Start your ISO-IEC-27001-Lead-Implementer Exam Questions Preparation with Updated 82 Questions [Q30-Q55]

Share

Start your ISO-IEC-27001-Lead-Implementer Exam Questions Preparation with Updated 82 Questions

A Fully Updated 2023 ISO-IEC-27001-Lead-Implementer Exam Dumps - PDF Questions and Testing Engine


To become a PECB Certified ISO/IEC 27001 Lead Implementer, candidates must demonstrate their understanding of the key concepts, principles, and requirements of ISO/IEC 27001, as well as their ability to implement and manage an ISMS effectively. PECB Certified ISO/IEC 27001 Lead Implementer Exam certification exam covers topics such as risk assessment and management, security controls, documentation management, and continual improvement of the ISMS.


Get to know about the Registration Process for the PECB ISO IEC 27001 Lead Implementer Certification Exam:

Steps to register for the PECB ISO IEC 27001 Lead Implementer Certification Exam given in the ISO IEC 27001 Lead Implementer exam dumps are as follows:

  • Fill in the registration form. You will be asked to provide contact information, email address, the desired username, and password. You will also be asked about your preferences for the delivery method (online, phone, or office).

  • Once you have paid the registration fee, you will receive an email confirmation with your username and the link to the PECB ISO IEC 27001 Lead Implementer Certification Exam form.

  • Go to the Official website of the PECB.

  • After you have finished filling in all the required fields, click on “Register Now” to proceed to the payment page. The price is 500 USD.


PECB ISO-IEC-27001-Lead-Implementer certification exam is an excellent opportunity for information security professionals to demonstrate their skills and knowledge in implementing and managing an ISMS based on the ISO/IEC 27001 standard. Passing ISO-IEC-27001-Lead-Implementer exam is a significant achievement that can enhance the career prospects of an individual by validating their expertise in the field of information security.

 

NEW QUESTION # 30
Scenario 10: NetworkFuse develops, manufactures, and sells network hardware. The company has had an operational information security management system (ISMS) based on ISO/IEC 27001 requirements and a quality management system (QMS) based on ISO 9001 for approximately two years. Recently, it has applied for a j^ombined certification audit in order to obtain certification against ISO/IEC 27001 and ISO 9001.
After selecting the certification body, NetworkFuse prepared the employees for the audit The company decided to not conduct a self-evaluation before the audit since, according to the top management, it was not necessary. In addition, it ensured the availability of documented information, including internal audit reports and management reviews, technologies in place, and the general operations of the ISMS and the QMS.
However, the company requested from the certification body that the documentation could not be carried off-site However, the audit was not performed within the scheduled days because NetworkFuse rejected the audit team leader assigned and requested their replacement The company asserted that the same audit team leader issued a recommendation for certification to its main competitor, which, for the company's top management, was a potential conflict of interest. The request was not accepted by the certification body The certification body rejected NetworkFuse's request to change the audit team leader. Is this acceptable?
Refer to scenario 10.

  • A. No, because an auditee cannot request the rejection of an audit team member
  • B. Yes, because NetworkFuse did not give a valid reason to support their claims
  • C. No, auditee's requests for the replacement of auditors must be accepted

Answer: B

Explanation:
Explanation
According to the ISO/IEC 27001 : 2022 Lead Implementer course, the certification body is responsible for selecting and appointing the audit team members, taking into account the competence, impartiality, and objectivity of the auditors1. The auditee can request the replacement of an audit team member only if there is a valid reason to doubt their competence or impartiality, such as a personal or professional conflict of interest, a lack of relevant experience or qualifications, or a previous involvement in the auditee's activities2. However, NetworkFuse did not give a valid reason to support their claims, as the fact that the audit team leader issued a recommendation for certification to their main competitor does not imply a conflict of interest or a bias.
Therefore, the certification body rejected NetworkFuse's request to change the audit team leader, which is acceptable.
References: 1: PECB, ISO/IEC 27001 Lead Implementer Course, Module 11: Certification Audit of the ISMS, slide 13 2: PECB, ISO/IEC 27001 Lead Implementer Course, Module 11: Certification Audit of the ISMS, slide 14


NEW QUESTION # 31
Who is authorized to change the classification of a document?

