
ISO-IEC-27001-Lead-Implementer Braindumps Real Exam Updated on Jan 09, 2022 with 50 Questions
Latest ISO-IEC-27001-Lead-Implementer PDF Dumps & Real Tests Free Updated Today
NEW QUESTION 12
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered
- A. True
- B. False
Answer: A
NEW QUESTION 13
Which of the following measures is a correctivemeasure?
- A. Installing a virus scanner in an information system
- B. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
- C. Making a backup of the data that has been created or altered that day
- D. Incorporating an Intrusion Detection System (IDS) in the design of a computer center
Answer: B
NEW QUESTION 14
What is an example of a security incident?
- A. A member of staff loses a laptop.
- B. You cannot set the correct fonts in your word processing software.
- C. A file is saved under an incorrect name.
- D. The lighting in the department no longer works.
Answer: A
NEW QUESTION 15
In the context ofcontact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.
- A. Availability
- B. Authentic
- C. Authorization
- D. Confidential
Answer: D
NEW QUESTION 16
What is an example of a non-human threat to the physical environment?
- A. Virus
- B. Fraudulent transaction
- C. Storm
- D. Corrupted file
Answer: C
NEW QUESTION 17
Responsibilities for information security in projects should be defined and allocated to:
- A. the owner of the involved asset
- B. specified roles defined in the used project management method of the organization
- C. the InfoSec officer
- D. the project manager
Answer: B
NEW QUESTION 18
What are the data protection principles set out in the GDPR?
- A. Purpose limitation, proportionality, data minimisation, transparency
- B. Purpose limitation, proportionality, availability, data minimisation
- C. Purpose limitation, pudicity, transparency, data minimisation
- D. Target group, proportionality, transparency, data minimisation
Answer: A
NEW QUESTION 19
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
- A. Paul and Susan, the sender and the recipient of the information.
- B. Paul, therecipient of the information.
- C. Susan, the sender of the information.
Answer: B
NEW QUESTION 20
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of theclients is earlier than the start date. What type of measure could prevent this error?
- A. Organizational measure
- B. Integrity measure
- C. Technical measure
- D. Availability measure
Answer: C
NEW QUESTION 21
Which of these control objectives are NOT in the domain "12.OPERATIONAL SAFETY"?
- A. Redundancies
- B. Test data
- C. Protection against malicious code
- D. Technical vulnerability management
Answer: A
NEW QUESTION 22
Which of the following measures is a preventive measure?
- A. Installing a logging system that enables changes in a system to be recognized
- B. Putting sensitive information in a safe
- C. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
- D. Shutting down all internet traffic after a hacker has gained access to thecompany systems
Answer: B
NEW QUESTION 23
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
- A. Availability, Integrity and Confidentiality
- B. Timeliness, Accuracy and Completeness
- C. Availability, Integrity and Completeness
- D. Availability, Information Value and Confidentiality
Answer: A
NEW QUESTION 24
What is the greatest risk for an organization ifno information security policy has been defined?
- A. It is not possible for an organization to implement information security in a consistent manner.
- B. Information security activities are carried out by only a few people.
- C. Too many measures areimplemented.
- D. If everyone works with the same account, it is impossible to find out who worked on what.
Answer: A
NEW QUESTION 25
It is allowed that employees and contractors are provided with an anonymous reporting channel to report violations of information security policies or procedures ("whistle blowing")
- A. True
- B. False
Answer: A
NEW QUESTION 26
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?
- A. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
- B. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
- C. The costs for automating are easier to charge to the responsible departments.
- D. Reports can be developed more easily and with fewer errors.
Answer: A
NEW QUESTION 27
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. Encryption ofinformation
- B. Information Security Management System
- C. Validation of input and output data in applications
- D. The use of tokens to gain access to information systems
Answer: B
NEW QUESTION 28
What do employees need to know to report a security incident?
- A. How to report an incident and to whom.
- B. Whether the incident has occurred before and what was the resulting damage.
- C. The measures that should have been taken to prevent the incident in the first place.
- D. Who is responsible for the incident and whether it was intentional.
Answer: A
NEW QUESTION 29
What is the best description of a risk analysis?
- A. A risk analysis calculates the exact financial consequences of damages.
- B. A risk analysis helps to estimate the risks and develop the appropriate security measures.
- C. A risk analysis is a method of mapping risks without looking at company processes.
Answer: B
NEW QUESTION 30
......
ISO-IEC-27001-Lead-Implementer Dumps With 100% Verified Q&As - Pass Guarantee or Full Refund: https://examcollection.dumpsvalid.com/ISO-IEC-27001-Lead-Implementer-brain-dumps.html