ISO 27001 Lead Auditor Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

The review process indicates that following a recent significant data breach, the organization has logged the incident but has not conducted a formal assessment of the breach\'s impact on its information security objectives, contractual obligations, or overall business operations. Which of the following actions by the Lead Auditor best addresses this situation in accordance with ISO 27001 Lead Auditor principles?

Escalate the finding to senior management, highlighting the need for a comprehensive impact assessment as required by Clause 9.1, and recommend the initiation of a formal process to evaluate the breach's consequences and inform risk treatment.
Document the lack of an impact assessment as a minor observation, assuming the incident response team will address it as part of their ongoing operational activities.
Advise the organization to immediately implement specific technical security patches without first understanding the full scope of the breach's impact.
Conclude that the incident logging process is sufficient and no further action is required from an audit perspective, as the breach has already been recorded.

About the ISO 27001 Lead Auditor Certification

These free practice questions are designed to help you assess your readiness for the ISO 27001 Lead Auditor exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.