  • A. The author of the document
  • B. The manager of the owner of the document
  • C. The administrator of the document
  • D. The owner of the document

Answer: D


NEW QUESTION # 32
Which of the actions presented in scenario 4 is NOT compliant with the requirements of ISO/IEC 27001?

  • A. The external experts selected security controls and drafted the Statement of Applicability
  • B. The Statement of Applicability was drafted before conducting the risk assessment
  • C. TradeB selected only ISO/IEC 27001 controls deemed applicable to the company

Answer: B


NEW QUESTION # 33
Who should be involved, among others, in the draft, review, and validation of information security procedures?

  • A. The employees in charge of ISMS operation
  • B. An external expert
  • C. The information security committee

Answer: C


NEW QUESTION # 34
Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)

  • A. Physical security perimeter
  • B. Cryptographic Controls Use Policy
  • C. Key management
  • D. Work in safe areas

Answer: B,C


NEW QUESTION # 35
Based on scenario 8. does SunDee comply with ISO/IEC 27001 requirements regarding the monitoring and measurement process?

  • A. No, because even though the standard does not imply when such a process should be performed, the company must have a monitoring and measurement process in place
  • B. Yes. because the standard does not Indicate when the monitoring and measurement phase should be performed
  • C. Yes, because the standard requires that the monitoring and measurement phase be conducted every two years

Answer: A


NEW QUESTION # 36
Scenario 4: TradeB. a commercial bank that has just entered the market, accepts deposits from its clients and offers basic financial services and loans for investments. TradeB has decided to implement an information security management system (ISMS) based on ISO/IEC 27001 Having no experience of a management
[^system implementation, TradeB's top management contracted two experts to direct and manage the ISMS implementation project.
First, the project team analyzed the 93 controls of ISO/IEC 27001 Annex A and listed only the security controls deemed applicable to the company and their objectives Based on this analysis, they drafted the Statement of Applicability. Afterward, they conducted a risk assessment, during which they identified assets, such as hardware, software, and networks, as well as threats and vulnerabilities, assessed potential consequences and likelihood, and determined the level of risks based on three nonnumerical categories (low, medium, and high). They evaluated the risks based on the risk evaluation criteria and decided to treat only the high risk category They also decided to focus primarily on the unauthorized use of administrator rights and system interruptions due to several hardware failures by establishing a new version of the access control policy, implementing controls to manage and control user access, and implementing a control for ICT readiness for business continuity Lastly, they drafted a risk assessment report, in which they wrote that if after the implementation of these security controls the level of risk is below the acceptable level, the risks will be accepted Which of the actions presented in scenario 4 is NOT compliant with the requirements of ISO/IEC 27001?

  • A. The external experts selected security controls and drafted the Statement of Applicability
  • B. The Statement of Applicability was drafted before conducting the risk assessment
  • C. TradeB selected only ISO/IEC 27001 controls deemed applicable to the company

Answer: B

Explanation:
Explanation
According to ISO/IEC 27001:2022, clause 6.1.3, the Statement of Applicability (SoA) is a document that identifies the controls that are applicable to the organization's ISMS and explains why they are selected or not.
The SoA is based on the results of the risk assessment and risk treatment, which are the previous steps in the risk management process. Therefore, the SoA should be drafted after conducting the risk assessment, not before. Drafting the SoA before the risk assessment may lead to inappropriate or incomplete selection of controls, as the organization may not have a clear understanding of its information security risks and their impact.
References: ISO/IEC 27001:2022, clause 6.1.3; PECB ISO/IEC 27001 Lead Implementer Course, Module 5, slide 18.


NEW QUESTION # 37
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?

  • A. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
  • B. A code of conduct is a standard part of a labor contract.
  • C. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.

Answer: A


NEW QUESTION # 38
Scenario 2: Beauty is a cosmetics company that has recently switched to an e-commerce model, leaving the traditional retail. The top management has decided to build their own custom platform in-house and outsource the payment process to an external provider operating online payments systems that support online money transfers.
Due to this transformation of the business model, a number of security controls were implemented based on the identified threats and vulnerabilities associated to critical assets. To protect customers' information.
Beauty's employees had to sign a confidentiality agreement. In addition, the company reviewed all user access rights so that only authorized personnel can have access to sensitive files and drafted a new segregation of duties chart.
However, the transition was difficult for the IT team, who had to deal with a security incident not long after transitioning to the e commerce model. After investigating the incident, the team concluded that due to the out-of-date anti-malware software, an attacker gamed access to their files and exposed customers' information, including their names and home addresses.
The IT team decided to stop using the old anti-malware software and install a new one which would automatically remove malicious code in case of similar incidents. The new software was installed in every workstation within the company. After installing the new software, the team updated it with the latest malware definitions and enabled the automatic update feature to keep it up to date at all times. Additionally, they established an authentication process that requires a user identification and password when accessing sensitive information.
In addition, Beauty conducted a number of information security awareness sessions for the IT team and other employees that have access to confidential information in order to raise awareness on the importance of system and network security.
Which statement below suggests that Beauty has implemented a managerial control that helps avoid the occurrence of incidents? Refer to scenario 2.

