New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 1 Question 40 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 40
Topic #: 1
[All ISO-IEC-27001-Lead-Auditor Questions]

Scenario 5: Cobt. an insurance company in London, offers various commercial, industrial, and life insurance solutions. In recent years, the number of Cobt's clients has increased enormously. Having a huge amount of data to process, the company decided that certifying against ISO/IEC 27001 would bring many benefits to securing information and show its commitment to continual improvement. While the company was well-versed in conducting regular risk assessments, implementing an ISMS brought major changes to its daily operations. During the risk assessment process, a risk was identified where significant defects occurred without being detected or prevented by the organizations internal control mechanisms.

The company followed a methodology to implement the ISMS and had an operational ISMS in place after only a few months After successfully implementing the ISMS, Cobt applied for ISO/IEC 27001 certification Sarah, an experienced auditor, was assigned to the audit Upon thoroughly analyzing the audit offer, Sarah accepted her responsibilities as an audit team leader and immediately started to obtain general information about Cobt She established the audit criteria and objective, planned the audit, and assigned the audit team members' responsibilities.

Sarah acknowledged that although Cobt has expanded significantly by offering diverse commercial and insurance solutions, it still relies on some manual processes Therefore, her initial focus was to gather information on how the company manages its information security risks Sarah contacted Cobt's representatives to request access to information related to risk management for the off-site review, as initially agreed upon for part of the audit However, Cobt later refused, claiming that such information is too sensitive to be accessed outside of the company This refusal raised concerns about the audit's feasibility, particularly regarding the availability and cooperation of the auditee and access to evidence Moreover, Cobt raised concerns about the audit schedule, stating that it does not properly reflect the recent changes the company made It pointed out that the actions to be performed during the audit apply only to the initial scope and do not encompass the latest changes made in the audit scope

Sarah also evaluated the materiality of the situation, considering the significance of the information denied for the audit objectives. In this case, the refusal by Cobt raised questions about the completeness of the audit and its ability to provide reasonable assurance. Following these situations, Sarah decided to withdraw from the audit before a certification agreement was signed and communicated her decision to Cobt and the certification body. This decision was made to ensure adherence to audit principles and maintain transparency, highlighting her commitment to consistently upholding these principles.

Based on the scenario above, answer the following question:

Based on the role of Sarah described in Scenario 5, which of the following should NOT be part of her responsibilities?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

0/2000 characters
Johnna
3 months ago
Assigning responsibilities? That's a given for any audit leader!
upvoted 0 times
...
Ngoc
3 months ago
Sounds like they might be hiding something.
upvoted 0 times
...
Veronica
3 months ago
Wait, Cobt refused access to info? That's a huge red flag!
upvoted 0 times
...
Novella
4 months ago
I think planning the audit is also part of her job.
upvoted 0 times
...
Giovanna
4 months ago
Sarah should definitely be defining the audit criteria.
upvoted 0 times
...
Loreta
4 months ago
I recall that planning the audit is crucial, but I wonder if Sarah should have more oversight on the audit team rather than just assigning tasks.
upvoted 0 times
...
Fredric
4 months ago
I practiced a case where the auditor had to ensure compliance with standards, and I think defining audit criteria is definitely part of their role.
upvoted 0 times
...
Alyce
4 months ago
I'm not entirely sure, but I feel like assigning responsibilities might be something that should be done by a higher authority, not just the audit team leader.
upvoted 0 times
...
Krissy
5 months ago
I remember that in similar practice questions, the auditor's role was clearly defined, and I think Sarah's responsibilities were mostly about planning and leading the audit.
upvoted 0 times
...
Deonna
5 months ago
The scenario provides a lot of relevant details about the audit process and Sarah's role. I feel confident I can use that information to determine which responsibility should not be part of her duties as the audit team leader.
upvoted 0 times
...
Tamera
5 months ago
This is a good question that tests our understanding of the auditor's responsibilities. I'll make sure to read the scenario thoroughly and consider each option carefully before selecting my answer.
upvoted 0 times
...
Pearlie
5 months ago
Okay, let me think this through step-by-step. Sarah's responsibilities as the audit team leader include assigning responsibilities to the team, defining the audit criteria and objectives, and planning the audit. I just need to identify which of those is not part of her role.
upvoted 0 times
...
Ellsworth
5 months ago
Hmm, I'm a bit confused by the details in the scenario. There's a lot of information about the insurance company and the ISMS implementation. I'll need to carefully read through it to make sure I understand the context before answering.
upvoted 0 times
...
Nidia
5 months ago
This seems like a straightforward question about the responsibilities of an audit team leader. I'm confident I can identify the one responsibility that should not be part of Sarah's role.
upvoted 0 times
...
Dorothy
5 months ago
Hmm, I'm a bit unsure about this one. I'll need to think through the process of collecting logs using Log Service. Let me re-read the question and options.
upvoted 0 times
...
Lashaun
5 months ago
Okay, I've got this. The key is to go to the Defend > Compliance > Cloud Platforms page and configure the serverless radar. That's going to give you the most comprehensive view of your serverless environment and any potential vulnerabilities.
upvoted 0 times
...
Bobbie
10 months ago
Hold up, did anyone else catch that Cobt is in London? I wonder if they serve tea and crumpets during the audit. *chuckles*
upvoted 0 times
Kenny
9 months ago
Sarah's responsibilities were more focused on planning and defining audit criteria.
upvoted 0 times
...
Jacklyn
9 months ago
Definitely not part of the audit process!
upvoted 0 times
...
Erasmo
9 months ago
I don't think they serve tea and crumpets during audits, haha.
upvoted 0 times
...
...
Honey
10 months ago
I agree with Felton. Planning the audit is definitely within Sarah's responsibilities as the team leader. It's her job to coordinate the overall audit process.
upvoted 0 times
Raylene
8 months ago
I agree with Felton. Planning the audit is definitely within Sarah's responsibilities as the team leader. It's her job to coordinate the overall audit process.
upvoted 0 times
...
Freeman
9 months ago
C) Planning the audit
upvoted 0 times
...
Martha
9 months ago
B) Defining the audit criteria and objectives
upvoted 0 times
...
In
9 months ago
A) Assigning responsibilities to the audit team members
upvoted 0 times
...
...
Chanel
11 months ago
But I believe assigning responsibilities to the audit team members should not be part of Sarah's responsibilities.
upvoted 0 times
...
Broderick
11 months ago
I disagree. Defining the audit criteria and objectives is a critical part of the auditor's job. Without clear goals, the audit process would be directionless.
upvoted 0 times
Jenifer
9 months ago
I agree. Defining the audit criteria and objectives is crucial for a successful audit process.
upvoted 0 times
...
Carlton
9 months ago
C) Planning the audit
upvoted 0 times
...
Annelle
10 months ago
B) Planning the audit
upvoted 0 times
...
Leana
10 months ago
A) Assigning responsibilities to the audit team members
upvoted 0 times
...
Ronald
10 months ago
B) Defining the audit criteria and objectives
upvoted 0 times
...
Ezekiel
10 months ago
A) Assigning responsibilities to the audit team members
upvoted 0 times
...
...
Lashaunda
11 months ago
I disagree, planning the audit is a crucial part of Sarah's responsibilities.
upvoted 0 times
...
Felton
11 months ago
Hmm, I would say that Sarah's responsibilities should not include assigning responsibilities to the audit team members. As the audit team leader, her role should be to oversee the process, not micromanage the individual tasks.
upvoted 0 times
...
Chanel
11 months ago
I think Sarah should not be responsible for planning the audit.
upvoted 0 times
...

Save Cancel