- 홈페이지
- PECB
- ISO-IEC-27001-Lead-Auditor-KR
- PECB.ISO-IEC-27001-Lead-Auditor-KR.v2026-04-28.q207 모의시험 (Page 22)
ISO-IEC-27001-Lead-Auditor-KR 문제 101
Audit methods with interaction include reviewing checklists with auditee and conducting interviews, as they involve direct communication and feedback from the auditee. Audit methods without interaction include sampling (e.g. products), observing work performed via live video streaming, checking legal compliance with local authorities, and analysing documents provided in advance of the audit, as they do not require any dialogue or exchange with the auditee. References: PECB Candidate Handbook for ISO/IEC 27001 Lead Auditor, page 12.
ISO-IEC-27001-Lead-Auditor-KR 문제 102
다음 중 두 가지 진술은 사실입니까?
The organisation shall implement any action needed, review the effectiveness of any corrective action taken, and make changes to the information security management system, if necessary12 A follow-up audit is a type of internal audit that is conducted after a previous audit to verify whether the nonconformities and corrective actions have been addressed and resolved, and whether the information security management system has been improved12 Therefore, the following statements are true for preparing a follow-up audit plan:
* Verification should focus on whether any action undertaken is complete. This means that the auditor should check whether the organisation has implemented all the planned actions to correct and prevent the nonconformities, and whether the actions have been documented and communicated as required12
* Verification should focus on whether any action undertaken has been undertaken effectively. This means that the auditor should check whether the organisation has achieved the intended results and objectives of the actions, and whether the actions have eliminated or reduced the nonconformities and their causes and consequences12 The following statements are false for preparing a follow-up audit plan:
* Verification should focus on whether any action undertaken has been undertaken efficiently. This is false because efficiency is not a criterion for verifying the actions taken to address the nonconformities and corrective actions. Efficiency refers to the optimal use of resources to achieve the desired outcomes, but it is not a requirement of ISO 27001:2022. The auditor should focus on the effectiveness and completeness of the actions, not on the efficiency12
* Corrections should be verified first, followed by corrective actions and finally opportunities for improvement. This is false because there is no prescribed order for verifying the corrections, corrective actions, and opportunities for improvement. The auditor should verify all the actions taken by the organisation, regardless of their sequence or priority. The auditor may choose to verify the actions based on their relevance, significance, or impact, but this is not a mandatory requirement12
* Opportunities for improvement should be verified first, followed by corrections and finally corrective actions. This is false because there is no prescribed order for verifying the opportunities for improvement, corrections, and corrective actions. The auditor should verify all the actions taken by the organisation, regardless of their sequence or priority. The auditor may choose to verify the actions based on their relevance, significance, or impact, but this is not a mandatory requirement12
* Corrective actions should be reviewed first, followed by corrections and finally opportunities for improvement. This is false because there is no prescribed order for reviewing the corrective actions, corrections, and opportunities for improvement. The auditor should review all the actions taken by the organisation, regardless of their sequence or priority. The auditor may choose to review the actions based on their relevance, significance, or impact, but this is not a mandatory requirement12 References:
1: ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) Course by CQI and IRCA Certified Training 1 2: ISO/IEC 27001 Lead Auditor Training Course by PECB 2
ISO-IEC-27001-Lead-Auditor-KR 문제 103
27001 Brochures | PECB], page 6.
ISO-IEC-27001-Lead-Auditor-KR 문제 104
2022 Lead Auditor Course Handbook, page 34. : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 37. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 14.
ISO-IEC-27001-Lead-Auditor-KR 문제 105
* 문서화된 경영 시스템이 감사 기준에 부합하는지 여부를 밝히고 감사 보고서를 뒷받침할 증거를 수집하기 위함
* Determine the conformity of the management system, as far as documented, with audit criteria, i.e., to check whether the documents are consistent, complete, and compliant with the requirements of ISO
/IEC 27001 and any other applicable standards or regulations.
* Gather information to support the on-site audit activities, i.e., to identify the scope, objectives, processes, controls, risks, and opportunities of the management system, and to plan the audit methods, techniques, and resources accordingly.
The other statements are not accurate, because:
* A document review does not reveal or decide about the conformity or nonconformity of the management system as a whole, but only of the documented information. The conformity or nonconformity of the management system is determined by the on-site audit activities, which include interviews, observations, and tests12
* A document review does not gather evidence or findings to support the audit report or process, but information to support the on-site audit activities. The evidence or findings are collected during the on- site audit activities, which are then documented and reported12
* A document review does not detect any nonconformity of the management system, if documented, but determines the conformity of the documented information. The nonconformity of the management system is detected by the on-site audit activities, which evaluate the performance and effectiveness of the management system12
* A document review does not identify information to support the audit plan, but gathers information to support the on-site audit activities. The audit plan is prepared before the document review, based on the audit scope, objectives, criteria, and program. The document review is part of the audit plan implementation12 References:
1: ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) Course by CQI and IRCA Certified Training 1 2: ISO/IEC 27001 Lead Auditor Training Course by PECB 2
- 다른 버전
- 960PECB.ISO-IEC-27001-Lead-Auditor-KR.v2025-04-10.q163
- 1257PECB.ISO-IEC-27001-Lead-Auditor-KR.v2025-03-19.q128
- 최근 업로드
- 168Cisco.500-420.v2026-09-09.q50
- 152WGU.Introduction-to-IT.v2026-09-09.q52
- 196GARP.2016-FRR.v2026-09-08.q268
- 137Oracle.1Z0-1051-26.v2026-09-08.q15
- 149DAMA.MD-1220.v2026-09-08.q48
- 143Saviynt.SCAIP.v2026-09-07.q20
- 323ISC.CCSP-KR.v2026-09-07.q424
- 147Oracle.1Z0-1032-26.v2026-09-07.q23
- 165Nursing.PMHN-BC.v2026-09-07.q38
- 279Cisco.300-430.v2026-09-07.q266
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. PECB.ISO-IEC-27001-Lead-Auditor-KR.v2026-04-28.q207 모의시험 시험자료를 다운 받으세요.
