DumpsFiles
 Request Exam  Contact
  • Home
  • PRACTICE EXAMS
    Oracle
    Fortinet
    Juniper
    Microsoft
    Cisco
    Citrix
    CompTIA
    VMware
    SAP
    EMC
    PMI
    HP
    Salesforce
    Other
  • View All Exams
  • New Dumps Files
  • Upload
  • Oracle
    Oracle
  • Fortinet
    Fortinet
  • Juniper
    Juniper
  • Microsoft
    Microsoft
  • Cisco
    Cisco
  • Citrix
    Citrix
  • CompTIA
    CompTIA
  • VMware
    VMware
  • SAP
    SAP
  • EMC
    EMC
  • PMI
    PMI
  • HP
    HP
  • Salesforce
    Salesforce
  1. Home
  2. PECB
  3. PECB Certified ISO/IEC 27001 Lead Implementer Exam
  4. PECB.ISO-IEC-27001-Lead-Implementer.v2025-06-12.q94
  5. Question 1

Join the discussion

Question 1/94

Scenario 9:
OpenTech, headquartered in San Francisco, specializes in information and communication technology (ICT) solutions. Its clientele primarily includes data communication enterprises and network operators. The company's core objective is to enable its clients to transition smoothly into multi-service providers, aligning their operations with the complex demands of the digital landscape.
Recently, Tim, the internal auditor of OpenTech, conducted an internal audit that uncovered nonconformities related to their monitoring procedures and system vulnerabilities. In response to these nonconformities, OpenTech decided to employ a comprehensive problem-solving approach to address the issues systematically.
This method encompasses a team-oriented approach, aiming to identify, correct, and eliminate the root causes of the issues. The approach involves several steps: First, establish a group of experts with deep knowledge of processes and controls. Next, break down the nonconformity into measurable components and implement interim containment measures. Then, identify potential root causes and select and verify permanent corrective actions. Finally, put those actions into practice, validate them, take steps to prevent recurrence, and recognize and acknowledge the team's efforts.
Following the analysis of the root causes of the nonconformities, OpenTech's ISMS project manager, Julia, developed a list of potential actions to address the identified nonconformities. Julia carefully evaluated the list to ensure that each action would effectively eliminate the root cause of the respective nonconformity. While assessing potential corrective actions, Julia identified one issue as significant and assessed a high likelihood of its recurrence. Consequently, she chose to implement temporary corrective actions. Julia then combined all the nonconformities into a single action plan and sought approval from top management. The submitted action plan was written as follows:
"A new version of the access control policy will be established and new restrictions will be created to ensure that network access is effectively managed and monitored by the Information and Communication Technology (ICT) Department." However, Julia's submitted action plan was not approved by top management. The reason cited was that a general action plan meant to address all nonconformities was deemed unacceptable. Consequently, Julia revised the action plan and submitted separate ones for approval. Unfortunately, Julia did not adhere to the organization's specified deadline for submission, resulting in a delay in the corrective action process.
Additionally, the revised action plans lacked a defined schedule for execution.
Based on scenario 9, was it acceptable that the top management rejected the action plan submitted by Julia?

