| Exam Code/Number: | ISO-IEC-27001-Lead-AuditorJoin the discussion |
| Exam Name: | PECB Certified ISO/IEC 27001 Lead Auditor exam |
| Certification: | PECB |
| Question Number: | 418 |
| Publish Date: | Sep 02, 2026 |
|
Rating
100%
|
|
You are performing an ISMS audit at a European-based residential nursing home called ABC that provides healthcare services.
During the audit, you discovered evidence suggesting that ABC may be leaking personal data of residents' family members to a third party for marketing purposes, despite signed agreements prohibiting this.
Complaints were treated as nonconformities, and corrective actions were documented under procedure ISMS L2 10.1.
You decide to write a non-conformity. Select the best sentence for the nonconformity:
You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team.
You are currently in a large room that is subdivided into several smaller rooms, each of which has a numeric combination lock and swipe card reader on the door. You notice two external contractors using a swipe card and combination number provided by the centre's reception desk to gain access to a client's suite to carry out authorised electrical repairs.
You go to reception and ask to see the door access record for the client's suite. This indicates only one card was swiped. You ask the receptionist and they reply, "yes it's a common problem. We ask everyone to swipe their cards but with contractors especially, one tends to swipe and the rest simply 'tailgate' their way in" but we know who they are from the reception sign-in.
Based on the scenario above which one of the following actions would you now take?
The following are purposes of Information Security, except:
You are an experienced ISMS audit team leader providing guidance to an auditor in training.
The auditor in training appears to be confused about the interpretation of competence in ISO 27001:2022 and is seeking clarification from you that his understanding is correct. He sets out a series of mini scenarios and asks you which of these you would attribute to a lack of competence. Select four correct options.
You are conducting an ISMS audit in the despatch department of an international logistics organisation that provides shipping services to large organisations including local hospitals and government offices. Parcels typically contain pharmaceutical products, biological samples, and documents such as passports and driving licences. You note that the company records show a very large number of returned items with causes including mis-addressed labels and, in 15% of company cases, two or more labels for different addresses for the one package. You are interviewing the Shipping Manager (SM).
You: Are items checked before being dispatched?
SH: Any obviously damaged items are removed by the duty staff before being dispatched, but the small profit margin makes it uneconomic to implement a formal checking process.
You: What action is taken when items are returned?
SM: Most of these contracts are relatively low value, therefore it has been decided that it is easier and more convenient to simply reprint the label and re-send individual parcels than it is to implement an investigation.
You raise a nonconformity. Referencing the scenario, which six of the following Appendix A controls would you expect the auditee to have implemented when you conduct the follow-up audit?
PECB.ISO-IEC-27001-Lead-Auditor.v2026-01-12.q371
Jan 12, 2026
PECB.ISO-IEC-27001-Lead-Auditor.v2025-07-02.q187
Jul 02, 2025
PECB.ISO-IEC-27001-Lead-Auditor.v2024-08-31.q185
Aug 31, 2024
PECB.ISO-IEC-27001-Lead-Auditor.v2023-10-14.q33
Oct 14, 2023
PECB.ISO-IEC-27001-Lead-Auditor.v2023-08-19.q35
Aug 19, 2023
PECB.ISO-IEC-27001-Lead-Auditor.v2022-11-19.q36
Nov 19, 2022
PECB.ISO-IEC-27001-Lead-Auditor.v2022-04-09.q33
Apr 09, 2022
Enter your email address to download PECB.ISO-IEC-27001-Lead-Auditor.premium Dumps