after a significant defect of an internal control is detected and
corrected - ✔✔B. The risk that a significant defect could not be prevented by the
organization's internal control mechanisms
✔✔1. What action is taken during stage 1 audit when evaluating materiality during the
audit?
A. Identifying the key processes to be audited
B. Determining the audit duration
C. Adjusting the plan based on the materiality of each process or asset - ✔✔A.
Identifying the key processes to be audited
✔✔1. Which parties are involved in an audit offer?
A. The auditor and the auditee
B. The certification body and the auditee
C. The certification body and the auditor - ✔✔C. The certification body and the auditor
✔✔1. How many audit team leaders should be appointed for a joint audit?
A. One audit team leader
B. Two audit team leaders
C. It is up to the certification body - ✔✔A. One audit team leader
✔✔1. What can trigger the initiation of a change in the audit scope?
A. Recent changes in the existing processes
B. Review of major information security incidents
C. Modifications in the information security policy - ✔✔A. Recent changes in the existing
processes
✔✔1. Auditors use the _______________ as a reference to determine conformity.
A. Audit feasibility
B. Audit criteria
C. Audit objectives - ✔✔B. Audit criteria
✔✔1. The certification agreement document formalizes the acceptance of an audit
mandate from the auditor.
A. True
B. False - ✔✔B. False
✔✔1. What is the purpose of an initial contact with the auditee?
A. To determine the audit objectives
B. To discuss the audit schedule
AND ANSWERS SURE A+
✔✔1. Linear regression and logistic regression are algorithms utilized by:
A. Machine learning
B. Outsourced operations
C. Cloud computing - ✔✔A. Machine learning
✔✔1. Artificial general intelligence (AGI) is also known as:
A. Strong artificial intelligence
B. Weak artificial intelligence
C. Supervised artificial intelligence - ✔✔A. Strong artificial intelligence
✔✔1. Audit evidence must be:
A. Verifiable
B. Physical
C. Refutable - ✔✔A. Verifiable
✔✔1. A piece of audit evidence can be a combination of several types of evidence.
A. True
B. False - ✔✔A. True
✔✔1. What type of evidence is an external audit report?
A. Physical
B. Confirmative
C. Analytical - ✔✔B. Confirmative
✔✔1. How can an auditor verify conformity to control A.9.2.6 Removal or adjustment of
access rights of ISO/IEC 27001 by using analytical evidence?
A. By analyzing results of the access rights removal procedure on a sample of users
upon the termination of their contracts
B. By analyzing the removal or adjustment of access rights procedure
,C. By analyzing the access rights removal simulation test - ✔✔A. By analyzing results of
the access rights removal procedure on a sample of users upon the termination of their
contracts
✔✔1. What makes audit evidence appropriate?
A. Sufficiency
B. Relevance and reliability
C. Approval - ✔✔B. Relevance and reliability
✔✔1. Which type of audit evidence is considered the least reliable?
A. Verbal
B. Confirmative
C. Physical - ✔✔A. Verbal
✔✔1. What type of evidence is the observation of a firewall configuration?
A. Analytical
B. Mathematical
C. Technical - ✔✔C. Technical
✔✔1. Which type of audit risk is known as the risk that occurs in the management
system despite the internal control mechanisms in an organization?
A. Inherent risk
B. Control risk
C. Detection risk - ✔✔A. Inherent risk
✔✔1. Which of the following factors should be considered when determining the
materiality of a system?
A. The organizational changes
B. The conditions of service-level agreements
C. The audit results - ✔✔B. The conditions of service-level agreements
✔✔1. During an ISO/IEC 27001 audit, auditors must obtain absolute assurance that
every single process is effective and conforms to the standard requirements.
A. True
B. False - ✔✔B. False
✔✔1. Materiality is taken into account to determine the duration of the audit based on
the risks inherent to the organization during:
A. Initial contact
B. Stage 1 audit
C. Stage 2 audit - ✔✔A. Initial contact
✔✔1. What does "control risk" mean?
, A. The risk that a significant defect related to the organizations' internal controls could
not be detected by the auditor
B. The risk that a significant defect could not be prevented by the organization's internal
control mechanisms
C. The risk that remains after a significant defect of an internal control is detected and
corrected - ✔✔B. The risk that a significant defect could not be prevented by the
organization's internal control mechanisms
✔✔1. What action is taken during stage 1 audit when evaluating materiality during the
audit?
A. Identifying the key processes to be audited
B. Determining the audit duration
C. Adjusting the plan based on the materiality of each process or asset - ✔✔A.
Identifying the key processes to be audited
✔✔1. Which parties are involved in an audit offer?
A. The auditor and the auditee
B. The certification body and the auditee
C. The certification body and the auditor - ✔✔C. The certification body and the auditor
✔✔1. How many audit team leaders should be appointed for a joint audit?
A. One audit team leader
B. Two audit team leaders
C. It is up to the certification body - ✔✔A. One audit team leader
✔✔1. What can trigger the initiation of a change in the audit scope?
A. Recent changes in the existing processes
B. Review of major information security incidents
C. Modifications in the information security policy - ✔✔A. Recent changes in the existing
processes
✔✔1. Auditors use the _______________ as a reference to determine conformity.
A. Audit feasibility
B. Audit criteria
C. Audit objectives - ✔✔B. Audit criteria
✔✔1. The certification agreement document formalizes the acceptance of an audit
mandate from the auditor.
A. True
B. False - ✔✔B. False
✔✔1. What is the purpose of an initial contact with the auditee?
A. To determine the audit objectives
B. To discuss the audit schedule