Correct Answer: B

Add Comments

Your email address will not be published. Required fields are marked *

insert code
Type the characters from the picture.
Rating:
Other Question (94q)
Q1. Scenario 9: OpenTech, headquartered in San Francisco, specializes in information and commu...
Q2. Scenario 8: SunDee is an American biopharmaceutical company, headquartered in California, ...
Q3. If an organization wants to monitor operations in real time and notify users about deviati...
Q4. Org Y. a well-known bank, uses an online banking platform that enables clients to easily a...
Q5. Kyte. a company that has an online shopping website, has added a Q&A section to its we...
Q6. Scenario 9: OpenTech, headquartered in San Francisco, specializes in information and commu...
Q7. What should an organization allocate to ensure the maintenance and improvement of the info...
Q8. Scenario 1: HealthGenic is a pediatric clinic that monitors the health and growth of indiv...
Q9. Scenario 8: BioVitalis BioVitalis is a biopharmaceutical firm headquartered in California,...
Q10. An organization has implemented a control that enables the company to manage storage media...
Q11. Which approach should organizations use to implement an ISMS based on ISO/IEC 27001?...
Q12. Del&Co has decided to improve their staff-related controls to prevent incidents. Which...
Q13. Invalid Electric, a manufacturer of electrical components, is preparing for its upcoming I...
Q14. Question: Which audit phase was conducted after the issue with the audit team was resolved...
Q15. Scenario 4: TradeB. a commercial bank that has just entered the market, accepts deposits f...
Q16. Scenario 9: OpenTech, headquartered in San Francisco, specializes in information and commu...
Q17. Scenario 5: Operaze is a small software development company that develops applications for...
Q18. Question: Which statement regarding management reviews is correct?...
Q19. Scenario 8: SunDee is a biopharmaceutical firm headquartered in California, US. Renowned f...
Q20. Scenario 4: TradeB. a commercial bank that has just entered the market, accepts deposits f...
Q21. Scenario 2: Beauty is a cosmetics company that has recently switched to an e-commerce mode...
Q22. Question: According to ISO/IEC 27001 controls, why should the use of privileged utility pr...
Q23. Scenario 4: TradeB is a newly established commercial bank located in Europe, with a divers...
Q24. Scenario 3: Socket Inc is a telecommunications company offering mainly wireless products a...
Q25. Which tool is used to identify, analyze, and manage interested parties?...
Q26. Why should the security testing processes be defined and implemented in the development li...
Q27. Scenario 7: InfoSec is a multinational corporation headquartered in Boston, MA, which prov...
Q28. Scenario 6: GreenWave GreenWave, a manufacturer of sustainable and energy efficient home a...
Q29. The purpose of control 5.9 inventory of Information and other associated assets of ISO/IEC...
Q30. An employee from Reyae Ltd. unintentionally sent an email containing critical business str...
Q31. Scenario 3: Socket Inc is a telecommunications company offering mainly wireless products a...
Q32. Question: An organization has compared its actual performance against predetermined perfor...
Q33. Scenario 8: SunDee is an American biopharmaceutical company, headquartered in California, ...
Q34. Scenario 7: CyTekShield CyTekShield based in Dublin. Ireland, is a cybersecurity consultin...
Q35. Question: Which of the following would be an acceptable justification for excluding the An...
Q36. Which of the following is the information security committee responsible for?...
Q37. FinanceX, a well-known financial institution, uses an online banking platform that enables...
Q38. Levo Corporation has implemented a demilitarized zone (DMZ) and virtual private network (V...
Q39. According to ISO/IEC 270G1. why shall organizations document nonconformities?...
Q40. Scenario 3: Socket Inc. is a dynamic telecommunications company specializing in wireless p...
Q41. Scenario 7: InfoSec, based in Boston, MA, is a multinational corporation offering professi...
Q42. Which of the following statements is accurate regarding the methodology for managing the i...
Q43. Scenario 1: HealthGenic is a pediatric clinic that monitors the health and growth of indiv...
Q44. Scenario 3: Socket Inc. is a dynamic telecommunications company specializing in wireless p...
Q45. Company X restricted the access of the internal auditor of some of its documentation takin...
Q46. An organization uses Platform as a Service (PaaS) to host its cloud-based services. As suc...
Q47. TradeB communicated the information security processes and procedures to employees. Which ...
Q48. Scenario 5: OperazelT is a software development company that develops applications for var...
Q49. Question: An organization has implemented additional controls from other sources alongside...
