PECB Certified ISO/IEC 27001 Lead Auditor exam (ISO-IEC-27001-Lead-Auditor Korean Version) - ISO-IEC-27001-Lead-Auditor Korean Exam Practice Test

조직의 정보 보안 관리 시스템(ISMS)과 관련된 문서화된 정보를 보관하는 목적을 가장 잘 설명하는 옵션은 무엇입니까?
Correct Answer: B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
시나리오 2: Knight는 미국 북부 캘리포니아의 전자 회사로 비디오 게임 콘솔을 개발합니다. Knight는 전 세계적으로 300명 이상의 직원을 보유하고 있습니다. 설립 5주년을 맞아 전 세계 시장을 겨냥한 차세대 비디오 게임 콘솔인 G-Console을 출시하기로 결정했습니다. G-Console은 플레이어에게 최고의 게임 경험을 선사할 2021년 최고의 미디어 머신으로 여겨집니다.
콘솔 팩에는 VR 헤드셋 한 쌍, 2개가 포함됩니다.
게임 및 기타 선물.
수년에 걸쳐 이 회사는 고객에 대한 성실함, 정직함, 존중심을 보임으로써 좋은 평판을 쌓았습니다. 이 좋은 평판은 대부분의 열정적인 게이머가 Knight's G-콘솔이 시장에 출시되자마자 그것을 갖고 싶어하는 이유 중 하나입니다.
Knight는 고객 중심적인 회사일 뿐만 아니라
개발 중인 품질로 인해 게임 업계에서도 널리 알려졌습니다. 가격은 합리적인 기준이 허용하는 것보다 약간 높습니다.
그럼에도 불구하고 Knight의 충성스러운 고객 대부분에게는 이는 문제가 되지 않습니다. Knight의 품질이 최고 수준이기 때문입니다.
세계 최고의 비디오 게임 콘솔 개발사 중 하나인 Knight는 종종 악의적인 활동의 주목을 받습니다. 이 회사는 1년 이상 운영 ISMS를 보유하고 있습니다. ISMS 범위에는 재무 및 HR 부서를 제외한 Knight의 모든 부서가 포함됩니다.
최근, Knight의 독점 정보가 담긴 여러 파일이 해커에 의해 유출되었습니다. Knight의 사고 대응팀(IRT)은 즉시 시스템의 모든 부분과 사고의 세부 사항을 분석하기 시작했습니다.
IRT의 첫 번째 의심은 Knight의 직원들이 취약한 비밀번호를 사용했고 결과적으로 해커가 계정에 무단으로 접근하여 쉽게 해독되었다는 것이었습니다. 그러나 IRT는 사건을 신중하게 조사한 후 해커가 파일 전송 프로토콜(FTP) 트래픽을 캡처하여 계정에 접근했다는 것을 확인했습니다.
FTP는 계정 간에 파일을 전송하기 위한 네트워크 프로토콜입니다. 인증을 위해 일반 텍스트 비밀번호를 사용합니다.
이 정보 보안 사고의 영향을 파악하고 IRT의 제안에 따라 Knight는 FTP를 Secure Shell(SSH) 프로토콜로 대체하여 트래픽을 캡처하는 모든 사람이 암호화된 데이터만 볼 수 있도록 결정했습니다.
이러한 변화에 따라 Knight는 통제의 구현이 유사한 사고의 위험을 최소화했는지 확인하기 위해 위험 평가를 실시했습니다. 프로세스의 결과는 ISMS 프로젝트 관리자가 승인했으며, 그는 새로운 통제를 구현한 후의 위험 수준이 회사의 위험 수용 수준에 부합한다고 주장했습니다.
이 시나리오를 바탕으로 다음 질문에 답하세요.
시나리오 2에 따르면 ISMS 범위는 Knight의 재무 및 인사부에 적용되지 않았습니다. 이것이 허용 가능할까요?
Correct Answer: B
귀하는 감사원 교육을 지도하는 숙련된 감사팀 리더입니다. 귀하의 팀은 현재 외부 고객을 대신하여 데이터를 저장하는 조직에 대한 제3자 감시 감사를 실시하고 있습니다. 교육 중인 감사원은 적용성 설명서(SoA)에 나열되어 있고 사이트에 구현된 기술적 통제를 검토하는 업무를 맡았습니다.
