A.Only reviewing the risk assessment. Clause 4.4 treats this as a nonconformity finding during the corrective action process rather than as routine ISMS operation.
B.Only document review
C.Only automated scanning
D.Interviews, observation, and review of documented information and records
Why D is correct
Auditors gather evidence through multiple methods: interviews with staff, observation of practices, and review of documentation and records.
Know someone studying for ISO 27001? Send them this one.
Where this fits in the ISO 27001 exam
Iso Certification Audit
ISO 27001 certification: Stage 1 and Stage 2 audits, nonconformities, surveillance audits, and recertification.
This question belongs to the "Performance Evaluation & Improvement" domain, which makes up about 15% of the ISO 27001 exam.
CyberCertPrep gives you 20 free ISO 27001 questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
ISO 27001 and ISO are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by ISO or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
Which of the following is mandatory documented information for ISO 27001 certification?