Q50. Scenario 2: Beauty is a well-established cosmetics company in the beauty industry. The com...
Q51. Upon the risk assessment outcomes. Socket Inc. decided to: * Require the use of passwords ...
Q52. An organization has decided to conduct information security awareness and training session...
Q53. The application used by an organization has a complicated user interface. What does the co...
Q54. Scenario 3: Socket Inc. is a dynamic telecommunications company specializing in wireless p...
Q55. In the SABSA framework, which layer is concerned with viewing the services at a high level...
Q56. A small organization that is implementing an ISMS based on ISO/lEC 27001 has decided to ou...
Q57. Scenario 2: Beauty is a cosmetics company that has recently switched to an e-commerce mode...
Q58. Scenario 5: Operaze is a small software development company that develops applications for...
Q59. Scenario 5: OperazelT is a software development company that develops applications for var...
Q60. Question: How should the level of detail in risk identification evolve over time?...
Q61. Who should be involved, among others, in the draft, review, and validation of information ...
Q62. Scenario 3: Socket Inc is a telecommunications company offering mainly wireless products a...
Q63. Scenario 10: NetworkFuse develops, manufactures, and sells network hardware. The company h...
Q64. Which of the following is the most suitable option for presenting raw data in a user-frien...
Q65. Scenario 10: NetworkFuse develops, manufactures, and sells network hardware. The company h...
Q66. What is the main difference between an audit program and an audit plan?...
Q67. What is the purpose of an internal audit charter?...
Q68. Scenario 3: Socket Inc is a telecommunications company offering mainly wireless products a...
Q69. Scenario 2: Beauty is a well-established cosmetics company in the beauty industry. The com...
Q70. Scenario 1: HealthGenic is a leading multi-specialty healthcare organization providing pat...
Q71. Scenario 4: TradeB is a newly established commercial bank located in Europe, with a divers...
Q72. Scenario 7: Incident Response at Texas H&H Inc. Once they made sure that the attackers...
Q73. Scenario 9: OpenTech provides IT and communications services. It helps data communication ...
Q74. Scenario 1: HealthGenic is a pediatric clinic that monitors the health and growth of indiv...
Q75. An organization has adopted a new authentication method to ensure secure access to sensiti...
Q76. Scenario 6: Skyver offers worldwide shipping of electronic products, including gaming cons...
Q77. Which option below should be addressed in an information security policy?...
Q78. Which security controls must be implemented to comply with ISO/IEC 27001?...
Q79. Which statement is an example of risk retention?...
Q80. Following a repotted event, an Information security event ticket has been completed and it...
Q81. Scenario 8: SunDee is a biopharmaceutical firm headquartered in California, US. Renowned f...
Q82. Scenario 8: BioVitalis BioVitalis is a biopharmaceutical firm headquartered in California,...
Q83. Question: Which statement best describes an organization that has achieved the "Defined" m...
Q84. Upon the risk assessment outcomes. Socket Inc. decided to: * Require the use of passwords ...
Q85. Scenario 6: Skyver offers worldwide shipping of electronic products, including gaming cons...
Q86. Scenario 7: InfoSec, based in Boston, MA, is a multinational corporation offering professi...
Q87. Scenario 1: HealthGenic is a leading multi-specialty healthcare organization providing pat...
Q88. What does the organization still need to manage when using Platform as a Service (PaaS)?...
Q89. An organization that has an ISMS in place conducts management reviews at planned intervals...
Q90. Scenario 9: OpenTech provides IT and communications services. It helps data communication ...
Q91. Scenario 7: InfoSec is a multinational corporation headquartered in Boston, MA, which prov...
Q92. Scenario 1: HealthGenic is a pediatric clinic that monitors the health and growth of indiv...
Q93. Scenario 4: TradeB. a commercial bank that has just entered the market, accepts deposits f...
Q94. Once they made sure that the attackers do not have access in their system, the security ad...
[×]

Download PDF File

Enter your email address to download PECB.ISO-IEC-27001-Lead-Implementer.v2025-06-12.q94.pdf

Email:

DumpsFiles

Our website provides the Largest and the most Latest vendors Certification Exam materials around the world.

Using dumps we provide to Pass the Exam, we has the Valid Dumps with passing guranteed just which you need.

  • DMCA
  • About
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
©2025 DumpsFiles

www.dumpsfiles.com materials do not contain actual questions and answers from Cisco's certification exams.