다음 중에서 감사자가 훈련을 받으면서 검토해야 할 것으로 생각하는 통제 항목을 네 가지 선택하세요.
Correct Answer: A,C,G,L
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
다음 중 1자 감사에 참여하지 않는 두 가지 옵션은 무엇입니까?
Correct Answer: C,D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
귀하의 조직은 현재 ISO/IEC27001:2022 인증을 추구하고 있습니다. 방금 내부 ISMS 감사원 자격을 취득했고 ICT 관리자가 새로 습득한 지식을 사용하여 정보 보안 사고 관리 프로세스 설계를 돕고 싶어합니다.
그는 계획된 프로세스에서 다음 단계를 식별하고 각 단계를 어떤 순서로 나열해야 할지 확인해 달라고 요청합니다.
Correct Answer:

Explanation:
Step 1 = Incident logging Step 2 = Incident categorisation Step 3 = Incident prioritisation Step 4 = Incident assignment Step 5 = Task creation and management Step 6 = SLA management and escalation Step 7 = Incident resolution Step 8 = Incident closure The order of the stages in the information security incident management process should follow a logical sequence that ensures a quick, effective, and orderly response to the incidents, events, and weaknesses. The order should also be consistent with the best practices and guidance provided by ISO/IEC 27001:2022 and ISO
/IEC 27035:2022. Therefore, the following order is suggested:
* Step 1 = Incident logging: This step involves recording the details of the potential incident, event, or weakness, such as the date, time, source, description, impact, and reporter. This step is important to provide a traceable record of the incident and to facilitate the subsequent analysis and response. This step is related to control A.16.1.1 of ISO/IEC 27001:2022, which requires the organization to establish responsibilities and procedures for the management of information security incidents, events, and weaknesses. This step is also related to clause 6.2 of ISO/IEC 27035:2022, which provides guidance on how to log the incidents, events, and weaknesses.
* Step 2 = Incident categorisation: This step involves determining the type and nature of the incident, event, or weakness, such as whether it is a hardware issue, network issue, or software issue. This step is important to classify the incident and to assign it to the appropriate resolver or team. This step is related to control A.16.1.2 of ISO/IEC 27001:2022, which requires the organization to report information security events and weaknesses as quickly as possible through appropriate management channels. This step is also related to clause 6.3 of ISO/IEC 27035:2022, which provides guidance on how to categorize the incidents, events, and weaknesses.
* Step 3 = Incident prioritisation: This step involves assessing the severity and urgency of the incident, event, or weakness, and classifying it as critical, high, medium, or low. This step is important to prioritize the incident and to allocate the necessary resources and time for the response. This step is related to control A.16.1.3 of ISO/IEC 27001:2022, which requires the organization to assess and prioritize information security events and weaknesses in accordance with the defined criteria. This step is also related to clause 6.4 of ISO/IEC 27035:2022, which provides guidance on how to prioritize the incidents, events, and weaknesses.
* Step 4 = Incident assignment: This step involves passing the incident, event, or weakness to the individual or team who is best suited to resolve it, based on their skills, knowledge, and availability.
This step is important to ensure that the incident is handled by the right person or team and to avoid delays or confusion. This step is related to control A.16.1.4 of ISO/IEC 27001:2022, which requires the organization to respond to information security events and weaknesses in a timely manner, according to the agreed procedures. This step is also related to clause 6.5 of ISO/IEC 27035:2022, which provides guidance on how to assign the incidents, events, and weaknesses.
* Step 5 = Task creation and management: This step involves identifying and coordinating the work needed to resolve the incident, event, or weakness, such as performing root cause analysis, testing solutions, implementing changes, and documenting actions. This step is important to ensure that the incident is resolved effectively and efficiently, and that the actions are tracked and controlled. This step is related to control A.16.1.5 of ISO/IEC 27001:2022, which requires the organization to apply lessons learned from information security events and weaknesses to take corrective and preventive actions. This step is also related to clause 6.6 of ISO/IEC 27035:2022, which provides guidance on how to create and manage the tasks for the incidents, events, and weaknesses.