  • A. Beauty updated the segregation of duties chart
  • B. Beauty's employees signed a confidentiality agreement
  • C. Beauty conducted a number of information security awareness sessions for the IT team and other employees that have access to confidential information

Answer: C


NEW QUESTION # 39
A small organization that is implementing an ISMS based on ISO/lEC 27001 has decided to outsource the internal audit function to a third party. Is this acceptable?

  • A. No, the organizations cannot outsource the internal audit function to a third party because during internal audit, the organization audits its own system
  • B. No, the outsourcing of the internal audit function may compromise the independence and impartiality of the internal audit team
  • C. Yes, outsourcing the internal audit function to a third party is often a better option for small organizations to demonstrate independence and impartiality

Answer: C

Explanation:
Explanation
According to the ISO/IEC 27001:2022 standard, an internal audit is an audit conducted by the organization itself to evaluate the conformity and effectiveness of its information security management system (ISMS). The standard requires that the internal audit should be performed by auditors who are objective and impartial, meaning that they should not have any personal or professional interest or bias that could influence their judgment or compromise their integrity. The standard also allows the organization to outsource the internal audit function to a third party, as long as the criteria of objectivity and impartiality are met.
Outsourcing the internal audit function to a third party can be a better option for small organizations that may not have enough resources, skills, or experience to perform an internal audit by themselves. By hiring an external auditor, the organization can benefit from the following advantages:
The external auditor can provide a fresh and independent perspective on the organization's ISMS, identifying strengths, weaknesses, opportunities, and threats that may not be apparent to the internal staff.
The external auditor can bring in specialized knowledge, expertise, and best practices from other organizations and industries, helping the organization to improve its ISMS and achieve its objectives.
The external auditor can reduce the risk of conflict of interest, bias, or influence that may arise when the internal staff audit their own work or the work of their colleagues.
The external auditor can save the organization time and money by conducting the internal audit more efficiently and effectively, avoiding duplication of work or unnecessary delays.
Therefore, outsourcing the internal audit function to a third party is acceptable and often preferable for small organizations that are implementing an ISMS based on ISO/IEC 27001.
References:
ISO/IEC 27001:2022, Information technology - Security techniques - Information security management systems - Requirements, Clause 9.2, Internal audit ISO/IEC 27007:2023, Information technology - Security techniques - Guidelines for information security management systems auditing PECB, ISO/IEC 27001 Lead Implementer Course, Module 12, Internal audit A Complete Guide to an ISO 27001 Internal Audit - Sprinto


NEW QUESTION # 40
Based on scenario 7, what should Anna be aware of when gathering data?

  • A. The collection and preservation of records
  • B. The use of the buffer zone that blocks potential attacks coming from malicious websites where data can be collected
  • C. The type of data that helps prevent future occurrences of information security incidents

Answer: A


NEW QUESTION # 41
An employee of the organization accidentally deleted customers' data stored in the database. What is the impact of this action?

  • A. Information is not available to only authorized users
  • B. Information is not accessible when required
  • C. Information is modified in transit

Answer: B

Explanation:
Explanation
According to ISO/IEC 27001:2022, availability is one of the three principles of information security, along with confidentiality and integrity1. Availability means that information is accessible and usable by authorized persons whenever it is needed2. If an employee of the organization accidentally deleted customers' data stored in the database, this would affect the availability of the information, as it would not be accessible when required by the authorized persons, such as the customers themselves, the organization's staff, or other stakeholders. This could result in loss of trust, reputation, or business opportunities for the organization, as well as dissatisfaction or inconvenience for the customers.
References:
ISO/IEC 27001:2022 - Information security, cybersecurity and privacy protection - Information security management systems - Requirements What is ISO 27001? A detailed and straightforward guide - Advisera


NEW QUESTION # 42
FinanceX, a well-known financial institution, uses an online banking platform that enables clients to easily and securely access their bank accounts. To log in, clients are required to enter the one-lime authorization code sent to their smartphone. What can be concluded from this scenario?

