PECB Lead Auditor - ISO/IEC 27001 Lead Auditor Exam

Question #11 (Topic: Exam A)
Which of the following statements regarding threats and vulnerabilities in information security is NOT correct?
A. Vulnerabilities can be intrinsic or extrinsic, related to the characteristics of the asset or to external factors B. Threats must exploit a vulnerability to have a negative impact on the confidentiality, integrity, and/or availability of information C. All vulnerabilities require immediate implementation of controls regardless of corresponding threats
Answer: C
Question #12 (Topic: Exam A)
Which situation presented below represents a threat?
A. An employee accesses unauthorized files using their legitimate credentials B. An organization fails to implement multi-factor authentication (MFA) for its cloud services C. Cyber attackers infiltrated the network by exploiting a zero-day vulnerability in the organization's firewall software
Answer: C
Question #13 (Topic: Exam A)
A cybersecurity company implemented an access control software that allows only authorized personnel to access sensitive files. Which type of control has the company implemented in this case?
A. Preventive control B. Detective control C. Corrective control
Answer: A
Question #14 (Topic: Exam A)
Scenario: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart-related conditions and complex surgical interventions. Based in Europe, it serves both patients and healthcare professionals. Clinic collects patient data to tailor treatments, monitor outcomes, and improve device functionality. To enhance data security and build trust, Clinic is implementing an information security management system (ISMS) based on ISO/IEC 27001. This initiative demonstrates Clinic's commitment to securely managing sensitive patient information and its proprietary technologies.
Clinic established the scope of its ISMS by solely considering internal issues, interfaces and dependencies between activities conducted internally and those outsourced to other organizations, and the expectations of interested parties. This scope was carefully documented and made accessible. In defining its ISMS, Clinic chose to focus specifically on key processes within critical departments such as Research and Development, Patient Data Management, and Customer Support.
Despite initial challenges. Clinic remained committed to its ISMS implementation, tailoring security controls to its unique needs. The project team excluded certain Annex A controls from ISO/IEC 27001, incorporating additional sector-specific controls to enhance security. The project team meticulously evaluated the applicability of these controls against internal and external factors, culminating in developing a comprehensive Statement of Applicability (SoA) detailing the rationale behind control selection and implementation.
As preparations for certification progressed, Brian, appointed as the team leader for the project team, adopted a self-directed risk assessment methodology to identify and evaluate the company, strategic issues, and security practices. This proactive approach ensured that Clinic's risk assessment aligned with its objectives and missions.
Based on the scenario above, answer the following question:
Does the Clinic's SoA document meet the ISO/IEC 27001 requirements for the SoA?
A. Yes, because it comprises an exhaustive list of controls considered applicable from Annex A of ISO/IEC 27001 and the other sources B. No, because security controls selected from sources other than Annex A of ISO/IEC 27001 are included C. No. because it does not contain the justification for the exclusion of controls from Annex A of ISO/IEC 27001
Answer: C
Question #15 (Topic: Exam A)
Scenario: Clinic, founded in the 1990s, is a medical device company that specializes in treatments for heart-related conditions and complex surgical interventions. Based in Europe, it serves both patients and healthcare professionals. Clinic collects patient data to tailor treatments, monitor outcomes, and improve device functionality. To enhance data security and build trust, Clinic is implementing an information security management system (ISMS) based on ISO/IEC 27001. This initiative demonstrates Clinic's commitment to securely managing sensitive patient information and its proprietary technologies.
Clinic established the scope of its ISMS by solely considering internal issues, interfaces and dependencies between activities conducted internally and those outsourced to other organizations, and the expectations of interested parties. This scope was carefully documented and made accessible. In defining its ISMS, Clinic chose to focus specifically on key processes within critical departments such as Research and Development, Patient Data Management, and Customer Support.
Despite initial challenges. Clinic remained committed to its ISMS implementation, tailoring security controls to its unique needs. The project team excluded certain Annex A controls from ISO/IEC 27001, incorporating additional sector-specific controls to enhance security. The project team meticulously evaluated the applicability of these controls against internal and external factors, culminating in developing a comprehensive Statement of Applicability (SoA) detailing the rationale behind control selection and implementation.
As preparations for certification progressed, Brian, appointed as the team leader for the project team, adopted a self-directed risk assessment methodology to identify and evaluate the company, strategic issues, and security practices. This proactive approach ensured that Clinic's risk assessment aligned with its objectives and missions.
According to scenario, was the scope of Clinic's ISMS determined correctly?
A. No, Clinic should have also considered external issues B. Yes, the scope of Clinic's ISMS was determined correctly C. No, Clinic should have also included exclusions along with justifications for them as part of its ISMS scope
Answer: A
Download Exam
Page: 3 / 50
Total 249 questions