* Step 6 = SLA management and escalation: This step involves ensuring that any service level agreements (SLAs) are adhered to while the resolution is being implemented, and that the incident is escalated to a higher level of authority or support if a breach looks likely or occurs. This step is important to ensure that the incident is resolved within the agreed time frame and quality, and that any deviations or issues are communicated and addressed. This step is related to control A.16.1.6 of ISO
/IEC 27001:2022, which requires the organization to communicate information security events and weaknesses to the relevant internal and external parties, as appropriate. This step is also related to clause 6.7 of ISO/IEC 27035:2022, which provides guidance on how to manage the SLAs and escalations for the incidents, events, and weaknesses.
* Step 7 = Incident resolution: This step involves applying a temporary workaround or a permanent solution to resolve the incident, event, or weakness, and restoring the normal operation of the information and information processing facilities. This step is important to ensure that the incident is resolved completely and satisfactorily, and that the information security is restored to the desired level.
This step is related to control A.16.1.7 of ISO/IEC 27001:2022, which requires the organization to identify the cause of information security events and weaknesses, and to take actions to prevent their recurrence or occurrence. This step is also related to clause 6.8 of ISO/IEC 27035:2022, which provides guidance on how to resolve the incidents, events, and weaknesses.
* Step 8 = Incident closure: This step involves closing the incident, event, or weakness, after verifying that it has been resolved satisfactorily, and that all the actions have been completed and documented.
This step is important to ensure that the incident is formally closed and that no further actions are required. This step is related to control A.16.1.8 of ISO/IEC 27001:2022, which requires the organization to collect evidence and document the information security events and weaknesses, and the actions taken. This step is also related to clause 6.9 of ISO/IEC 27035:2022, which provides guidance on how to close the incidents, events, and weaknesses.
References:
ISO/IEC 27001:2022, Information technology - Security techniques - Information security management systems - Requirements1 PECB Candidate Handbook ISO/IEC 27001 Lead Auditor2 ISO 27001:2022 Lead Auditor - PECB3 ISO 27001:2022 certified ISMS lead auditor - Jisc4 ISO/IEC 27001:2022 Lead Auditor Transition Training Course5 ISO 27001 - Information Security Lead Auditor Course - PwC Training Academy6 ISO/IEC 27035:2022, Information technology - Security techniques - Information security incident management
시나리오 4: SendPay는 에이전트와 금융 기관 네트워크를 통해 서비스를 제공하는 금융 회사입니다. 주요 서비스 중 하나는 전 세계로 송금하는 것입니다. 신생 회사인 SendPay는 고객에게 최고 품질의 서비스를 제공하고자 합니다. 이 회사는 국제 거래를 제공하기 때문에 고객의 신원, 거래 이유 및 거래를 완료하는 데 필요할 수 있는 기타 세부 정보와 같은 개인 정보를 제공하도록 요구합니다. 따라서 SendPay는 발생할 수 있는 정보 보안 위협을 탐지, 조사 및 대응하는 것을 포함하여 고객의 정보를 보호하기 위한 보안 조치를 구현했습니다. 안전한 서비스를 제공하려는 그들의 노력은 회사가 많은 시간과 리소스를 투자한 ISMS 구현 중에도 반영되었습니다.
작년에 SendPay는 스마트폰이나 노트북과 같은 전자 기기를 통해 추가 수수료 없이 돈을 거래할 수 있는 디지털 플랫폼을 공개했습니다. 이 플랫폼을 통해 SendPay의 고객은 언제 어디서나 돈을 보내고 받을 수 있습니다. 이 디지털 플랫폼은 SendPay가 회사 운영을 간소화하고 사업을 더욱 확장하는 데 도움이 되었습니다. 당시 SendPay는 소프트웨어 운영을 아웃소싱하고 있었기 때문에 이 프로젝트는 아웃소싱된 회사의 소프트웨어 개발 팀에서 완료했습니다.
