Free Exam Dumps Collection
https://free.examcollectionpass.com/2024/09/2024-pass-iso-iec-27001-lead-auditor-exam-free-practice-test-with-100-accurate-answers-q56-q75/
Export date: Tue Mar 11 17:58:39 2025 / +0000 GMT

(2024) PASS ISO-IEC-27001-Lead-Auditor Exam Free Practice Test with 100% Accurate Answers [Q56-Q75]




(2024) PASS ISO-IEC-27001-Lead-Auditor Exam Free Practice Test with 100% Accurate Answers

ISO-IEC-27001-Lead-Auditor dumps Free Test Engine Verified By It Certified Experts

NEW QUESTION 56
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security incident management process. The IT Security Manager presents the information security incident management procedure and explains that the process is based on ISO/IEC 27035-1:2016.
You review the document and notice a statement “any information security weakness, event, and incident should be reported to the Point of Contact (PoC) within 1 hour after identification”. When interviewing staff, you found that there were differences in the understanding of the meaning of “weakness, event, and incident”.
You sample incident report records from the event tracking system for the last 6 months with summarized results in the following table.

You would like to further investigate other areas to collect more audit evidence. Select two options that will not be in your audit trail.

 
 
 
 
 
 
 

NEW QUESTION 57
A marketing agency has developed its own risk assessment approach as part of the ISMS implementation. Is this acceptable?

 
 
 

NEW QUESTION 58
Please match the roles to the following descriptions:

To complete the table click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable test from the options below. Alternatively, you may drag and drop each option to the appropriate blank section.

NEW QUESTION 59
There is a scheduled fire drill in your facility. What should you do?

 
 
 
 

NEW QUESTION 60
Match the correct responsibility with each participant of a second-party audit:

NEW QUESTION 61
In regard to generating an audit finding, select the words that best complete the following sentence.
To complete the sentence with the best word(s), click on the blank section you want to complete so that it Is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

NEW QUESTION 62
Which one of the following options is the definition of an interested party?

 
 
 
 

NEW QUESTION 63
Which threat could occur if no physical measures are taken?

 
 
 
 

NEW QUESTION 64
There is a network printer in the hallway of the company where you work. Many employees don’t pick up their printouts immediately and leave them on the printer.
What are the consequences of this to the reliability of the information?

 
 
 
 

NEW QUESTION 65
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee’s data centre with another member of your audit team.
You are currently in a large room that is subdivided into several smaller rooms, each of which has a numeric combination lock and swipe card reader on the door. You notice two external contractors using a swipe card and combination number provided by the centre’s reception desk to gain access to a client’s suite to carry out authorised electrical repairs.
You go to reception and ask to see the door access record for the client’s suite. This indicates only one card was swiped. You ask the receptionist and they reply, “yes it’s a common problem. We ask everyone to swipe their cards but with contractors especially, one tends to swipe and the rest simply ‘tailgate’ their way in” but we know who they are from the reception sign-in.
Based on the scenario above which one of the following actions would you now take?

 
 
 
 
 
 
 
 

NEW QUESTION 66
Which two of the following statements are true?

 
 
 

NEW QUESTION 67
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good.
What is an example of the indirect damage caused by this fire?

 
 
 
 

NEW QUESTION 68
Which one of the following options describes the main purpose of a Stage 1 audit?

 
 
 
 

NEW QUESTION 69
Integrity of data means

 
 
 

