Aegentra Labs
Menu
Login

Free · no account required

ISO/IEC 27001 Lead Auditor practice questions

Five original questions use a payroll data exposure to examine information security properties, control performance, vulnerabilities, asset inventories and access rights. Reveal each answer to see the reasoning and why the other options fail.

Independent subject review and learner calibration are pending. Explanations retain the cited ISO 19011:2018 and ISO/IEC 27000:2018 editions. ISO has published 2026 editions; alignment with the current PECB course materials has not yet been verified.

What this exact sample covers

Payroll exposure, access rights and control evidence

  • Information security properties
  • Control evidence
  • Annex A application

Scenario for Questions 1–5

Payroll data exposure

Tallowood Payroll Services processes fortnightly pay runs for about 400 small businesses from offices in Brisbane and Newcastle. Its ISMS, certified to ISO/IEC 27001:2022 last year, covers payroll processing, client onboarding and the supporting platform hosted by an external cloud provider. The information security manager reports to the chief operating officer and chairs a monthly security forum.

In March, a payroll officer exported a full client salary file to a personal cloud folder so she could work from home during a train strike. The file was never altered and the payroll system stayed available, but the folder link was shared by mistake with an unknown external address. The exposure was detected eight days later, when the data leakage prevention tool alerted on a second, similar upload.

Tallowood revoked the link, notified the affected clients and the regulator, and restored the officer's access only after refresher training. The incident report states that the data leakage prevention arrangements "demonstrated prevention and timely detection of this disclosure" because the tool eventually raised an alert. It also records that the officer was granted export rights two years earlier for a one-off project and that nobody had reviewed them since.

One of Tallowood's largest clients then commissioned an audit of its payroll supplier. The auditor reviewed the incident report, the asset inventory and the access review records. The inventory lists the payroll database, servers and staff laptops, but not salary export files or the personal cloud service used to store the exported salary data.

  1. Question 01Domain 1 · recall

    Based on the scenario, which information security property was compromised by the incident?

    1. AConfidentiality and integrity, because the file was copied outside the controlled payroll system and its chain of custody was broken.
    2. BConfidentiality only, because the salary data was disclosed to an unauthorised party while remaining accurate, complete and available.
    3. CConfidentiality and availability, because Tallowood had to suspend the officer's access, which reduced payroll processing capacity.
    the answer and reasoning

    Correct answerB. Confidentiality only, because the salary data was disclosed to an unauthorised party while remaining accurate, complete and available.

    ISO/IEC 27000 defines confidentiality as the property that information is not made available or disclosed to unauthorised individuals, entities or processes; integrity concerns accuracy and completeness; availability concerns being accessible and usable on demand by an authorised entity. The file was disclosed but never altered, and the payroll system remained available. Reference: ISO/IEC 27000:2018, clause 3 (definitions of confidentiality, integrity and availability).

    Why the other options fail

    • A. Copying information outside a controlled system increases exposure, but integrity is lost only when information becomes inaccurate or incomplete. The scenario states the file was never altered.
    • C. Suspending one user's access was a response action. The payroll information and system remained accessible and usable by authorised users, so availability was not compromised.

    Published exam-scope sources: ISO/IEC 27001 Lead Auditor multiple-choice candidate handbook · ISO/IEC 27000:2018 ISMS vocabulary — cited edition

  2. Question 02Domain 1 · evaluation

    Based on the scenario, the incident report says prevention and timely detection of this disclosure were demonstrated. Which statement best evaluates that claim?

    1. AThe tool acted as a preventive control, because its alert stopped further uploads and the exposure was contained once the shared link was revoked.
    2. BThe alert demonstrates detection of the second upload eight days later, but not prevention or timely detection of the original disclosure.
    3. CThe tool acted as a corrective control, because its alert triggered the actions that restored the confidentiality of the disclosed salary file.
    the answer and reasoning

    Correct answerB. The alert demonstrates detection of the second upload eight days later, but not prevention or timely detection of the original disclosure.

    The observed role of the tool was detection of a second upload, eight days after the first disclosure. Those facts do not demonstrate prevention or timely detection of the original disclosure. Revoking the link was a separate containment action. The assessment concerns the evidence for the report's claim; the tool's design specification is not given. Reference: ISO/IEC 27001:2022, Annex A 8.12; ISO/IEC 27002:2022, 8.12.

    Why the other options fail

    • A. The first upload and sharing occurred before the alert. Revoking the link contained access later; it does not demonstrate that the original disclosure was prevented.
    • C. The alert identified a later upload. Revoking the link could limit further access, but it could not recall information already disclosed to an unknown party.