같은 팀은 SendPay의 기술 인프라 유지관리도 담당했습니다.
최근 이 회사는 ISMS를 거의 1년 동안 도입한 후 ISO/IEC 27001 인증을 신청했습니다. 그들은 기준에 맞는 인증 기관과 계약을 맺었습니다. 얼마 지나지 않아 인증 기관은 SendPay의 ISMS를 감사하기 위해 4명의 감사원 팀을 임명했습니다.
감사 과정에서 다음과 같은 상황이 관찰되었습니다.
1. 아웃소싱 소프트웨어 회사가 사전 통지 없이 SendPay와의 계약을 종료했습니다. 그 결과 SendPay는 즉시 서비스를 사내로 다시 가져올 수 없었고 운영이 5일 동안 중단되었습니다. 감사원은 SendPay의 담당자에게 계약 종료 시 따를 계획이 있다는 증거를 제공해 달라고 요청했습니다. 담당자는 서류 증거를 제공하지 않았지만 면접 중에 감사원에게 SendPay의 최고 경영진이 비슷한 상황이 다시 발생하면 즉시 서비스를 제공할 수 있는 다른 두 소프트웨어 개발 회사를 파악했다고 말했습니다.
2. 소프트웨어 개발 회사에 아웃소싱된 활동의 모니터링과 관련하여 사용 가능한 증거가 없습니다. 다시 한번, SendPay의 대표는 감사원에게 소프트웨어 개발 회사와 정기적으로 소통하고 발생할 수 있는 모든 가능한 변경 사항에 대해 적절하게 정보를 받고 있다고 말했습니다.
3. 방화벽 테스트 중에 불일치 사항이 발견되지 않았습니다. 감사원은 이러한 서비스가 제공하는 보안 수준을 확인하기 위해 방화벽 구성을 테스트했습니다. 그들은 패킷 분석기를 사용하여 방화벽 정책을 테스트하여 실시간으로 전송되거나 수신된 패킷을 확인할 수 있었습니다.
이 시나리오를 바탕으로 다음 질문에 답하세요.
SendPay의 대표는 회사가 활동을 아웃소싱한 회사와의 계약이 종료될 경우 따를 계획이 없다고 말했습니다. 대신 최고 경영진은 동일한 서비스를 제공할 수 있는 다른 두 개의 소프트웨어 개발 회사를 파악했습니다. 이 상황을 어떻게 설명하시겠습니까?
Correct Answer: A
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
ISMS 감사팀 리더로서, 귀하는 온라인 리테일러를 대신하여 국제 물류 회사에 대한 제2자 감사를 실시하고 있습니다. 감사 중에 귀하의 팀원 중 한 명이 ISO/IEC 27001:2022 부록 A의 제어 5.18(접근 권한)과 관련된 불일치 사항을 보고했습니다. 그녀는 지난 3개월 동안 떠난 20명의 서버 접근 프로토콜을 제거하는 데 최대 1주일이 걸렸지만 정책에 따라 떠난 후 24시간 이내에 접근 권한을 제거해야 한다는 증거를 발견했습니다.
가장 좋은 단어(들)로 문장을 완성하세요, dick 완성하고 싶은 빈칸에 빨간색으로 강조 표시한 다음 아래 옵션에서 해당 텍스트를 클릭하세요. 또는 해당 빈칸에 옵션을 끌어다 놓을 수 있습니다.
Correct Answer:

Explanation:
The purpose of including access rights in an information management system to ISO/IEC 27001:2022 is to provide, review, modify and remove these permissions in accordance with the organisation' s policy and rules for access control.
Access rights are the permissions granted to users or groups of users to access, use, modify, or delete information assets. Access rights should be aligned with the organisation's access control policy, which defines the objectives, principles, roles, and responsibilities for managing access to information systems.
