ISO/IEC 27007:2020 Guidelines for Information Security Management Systems Auditing Exam Free Practice Test — 30 Questions

30 questions · Full explanations · No account required

Free
Question 1 of 30

During an audit of an organization\'s information security management system, an auditor discovers that the documented procedure for access control provisioning has not been consistently followed, resulting in several instances of elevated privileges being granted to personnel who do not require them for their job functions. This constitutes a significant deviation from the established controls and the requirements of ISO/IEC 27001. What is the auditor\'s primary responsibility immediately after identifying and documenting this nonconformity?

Ensure the auditee identifies the root cause of the procedural lapse and initiates corrective actions.
Immediately recommend a new access control policy to the auditee.
Report the nonconformity to the certification body without further discussion with the auditee.
Conduct a detailed analysis of all historical access logs for the past five years.

About the ISO/IEC 27007:2020 Guidelines for Information Security Management Systems Auditing Exam Certification

These free practice questions are designed to help you assess your readiness for the ISO/IEC 27007:2020 Guidelines for Information Security Management Systems Auditing Exam exam by ISO. Each question comes with a detailed explanation to reinforce the correct concept. For a complete exam preparation experience with hundreds of questions, spaced-repetition study tools, and full exam simulations, explore our premium access.