
Free ISO-IEC-27001-Lead-Implementer Exam Braindumps certification guide Q&A
ISO-IEC-27001-Lead-Implementer Certification Overview Latest ISO-IEC-27001-Lead-Implementer PDF Dumps
NEW QUESTION 20
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. The use of tokens to gain access to information systems
- B. Encryption ofinformation
- C. Validation of input and output data in applications
- D. Information Security Management System
Answer: D
NEW QUESTION 21
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. When the organization is located near a river.
- B. When the computer systems are not insured.
- C. If the riskanalysis has not been carried out.
- D. When computer systems are kept in a cellar below ground level.
Answer: D
NEW QUESTION 22
Which of the following measures is a correctivemeasure?
- A. Making a backup of the data that has been created or altered that day
- B. Installing a virus scanner in an information system
- C. Incorporating an Intrusion Detection System (IDS) in the design of a computer center
- D. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
Answer: D
NEW QUESTION 23
How many domains does ISO / IEC 27002: 2013 have?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: B
NEW QUESTION 24
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct is a standard part of a labor contract.
- B. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
- C. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
Answer: C
NEW QUESTION 25
What should be used to protect data on removable media ifdata confidentiality or integrity are important considerations?
- A. a password
- B. cryptographic techniques
- C. logging
- D. backup on another removable medium
Answer: B
NEW QUESTION 26
The identified owner of an asset is always an individual
- A. True
- B. False
Answer: B
NEW QUESTION 27
ISO 27002 provides guidance in the following area
- A. Framework for an overall security andcompliance program
- B. PCI environment scoping
- C. Information handling recommendations
- D. Detailed lists of required policies and procedures
Answer: A
NEW QUESTION 28
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
- A. Availability, Integrity and Completeness
- B. Availability, Integrity and Confidentiality
- C. Timeliness, Accuracy and Completeness
- D. Availability, Information Value and Confidentiality
Answer: B
NEW QUESTION 29
What do employees need to know to report a security incident?
- A. Whether the incident has occurred before and what was the resulting damage.
- B. How to report an incident and to whom.
- C. The measures that should have been taken to prevent the incident in the first place.
- D. Who is responsible for the incident and whether it was intentional.
Answer: B
NEW QUESTION 30
Responsibilities for information security in projects should be defined and allocated to:
- A. the project manager
- B. the InfoSec officer
- C. the owner of the involved asset
- D. specified roles defined in the used project management method of the organization
Answer: D
NEW QUESTION 31
What is the objective of classifying information?
- A. Creating alabel that indicates how confidential the information is
- B. Defining different levels of sensitivity into which information may be arranged
- C. Authorizing the use of an information system
- D. Displaying on the document who is permitted access
Answer: B
NEW QUESTION 32
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?
- A. Reports can be developed more easily and with fewer errors.
- B. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
- C. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
- D. The costs for automating are easier to charge to the responsible departments.
Answer: B
NEW QUESTION 33
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.
- A. metadata
- B. teradata
- C. bridge
Answer: A
NEW QUESTION 34
What is the best description of a risk analysis?
- A. A risk analysis helps to estimate the risks and develop the appropriate security measures.
- B. A risk analysis is a method of mapping risks without looking at company processes.
- C. A risk analysis calculates the exact financial consequences of damages.
Answer: A
NEW QUESTION 35
You are a consultant and areregularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports.
Which reliability aspect of the information in your reports must you protect?
- A. Confidentiality
- B. Availability
- C. Integrity
Answer: A
NEW QUESTION 36
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventoryof threats and risks.
What is the relation between a threat, risk and risk analysis?
- A. A risk analysis is used to clarify which threats are relevant and what risks they involve.
- B. A risk analysis identifies threats from the known risks.
- C. A riskanalysis is used to remove the risk of a threat.
- D. Risk analyses help to find a balance between threats and risks.
Answer: A
NEW QUESTION 37
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)
- A. Return of assets
- B. Withdrawal or adaptation of access rights
- C. Restriction of access to information
- D. Management of access rights with special privileges
Answer: A,B,C
NEW QUESTION 38
What is the ISO / IEC 27002 standard?
- A. It is a guide of good practices that describes the controlobjectives and recommended controls regarding information security.
- B. It is a guide for the development and use of applicable metrics and measurement techniques to determine the effectiveness of an ISMS and the controls or groups of controls implemented according to ISO / IEC 27001.
- C. It is a guide that focuses on the critical aspects necessary for the successful design and implementation of an ISMS in accordance with ISO / IEC 27001
Answer: A
NEW QUESTION 39
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?
- A. Near Field Communication (NFC)
- B. The 4G protocol
- C. Bluetooth
- D. Radio Frequency Identification (RFID)
Answer: A
NEW QUESTION 40
......
The Best PECB ISO-IEC-27001-Lead-Implementer Study Guides and Dumps of 2021: https://www.actualcollection.com/ISO-IEC-27001-Lead-Implementer-exam-questions.html
Top PECB ISO-IEC-27001-Lead-Implementer Exam Audio Study Guide! Practice Questions Edition: https://drive.google.com/open?id=1AiSQKIWC94LTDHU3qPev_QEg97rYS8kU