GAQM ISO 27001 : 2013 ISMS - Certified Lead Auditor Sample Questions:
1. Why do we need to test a disaster recovery plan regularly, and keep it up to date?
A) Otherwise remotely stored backups may no longer be available to the security team
B) Otherwise the measures taken and the incident procedures planned may not be adequate
C) Otherwise it is no longer up to date with the registration of daily occurring faults
2. Who is responsible for Initial asset allocation to the user/custodian of the assets?
A) Asset Stakeholder
B) Asset Practitioner
C) Asset Owner
D) Asset Manager
3. We can leave laptops during weekdays or weekends in locked bins.
A) True
B) False
4. You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password.
What kind of threat is this?
A) Organizational threat
B) Social Engineering
C) Natural threat
D) Arason
5. How is the purpose of information security policy best described?
A) An information security policy provides insight into threats and the possible consequences.
B) An information security policy provides direction and support to the management regarding information security.
C) An information security policy documents the analysis of risks and the search for countermeasures.
D) An information security policy makes the security plan concrete by providing it with the necessary details.
Solutions:
| Question # 1 Answer: B | Question # 2 Answer: C | Question # 3 Answer: B | Question # 4 Answer: B | Question # 5 Answer: B |

We're so confident of our products that we provide no hassle product exchange.


By Verne