Access rights should also follow the organisation's rules for access control, which specify the criteria, procedures, and controls for granting, reviewing, modifying, and revoking access rights. The purpose of including access rights in an information management system is to ensure that only authorised users can access information assets according to their business needs and roles, and to prevent unauthorised or inappropriate access that could compromise the confidentiality, integrity, or availability of information assets. References:
* ISO/IEC 27001:2022 Annex A Control 5.181
* ISO/IEC 27002:2022 Control 5.182
* CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) Training Course3
귀하는 감사원의 교육을 지도하는 경험이 풍부한 감사팀 리더입니다.
귀하의 팀은 현재 외부 고객을 대신하여 데이터를 저장하는 조직에 대한 제3자 감시 감사를 실시하고 있습니다. 교육 중인 감사자는 적용성 설명서(SoA)에 나열되어 있고 사이트에 구현된 PEOPLE 통제를 검토하는 업무를 맡았습니다.
다음 중에서 감사자가 훈련을 받으면서 검토해야 할 것으로 생각하는 통제 항목을 네 가지 선택하세요.
Correct Answer: A,C,F,H
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
감사팀 리더는 올해 초 제3자 감시 감사를 완료한 후 후속 감사를 계획하고 있습니다. 그들은 시정 조치를 고려하기 전에 시정이 필요한 불일치 사항을 확인하기로 결정했습니다.
아래 설명을 기준으로 볼 때, 감시 과정에서 발견된 불일치 사항에 대한 시정 사항은 다음 중 어느 것입니까?
Correct Answer: C,D,G,H
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
다음 중 참인 문장은 두 개입니다.
* ISMS(정보 보안 관리 시스템) 도입의 주된 이점은 정보 보안 위험 감소에서 비롯됩니다.
Correct Answer: A,B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
시나리오 9: 테크매닉(Techmanic)은 1995년에 설립되어 현재 브뤼셀에서 운영 중인 벨기에 기업입니다. IT 컨설팅, 소프트웨어 설계, 하드웨어/소프트웨어 서비스(배포 및 유지보수 포함)를 제공합니다. 공공 서비스, 금융, 통신, 에너지, 의료, 교육 등 다양한 분야에 서비스를 제공하며, 고객 중심 기업으로서 강력한 고객 관계 구축과 최고 수준의 보안 관행을 최우선으로 생각합니다.
Techmanic은 ISO/IEC 27001 인증을 획득한 지 1년이 되었으며, 이 인증을 매우 자랑스럽게 생각합니다. 인증 심사 과정에서 심사관은 Techmanic의 ISMS 구현에 있어 몇 가지 불일치 사항을 발견했습니다. 하지만 이러한 사항들이 ISMS의 목표 달성 능력에 영향을 미치지 않았기 때문에, 심사관은 근본 원인 분석 및 시정 조치를 원격으로 진행한 후 Techmanic에 인증을 부여했습니다. 같은 해, Techmanic은 서비스 목록에 호스팅을 추가하고 해당 분야까지 인증 범위를 확장해 줄 것을 요청했습니다. 담당 심사관은 이 요청을 승인하고 Techmanic에 사후 심사 중에 확장 심사를 진행할 것이라고 통보했습니다. Techmanic은 사후 심사를 통해 자사의 ISMS가 ISO/IEC 27001을 준수하고 있으며, 지속적인 효과성을 유지하고 있는지 확인했습니다. 이번 사후 심사는 최근 추가된 호스팅 서비스를 포함한 Techmanic의 보안 관행이 인증의 엄격한 요구 사항을 완벽하게 충족하는지 확인하는 데 중점을 두었습니다. 심사관은 특히 IT 컨설팅 부문에서 추가 재인증 심사의 필요성을 없애기 위해 이전 사후 심사 보고서의 결과를 전략적으로 활용하여 재인증 절차를 진행했습니다. 지속적인 개선과 과거 평가로부터 배우는 것의 가치를 인식합니다.
테크매닉은 이전 사후 심사 보고서를 검토하는 관행을 도입했습니다. 이러한 선제적 접근 방식은 잠재적인 부적합 사항을 파악하고 해결하는 데 도움이 되었을 뿐만 아니라 IT 컨설팅 분야의 재인증 절차를 간소화하는 데에도 기여했습니다.
