2021 ISO-IEC-27001-Lead-Implementer dumps review - Professional Quiz Study Materials ISO-IEC-27001-Lead-Implementer Test Prep Training Practice Exam Questions Practice Tests NEW QUESTION 28 Which of the following measures is a preventive measure? A. Shutting down all internet traffic after a hacker has gained access to thecompany systems B. Putting sensitive information in a safe C. Installing a logging [...]

2021 ISO-IEC-27001-Lead-Implementer dumps review - Professional Quiz Study Materials [Q28-Q48]

Share

2021 ISO-IEC-27001-Lead-Implementer dumps review - Professional Quiz Study Materials

ISO-IEC-27001-Lead-Implementer Test Prep Training Practice Exam Questions Practice Tests

NEW QUESTION 28
Which of the following measures is a preventive measure?

  • A. Shutting down all internet traffic after a hacker has gained access to thecompany systems
  • B. Putting sensitive information in a safe
  • C. Installing a logging system that enables changes in a system to be recognized
  • D. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk

Answer: B

 

NEW QUESTION 29
Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)

  • A. Cryptographic Controls Use Policy
  • B. Key management
  • C. Work in safe areas
  • D. Physical security perimeter

Answer: A,B

 

NEW QUESTION 30
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?

  • A. A code of conduct is a standard part of a labor contract.
  • B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
  • C. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.

Answer: B

 

NEW QUESTION 31
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?

  • A. Information Security Management System
  • B. Encryption ofinformation
  • C. The use of tokens to gain access to information systems
  • D. Validation of input and output data in applications

Answer: A

 

NEW QUESTION 32
What does the Information Security Policy describe?

  • A. which InfoSec-controls have been selected and taken
  • B. how the InfoSec-objectives will be reached
  • C. what the implementation-planning of the information security management system is
  • D. which Information Security-procedures are selected

Answer: B

 

NEW QUESTION 33
In the context ofcontact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.

  • A. Confidential
  • B. Availability
  • C. Authentic
  • D. Authorization

Answer: A

 

NEW QUESTION 34
Which of the following measures is a correctivemeasure?

  • A. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
  • B. Making a backup of the data that has been created or altered that day
  • C. Installing a virus scanner in an information system
  • D. Incorporating an Intrusion Detection System (IDS) in the design of a computer center

Answer: A

 

NEW QUESTION 35
What is the most important reason for applying the segregation of duties?

  • A. Segregation of duties makes it clear who is responsible for what.
  • B. Segregation of duties makes it easier for a person who is readywith his or her part of the work to take time off or to take over the work of another person.
  • C. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
  • D. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.

Answer: D

 

NEW QUESTION 36
What is an example of a good physical security measure?

  • A. Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.
  • B. Printers that are defective or have been replacedare immediately removed and given away as garbage for recycling.
  • C. All employees and visitors carry an access pass.

Answer: C

 

NEW QUESTION 37
Why is compliance important forthe reliability of the information?

  • A. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
  • B. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
  • C. By meeting the legislative requirements and theregulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
  • D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and thereforeit guarantees the reliability of its information.

Answer: C

 

NEW QUESTION 38
Companies use 27002 for compliance for which of the following reasons:

  • A. A structured program that helps with security and compliance
  • B. Explicit requirements for all regulations
  • C. Compliance with ISO 27002 is sufficient to comply with all regulations

Answer: A

 

NEW QUESTION 39
The identified owner of an asset is always an individual

  • A. False
  • B. True

Answer: A

 

NEW QUESTION 40
ISO 27002 provides guidance in the following area

  • A. Framework for an overall security andcompliance program
  • B. Detailed lists of required policies and procedures
  • C. Information handling recommendations
  • D. PCI environment scoping

Answer: A

 

NEW QUESTION 41
Responsibilities for information security in projects should be defined and allocated to:

  • A. the InfoSec officer
  • B. specified roles defined in the used project management method of the organization
  • C. the owner of the involved asset
  • D. the project manager

Answer: B

 

NEW QUESTION 42
What should be used to protect data on removable media ifdata confidentiality or integrity are important considerations?

  • A. backup on another removable medium
  • B. a password
  • C. cryptographic techniques
  • D. logging

Answer: C

 

NEW QUESTION 43
Prior to employment, _________ as well as terms & conditions of employment are included as controls in ISO
27002 to ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.

  • A. authorizing
  • B. screening
  • C. controlling
  • D. flexing

Answer: B

 

NEW QUESTION 44
Which of these reliability aspects is "completeness" a part of?

  • A. Confidentiality
  • B. Availability
  • C. Integrity
  • D. Exclusivity

Answer: C

 

NEW QUESTION 45
How many domains does ISO / IEC 27002: 2013 have?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: C

 

NEW QUESTION 46
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?

  • A. When the organization is located near a river.
  • B. When computer systems are kept in a cellar below ground level.
  • C. If the riskanalysis has not been carried out.
  • D. When the computer systems are not insured.

Answer: B

 

NEW QUESTION 47
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?

  • A. The recipient, Rachel
  • B. The person who drafted the insurance terms and conditions
  • C. The sender, Peter
  • D. The manager, Linda

Answer: A

 

NEW QUESTION 48
......

Exam Questions Answers Braindumps ISO-IEC-27001-Lead-Implementer Exam Dumps PDF Questions: https://www.exam4free.com/ISO-IEC-27001-Lead-Implementer-valid-dumps.html

ISO-IEC-27001-Lead-Implementer Exam Dumps, ISO-IEC-27001-Lead-Implementer Practice Test Questions: https://drive.google.com/open?id=1_9PTWeGmRzkaN0PV_QqAs4vMe73gRzib