  • A. FinanceX has implemented an integrity control that avoids the involuntary corruption of data
  • B. FinanceX has implemented a securityControl that ensures the confidentiality of information
  • C. FinanceX has incorrectly implemented a security control that could become a vulnerability

Answer: B

Explanation:
Explanation
Confidentiality is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes. A security control is a measure that is put in place to protect the confidentiality, integrity, and availability of information assets. In this scenario, FinanceX has implemented a security control that ensures the confidentiality of information by requiring clients to enter a one-time authorization code sent to their smartphone when they log in to their online banking platform. This control prevents unauthorized access to the clients' bank accounts and protects their sensitive information from being disclosed to third parties. The one-time authorization code is a form of two-factor authentication, which is a security technique that requires two pieces of evidence to verify the identity of a user. In this case, the two factors are something the user knows (their username and password) and something the user has (their smartphone). Two-factor authentication is a recommended security control for online banking platforms, as it provides a higher level of security than single-factor authentication, which relies only on one piece of evidence, such as a password.
References: ISO/IEC 27001:2022 Lead Implementer Course Content, Module 5: Introduction to Information Security Controls based on ISO/IEC 27001:20221; ISO/IEC 27001:2022 Information Security, Cybersecurity and Privacy Protection, Clause 3.6: Confidentiality2; ISO/IEC 27002:2022 Code of practice for information security controls, Clause 9.4: Access control3


NEW QUESTION # 43
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

  • A. Thefirst step consists of checking if the user is using the correct certificate.
  • B. The first step consists of comparing the password with the registered password.
  • C. The first step consists of granting access to the information to which the user is authorized.
  • D. The first step consists of checking if the user appears on the list of authorized users.

Answer: D


NEW QUESTION # 44
What should TradeB do in order to deal with residual risks? Refer to scenario 4.

  • A. TradeB should accept the residual risks only above the acceptance level
  • B. TradeB should evaluate, calculate, and document the value of risk reduction following risk treatment
  • C. TradeB should immediately implement new controls to treat all residual risks

Answer: B


NEW QUESTION # 45
Based on scenario 5. which committee should Operaze create to ensure the smooth running of the ISMS?

  • A. Information security committee
  • B. Management committee
  • C. Operational committee

Answer: A


NEW QUESTION # 46
Who is accountable to classify information assets?

  • A. the Information Security Team
  • B. the CISO
  • C. theasset owner
  • D. the CEO

Answer: C


NEW QUESTION # 47
Scenario 5: Operaze is a small software development company that develops applications for various companies around the world. Recently, the company conducted a risk assessment to assess the information security risks that could arise from operating in a digital landscape. Using different testing methods, including penetration Resting and code review, the company identified some issues in its ICT systems, including improper user permissions, misconfigured security settings, and insecure network configurations. To resolve these issues and enhance information security, Operaze decided to implement an information security management system (ISMS) based on ISO/IEC 27001.
Considering that Operaze is a small company, the entire IT team was involved in the ISMS implementation project. Initially, the company analyzed the business requirements and the internal and external environment, identified its key processes and activities, and identified and analyzed the interested parties In addition, the top management of Operaze decided to Include most of the company's departments within the ISMS scope. The defined scope included the organizational and physical boundaries. The IT team drafted an information security policy and communicated it to all relevant interested parties In addition, other specific policies were developed to elaborate on security issues and the roles and responsibilities were assigned to all interested parties.
Following that, the HR manager claimed that the paperwork created by ISMS does not justify its value and the implementation of the ISMS should be canceled However, the top management determined that this claim was invalid and organized an awareness session to explain the benefits of the ISMS to all interested parties.
Operaze decided to migrate Its physical servers to their virtual servers on third-party infrastructure. The new cloud computing solution brought additional changes to the company Operaze's top management, on the other hand, aimed to not only implement an effective ISMS but also ensure the smooth running of the ISMS operations. In this situation, Operaze's top management concluded that the services of external experts were required to implement their information security strategies. The IT team, on the other hand, decided to initiate a change in the ISMS scope and implemented the required modifications to the processes of the company.
Based on the scenario above, answer the following question:
What led Operaze to implement the ISMS?