    Published exam-scope sources: ISO/IEC 27001 Lead Auditor multiple-choice candidate handbook · ISO/IEC 27001:2022 information security management systems · ISO/IEC 27002:2022 information security controls

  3. Question 03Domain 1 · recall

    Based on the scenario, which of the following is a vulnerability rather than a threat or a consequence?

    1. AAn unknown external party obtaining the salary file through the shared folder link.
    2. BExport rights from a one-off project two years ago that were never reviewed or removed.
    3. CThe obligation to notify the affected clients and the regulator about the disclosure.
    the answer and reasoning

    Correct answerB. Export rights from a one-off project two years ago that were never reviewed or removed.

    A vulnerability is a weakness of an asset or control that can be exploited by one or more threats. Unreviewed and unnecessary export rights are such a weakness. An external party obtaining the file is the threat being realised, and notification obligations are a consequence of the incident. Reference: ISO/IEC 27000:2018, clause 3 (definitions of threat and vulnerability); ISO/IEC 27001:2022, 6.1.2.

    Why the other options fail

    • A. An unauthorised party gaining access to the file is the threat acting on the weakness, not the weakness itself.
    • C. Notification arises after the event and is a consequence of the disclosure. It is not a weakness that a threat could exploit.

    Published exam-scope sources: ISO/IEC 27001 Lead Auditor multiple-choice candidate handbook · ISO/IEC 27001:2022 information security management systems · ISO/IEC 27000:2018 ISMS vocabulary — cited edition

  4. Question 04Domain 1 · analysis

    Based on the scenario, what is the most significant weakness in Tallowood's asset inventory?

    1. AIt omits salary export files and the cloud service actually used to store them, so relevant information flows and associated risks may be overlooked.
    2. BIt includes servers and laptops, whereas ISO/IEC 27001 expects the inventory to list information assets, leaving hardware to the IT asset register.
    3. CIt does not record a monetary value for each asset, which ISO/IEC 27001 requires so that consequences can be assessed consistently.
    the answer and reasoning

    Correct answerA. It omits salary export files and the cloud service actually used to store them, so relevant information flows and associated risks may be overlooked.

    An inventory used to support the ISMS should cover relevant information and associated assets, including copies and services involved in actual processing. Omitting the salary exports and the cloud service used for them creates a gap to investigate. It does not prove that risk identification had no other information source. Reference: ISO/IEC 27001:2022, 6.1.2 and Annex A 5.9; ISO/IEC 27002:2022, 5.9.

    Why the other options fail

    • B. Control 5.9 covers information and other associated assets, which include hardware such as servers and laptops. Including them is appropriate.
    • C. ISO/IEC 27001 does not require assets to be valued in money. Consequences can be assessed using criteria the organisation defines in its risk methodology.

    Published exam-scope sources: ISO/IEC 27001 Lead Auditor multiple-choice candidate handbook · ISO/IEC 27001:2022 information security management systems · ISO/IEC 27002:2022 information security controls

  5. Question 05Domain 1 · recall

    Based on the scenario, which Annex A control most directly addresses the root cause of the officer's excessive export rights?

    1. A5.18 Access rights, which covers the provision, regular review, adjustment and removal of access rights.
    2. B8.12 Data leakage prevention, which covers measures applied to systems and networks that process sensitive information.
    3. C6.3 Information security awareness, education and training, which covers staff understanding of handling rules.
    the answer and reasoning

    Correct answerA. 5.18 Access rights, which covers the provision, regular review, adjustment and removal of access rights.

    Access-rights review and adjustment directly address permissions that remain after their business purpose ends. The officer retained export rights for two years after a one-off project, with no review. This is the failure most directly addressed by access-rights management; DLP and training address other parts of the incident. Reference: ISO/IEC 27001:2022, Annex A 5.18; ISO/IEC 27002:2022, 5.18.

    Why the other options fail

    • B. Data leakage prevention could have reduced the impact, but it does not address why the officer still had export rights years after the project ended.
    • C. Training addresses the officer's handling behaviour. It does not fix the underlying failure to review and remove access rights that were no longer needed.

    Published exam-scope sources: ISO/IEC 27001 Lead Auditor multiple-choice candidate handbook · ISO/IEC 27001:2022 information security management systems · ISO/IEC 27002:2022 information security controls

Continue preparing

Move from examples to a saved practice session.

Casual mode shows feedback as you answer. Full access adds the complete weighted bank, exam mode, saved results and domain-level analysis for this exact qualification.

Start free practice Read the Lead Auditor study guideRead the complete exam guideBuy the official PECB course