NEW QUESTION 70
Scenario 1: Fintive is a distinguished security provider for online payments and protection solutions. Founded in 1999 by Thomas Fin in San Jose, California, Fintive offers services to companies that operate online and want to improve their information security, prevent fraud, and protect user information such as PII. Fintive centers its decision-making and operating process based on previous cases. They gather customer data, classify them depending on the case, and analyze them. The company needed a large number of employees to be able to conduct such complex analyses. After some years, however, the technology that assists in conducting such analyses advanced as well. Now, Fintive is planning on using a modern tool, a chatbot, to achieve pattern analyses toward preventing fraud in real-time. This tool would also be used to assist in improving customer service.
This initial idea was communicated to the software development team, who supported it and were assigned to work on this project. They began integrating the chatbot on their existing system. In addition, the team set an objective regarding the chatbot which was to answer 85% of all chat queries.
After the successful integration of the chatbot, the company immediately released it to their customers for use.
The chatbot, however, appeared to have some issues.
Due to insufficient testing and lack of samples provided to the chatbot during the training phase, in which it was supposed “to learn” the queries pattern, the chatbot failed to address user queries and provide the right answers. Furthermore, the chatbot sent random files to users when it received invalid inputs such as odd patterns of dots and special characters. Therefore, the chatbot was unable to properly answer customer queries and the traditional customer support was overwhelmed with chat queries and thus was unable to help customers with their requests.
Consequently, Fintive established a software development policy. This policy specified that whether the software is developed in-house or outsourced, it will undergo a black box testing prior to its implementation on operational systems.
Based on this scenario, answer the following question:
The chatbot was supposed “to learn” the queries pattern to address user queries and provide the right answers.
What type of technology enables
this?

 
 
 

NEW QUESTION 71
You are an ISMS audit team leader who has been assigned by your certification body to carry out a follow-up audit of a client. You are preparing your audit plan for this audit.
Which two of the following statements are true?

 
 
 
 
 
 

NEW QUESTION 72
An administration office is going to determine the dangers to which it is exposed.
What do we call a possible event that can have a disruptive effect on the reliability of information?

 
 
 
 

NEW QUESTION 73
Which situation presented below represents a threat?

 
 
 

NEW QUESTION 74
You are performing an ISMS audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to verify the information security of the business continuity management process.
During the audit, you learned that the organisation activated one of the business continuity plans (BCPs) to make sure the nursing service continued during the recent pandemic. You ask Service Manager to explain how the organisation manages information security during the business continuity management process.
The Service Manager presents the nursing service continuity plan for a pandemic and summarises the process as follows:
Stop the admission of any NEW residents.
70% of administration staff and 30% of medical staff will work from home.
Regular staff self-testing including submitting a negative test report 1 day BEFORE they come to the office.
Install ABC’s healthcare mobile app, tracking their footprint and presenting a GREEN Health Status QR-Code for checking on the spot.
You ask the Service Manager how to prevent non-relevant family members or interested parties from accessing residents’ personal data when staff work from home. The Service Manager cannot answer and suggests the n” Security Manager should help with that.
You would like to further investigate other areas to collect more audit evidence Select three options that will be in your audit trail.

 
 
 
 
 
 

NEW QUESTION 75
You are performing an ISO 27001 ISMS surveillance audit at a residential nursing home, ABC Healthcare Services. ABC uses a healthcare mobile app designed and maintained by a supplier, WeCare, to monitor residents’ well-being. During the audit, you learn that 90% of the residents’ family members regularly receive medical device advertisements from WeCare, by email and SMS once a week. The service agreement between ABC and WeCare prohibits the supplier from using residents’ personal data. ABC has received many complaints from residents and their family members.
The Service Manager says that the complaints were investigated as an information security incident which found that they were justified.
Corrective actions have been planned and implemented according to the nonconformity and corrective action management procedure.
You write a nonconformity “ABC failed to comply with information security control A.5.34 (Privacy and protection of PII) relating to the personal data of residents’ and their family members. A supplier, WeCare, used residents’ personal information to send advertisements to family members.” Select three options of the corrections and corrective actions listed that you would expect ABC to make in response to the nonconformity.

 
 
 
 
 
 
 
 

Latest PECB ISO-IEC-27001-Lead-Auditor Practice Test Questions: https://www.examcollectionpass.com/PECB/ISO-IEC-27001-Lead-Auditor-practice-exam-dumps.html 1

Links:
  1. https://www.examcollectionpass.com/PECB/ISO-IEC-27 001-Lead-Auditor-practice-exam-dumps.html
Post date: 2024-09-29 10:29:25
Post date GMT: 2024-09-29 10:29:25

Post modified date: 2024-09-29 10:29:25
Post modified date GMT: 2024-09-29 10:29:25

Export date: Tue Mar 11 17:58:39 2025 / +0000 GMT
This page was exported from Free Exam Dumps Collection [ http://free.examcollectionpass.com ]