  • A. Identification of vulnerabilities
  • B. Identification of threats
  • C. Identification of assets

Answer: A

Explanation:
Explanation
According to the scenario, Operaze conducted a risk assessment to assess the information security risks that could arise from operating in a digital landscape. Using different testing methods, including penetration testing and code review, the company identified some issues in its ICT systems, such as improper user permissions, misconfigured security settings, and insecure network configurations. These issues are examples of vulnerabilities, which are weaknesses or gaps in the protection of an asset that can be exploited by a threat.
Therefore, the identification of vulnerabilities led Operaze to implement the ISMS.
References:
ISO/IEC 27001:2022 Lead Implementer Training Course Guide1
ISO/IEC 27001:2022 Lead Implementer Info Kit2


NEW QUESTION # 48
Which of the situations below can negatively affect the internal audit process?

  • A. Reporting the internal audit results to the top management
  • B. Conducting internal audit interviews with all employees of the organization
  • C. Restricting the internal auditor's access to offices and documentation

Answer: C

Explanation:
Explanation
According to the ISO/IEC 27001 : 2022 Lead Implementer course, one of the factors that can negatively affect the internal audit process is the lack of cooperation from the auditees, which can manifest as restricting the internal auditor's access to offices and documentation1. This can hinder the auditor's ability to collect sufficient and appropriate audit evidence, verify the conformity of the information security management system (ISMS) with the audit criteria, and identify any nonconformities or opportunities for improvement2. Therefore, the auditees should be informed of the audit objectives, scope, criteria, and schedule in advance, and should provide the auditor with all the necessary information and resources to conduct the audit effectively3.
References: 1: PECB, ISO/IEC 27001 Lead Implementer Course, Module 9: Internal Audit, slide 22 2: PECB, ISO/IEC 27001 Lead Implementer Course, Module 9: Internal Audit, slide 23 3: PECB, ISO/IEC 27001 Lead Implementer Course, Module 9: Internal Audit, slide 24


NEW QUESTION # 49
Scenario 1: HealthGenic is a pediatric clinic that monitors the health and growth of individuals from infancy to early adulthood using a web-based medical software. The software is also used to schedule appointments, create customized medical reports, store patients' data and medical history, and communicate with all the
[^involved parties, including parents, other physicians, and the medical laboratory staff.
Last month, HealthGenic experienced a number of service interruptions due to the increased number of users accessing the software Another issue the company faced while using the software was the complicated user interface, which the untrained personnel found challenging to use.
The top management of HealthGenic immediately informed the company that had developed the software about the issue. The software company fixed the issue; however, in the process of doing so, it modified some files that comprised sensitive information related to HealthGenic's patients. The modifications that were made resulted in incomplete and incorrect medical reports and, more importantly, invaded the patients' privacy.
Based on the scenario above, answer the following question:
Which of the following indicates that the confidentiality of information was compromised?

  • A. Service interruptions due to the increased number of users
  • B. Invasion of patients' privacy
  • C. Modification of patients' medical reports

Answer: B


NEW QUESTION # 50
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?

  • A. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
  • B. The costs for automating are easier to charge to the responsible departments.
  • C. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
  • D. Reports can be developed more easily and with fewer errors.

Answer: C


NEW QUESTION # 51
Scenario 6: Skyver offers worldwide shipping of electronic products, including gaming consoles, flat-screen TVs. computers, and printers. In order to ensure information security, the company has decided to implement an information security management system (ISMS) based on the requirements of ISO/IEC 27001.
Colin, the company's best information security expert, decided to hold a training and awareness session for the personnel of the company regarding the information security challenges and other information security-related controls. The session included topics such as Skyver's information security approaches and techniques for mitigating phishing and malware.
One of the participants in the session is Lisa, who works in the HR Department. Although Colin explains the existing Skyver's information security policies and procedures in an honest and fair manner, she finds some of the issues being discussed too technical and does not fully understand the session. Therefore, in a lot of cases, she requests additional help from the trainer and her colleagues Based on scenario 6. when should Colin deliver the next training and awareness session?

