TEST WITH QUESTIONS AND VERIFIED
ANSWERS, PLUS DETAILED
RATIONALES/EXPERT VERIFIED FOR
GUARANTEED PASS 2026/LATEST
UPDATE/INSTANT DOWNLOAD PDF
Question 1
An organization has established a supply-chain security management
system (SCSMS) covering procurement, warehousing, transportation,
information systems, and third-party logistics providers. During an audit,
the lead auditor discovers that the organization has documented security
objectives but has not established measurable indicators for determining
whether those objectives are being achieved. Which finding is most
appropriate?
A. The organization is compliant because documented objectives alone
are sufficient.
B. The organization should establish measurable criteria or indicators
that allow it to evaluate achievement of its security objectives.
C. The organization must immediately terminate all third-party logistics
contracts.
D. The organization must replace its entire risk assessment
methodology.
Answer: B
Rationale: The effectiveness of management objectives must be
capable of being evaluated. Security objectives should be consistent
with the organization's policy and relevant requirements, while
appropriate measures or indicators provide evidence of achievement.
Simply documenting objectives without a mechanism for evaluating
1
,performance weakens the ability of the SCSMS to demonstrate
effectiveness.
Question 2
During an opening meeting, a department manager tells the audit team
that several records requested by the auditors contain commercially
sensitive information and therefore cannot be reviewed. What should the
lead auditor do first?
A. Accept the refusal and remove the department from the audit scope.
B. Threaten the organization with immediate certification withdrawal.
C. Explain the audit team's confidentiality obligations and determine an
appropriate controlled method for reviewing the necessary evidence.
D. Photograph the records without permission.
Answer: C
Rationale: Auditors must obtain sufficient objective evidence while
respecting confidentiality and security requirements. Sensitive records
can often be reviewed under controlled conditions, through sampling,
redaction, secure electronic access, or other agreed arrangements.
Refusing access without assessing alternatives can prevent the auditor
from reaching a valid conclusion.
Question 3
An auditor identifies that the organization has classified cargo theft as a
significant supply-chain security risk. The organization implemented
GPS tracking, route restrictions, driver verification, and exception
monitoring. Which audit approach provides the strongest evidence that
these controls are effective?
2
,A. Review only the written security policy.
B. Interview the security manager and accept the response as evidence.
C. Examine implementation records, sample actual shipments, review
monitoring results, and determine whether controls operate as planned.
D. Verify that the organization purchased GPS devices.
Answer: C
Rationale: An effective audit evaluates implementation and
effectiveness rather than merely the existence of policies or equipment.
Objective evidence can include operational records, monitoring data,
interviews, observations, and sampled transactions. Purchasing
technology does not demonstrate that the technology is properly
implemented or effective.
Question 4
A company has outsourced transportation to a logistics provider. The
organization argues that because transportation is outsourced, the
activity is outside the SCSMS and does not require security controls.
What should the auditor conclude?
A. Outsourcing automatically removes the activity from the
organization's responsibilities.
B. The organization remains responsible for managing relevant
outsourced processes and associated supply-chain security risks.
C. Only the logistics provider needs certification.
D. Transportation risks are excluded from ISO 28000.
Answer: B
Rationale: Outsourcing does not eliminate the organization's
responsibility for processes that can affect the intended outcomes of
the SCSMS. The organization needs to determine appropriate controls,
3
, requirements, monitoring, communication, and evaluation of relevant
externally provided processes.
Question 5
During a certification audit, the auditor discovers that the organization
has a documented emergency response procedure, but employees
interviewed during the audit cannot explain their responsibilities during
a major security incident. Which evidence is most significant?
A. The existence of the procedure proves conformity.
B. The procedure should be evaluated together with evidence of
implementation, awareness, competence, and operational effectiveness.
C. The auditor should ignore employee awareness because emergency
procedures are confidential.
D. The organization must create a new security policy.
Answer: B
Rationale: Documented information alone does not demonstrate
effective implementation. Personnel whose work can affect supply-
chain security should understand relevant responsibilities and actions.
Interviews, exercises, incident records, and observations can establish
whether arrangements actually function.
Question 6
A lead auditor notices that the organization's risk assessment identifies
"unauthorized access" as a risk but does not identify which assets,
processes, locations, or supply-chain activities could be affected. What
is the principal audit concern?
A. The risk assessment may not provide sufficient context and detail to
support appropriate treatment decisions.
4