사후 심사 과정에서 몇 가지 부적합 사항이 발견되었습니다. 하지만 ISMS는 ISO/IEC 기준을 계속해서 충족했습니다.
테크매닉은 ISO/IEC 27001 요구사항을 충족했지만, 내부 감사자가 보고한 호스팅 서비스 관련 부적합 사항을 해결하지 못했습니다. 또한, 내부 감사 보고서에는 여러 가지 불일치가 있어 호스팅 서비스 감사 과정에서 내부 감사자의 독립성에 의문이 제기되었습니다. 이러한 이유로 확장 인증이 부여되지 않았습니다. 결과적으로 테크매닉은 다른 인증 기관으로의 이전을 요청했습니다. 이와 동시에 테크매닉은 고객들에게 ISO/IEC 27001 인증이 호스팅 서비스뿐만 아니라 IT 서비스까지 포함한다는 내용의 성명을 발표했습니다.
위 시나리오를 바탕으로 다음 질문에 답하시오.
질문:
내부 감사 보고서에서 발견된 불일치를 고려할 때, 내부 감사인의 독립성에 의문을 제기하는 것이 중요한가요?
Correct Answer: C
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
채용 전 인사부의 요구 사항이 아닌 것은 무엇입니까?
Correct Answer: D
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
ISMS 감사팀 팀장으로서 온라인 소매업체를 대신하여 국제 물류 조직에 대한 제2자 감사를 수행하고 있습니다. 감사 도중 팀원 중 한 명이 ISO/IEC 27001:2022 부록 A의 통제 항목 5.18(접근 권한)과 관련된 부적합 사항을 보고했습니다. 해당 통제 항목은 적용성 설명서에 정당성이 명시되어 있었습니다. 팀원은 지난 3개월 동안 퇴사한 20명의 서버 접근 권한을 삭제하는 데 최대 1주일이 소요되는 것을 발견했는데, 이는 회사 정책상 퇴사 후 24시간 이내에 접근 권한을 삭제해야 한다는 규정을 위반하는 것입니다.
감사 대상 기업이 이 상황에 대처하기 위해 취한 가장 적절한 조치 세 가지를 선택하십시오.
Correct Answer: B,F,H
개인 데이터 암호화 및 가명화 테스트가 실패했는데도 조직에서 여전히 모바일 앱을 사용하는 이유를 IT 관리자에게 묻습니다. 또한 서비스 관리자가 해당 테스트를 승인할 권한이 있는지 여부도 묻습니다.
IT 관리자는 소프트웨어 보안 관리 절차에 따라 테스트 결과를 자신이 승인해야 한다고 설명했습니다. 암호화 및 가명화 기능이 실패한 이유는 이러한 기능이 시스템 및 서비스 성능을 심각하게 저하시켰기 때문입니다. 이를 해결하기 위해서는 추가로 150%의 리소스가 필요합니다. 서비스 관리자는 접근 제어가 충분히 효과적이며 허용 가능한 수준이라고 판단하여 승인서에 서명했습니다.
의료진 중 한 명의 휴대전화를 샘플링하여 ABC사의 의료 모바일 앱 버전 1.01이 설치되어 있는 것을 확인했습니다. 또한 버전 1.01에는 테스트 기록이 없는 것을 확인했습니다.
IT 관리자는 잦은 랜섬웨어 공격 때문에 외주를 준 모바일 앱 개발 업체가 테스트를 거친 소프트웨어에 대해 무료로 마이너 업데이트를 제공하고, 업데이트된 소프트웨어를 긴급 배포했으며, 보안 기능에 아무런 영향이 없을 것이라는 구두 보증을 했다고 설명했습니다.
20년간의 정보 보안 경력을 바탕으로 볼 때, 재시험은 필요하지 않습니다.
감사 결과를 준비하고 있습니다. 다음 중 맞는 두 가지 옵션을 선택하세요.
* 부적합 사항(NC)은 없습니다. IT 관리자는 자신의 역량을 완벽하게 입증했습니다. (7.2항 ​​관련)
Correct Answer: A,B
Explanation: Only visible for TrainingDump members. You can sign-up / login (it's free).
0
0
0
0