  • A. After he determines the employees' availability and motivation
  • B. After he ensures that the group of employees targeted have satisfied the organization's needs
  • C. After he conducts a competence needs analysis and records the competence related issues

Answer: C

Explanation:
Explanation
According to ISO/IEC 27001:2022, clause 7.2.3, the organization shall conduct a competence needs analysis to determine the necessary competence of persons doing work under its control that affects the performance and effectiveness of the ISMS. The organization shall also evaluate the effectiveness of the actions taken to acquire the necessary competence and retain appropriate documented information as evidence of competence.
Therefore, Colin should deliver the next training and awareness session after he conducts a competence needs analysis and records the competence related issues, such as the level of understanding, the gaps in knowledge, and the feedback from the participants.
References: ISO/IEC 27001:2022, clause 7.2.3; PECB ISO/IEC 27001 Lead Implementer Course, Module 7, slide 8.


NEW QUESTION # 52
Why is compliance important forthe reliability of the information?

  • A. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
  • B. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and thereforeit guarantees the reliability of its information.
  • C. By meeting the legislative requirements and theregulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
  • D. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.

Answer: C


NEW QUESTION # 53
Scenario 4: TradeB. a commercial bank that has just entered the market, accepts deposits from its clients and offers basic financial services and loans for investments. TradeB has decided to implement an information security management system (ISMS) based on ISO/IEC 27001 Having no experience of a management
[^system implementation, TradeB's top management contracted two experts to direct and manage the ISMS implementation project.
First, the project team analyzed the 93 controls of ISO/IEC 27001 Annex A and listed only the security controls deemed applicable to the company and their objectives Based on this analysis, they drafted the Statement of Applicability. Afterward, they conducted a risk assessment, during which they identified assets, such as hardware, software, and networks, as well as threats and vulnerabilities, assessed potential consequences and likelihood, and determined the level of risks based on three nonnumerical categories (low, medium, and high). They evaluated the risks based on the risk evaluation criteria and decided to treat only the high risk category They also decided to focus primarily on the unauthorized use of administrator rights and system interruptions due to several hardware failures by establishing a new version of the access control policy, implementing controls to manage and control user access, and implementing a control for ICT readiness for business continuity Lastly, they drafted a risk assessment report, in which they wrote that if after the implementation of these security controls the level of risk is below the acceptable level, the risks will be accepted Based on scenario 4, the fact that TradeB defined the level of risk based on three nonnumerical categories indicates that;

  • A. The level of risk will be evaluated against qualitative criteria
  • B. The level of risk will be evaluated using quantitative analysis
  • C. The level of risk will be defined using a formula

Answer: A

Explanation:
Explanation
Qualitative risk assessment is a method of evaluating risks based on nonnumerical categories, such as low, medium, and high. It is often used when there is not enough data or resources to perform a quantitative risk assessment, which involves numerical values and calculations. Qualitative risk assessment relies on the subjective judgment and experience of the risk assessors, and it can be influenced by various factors, such as the context, the stakeholders, and the criteria. According to ISO/IEC 27001:2022, Annex A, control A.8.2.1 states: "The organization shall define and apply an information security risk assessment process that: ... d) identifies the risk owners; e) analyses the risks: i) assesses the consequences that would result if the risks identified were to materialize; ii) assesses the realistic likelihood of the occurrence of the risks; f) identifies and evaluates options for the treatment of risks; g) determines the levels of residual risk and whether these are acceptable; and h) identifies the risk owners for the residual risks." Therefore, TradeB's decision to define the level of risk based on three nonnumerical categories indicates that they used a qualitative risk assessment process.
References:
ISO/IEC 27001:2022, Annex A, control A.8.2.1
PECB ISO/IEC 27001 Lead Implementer Course, Module 7, slides 12-13


NEW QUESTION # 54
Which of the following is NOT part of the steps required by ISO/IEC 27001 that an organization must take when a nonconformity is detected?

  • A. React to the nonconformity, take action to control and correct it. and deal with its consequences
  • B. Evaluate the need for action to eliminate the causes of the nonconformity so that it does not recur or occur elsewhere
  • C. Communicate the details of the nonconformity to every employee of the organization and suspend the employee that caused the nonconformity

Answer: C


NEW QUESTION # 55
......

Easy Success PECB ISO-IEC-27001-Lead-Implementer Exam in First Try: https://prepaway.vcetorrent.com/ISO-IEC-27001-Lead-Implementer-valid-vce-torrent.html