2021 Updated Verified Pass ISO-IEC-27001-Lead-Implementer Study Guides & Best Courses [Q11-Q32]

Share

2021 Updated Verified Pass ISO-IEC-27001-Lead-Implementer Study Guides & Best Courses

Ultimate Guide to the ISO-IEC-27001-Lead-Implementer - Latest Edition Available Now

NEW QUESTION 11
What is the objective of classifying information?

  • A. Defining different levels of sensitivity into which information may be arranged
  • B. Authorizing the use of an information system
  • C. Creating alabel that indicates how confidential the information is
  • D. Displaying on the document who is permitted access

Answer: A

 

NEW QUESTION 12
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?

  • A. Availability, Information Value and Confidentiality
  • B. Availability, Integrity and Completeness
  • C. Availability, Integrity and Confidentiality
  • D. Timeliness, Accuracy and Completeness

Answer: C

 

NEW QUESTION 13
What is an example of a non-human threat to the physical environment?

  • A. Virus
  • B. Storm
  • C. Corrupted file
  • D. Fraudulent transaction

Answer: B

 

NEW QUESTION 14
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?

  • A. Personal data protection legislation
  • B. Intellectual Property Rights
  • C. ISO/IEC 27002:2005
  • D. ISO/IEC 27001:2005

Answer: A

 

NEW QUESTION 15
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)

  • A. Restriction of access to information
  • B. Management of access rights with special privileges
  • C. Withdrawal or adaptation of access rights
  • D. Return of assets

Answer: A,C,D

 

NEW QUESTION 16
ISO 27002 provides guidance in the following area

  • A. Framework for an overall security andcompliance program
  • B. Detailed lists of required policies and procedures
  • C. Information handling recommendations
  • D. PCI environment scoping

Answer: A

 

NEW QUESTION 17
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?

  • A. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
  • B. The costs for automating are easier to charge to the responsible departments.
  • C. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
  • D. Reports can be developed more easily and with fewer errors.

Answer: A

 

NEW QUESTION 18
Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)

  • A. Cryptographic Controls Use Policy
  • B. Key management
  • C. Work in safe areas
  • D. Physical security perimeter

Answer: A,B

 

NEW QUESTION 19
Which of these reliability aspects is "completeness" a part of?

  • A. Confidentiality
  • B. Availability
  • C. Integrity
  • D. Exclusivity

Answer: C

 

NEW QUESTION 20
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the company's staff. Which kind of security measure could have prevented this?

  • A. physical security measure
  • B. A technical security measure
  • C. An organizational security measure

Answer: A

 

NEW QUESTION 21
What is an example of a good physical security measure?

  • A. Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.
  • B. Printers that are defective or have been replacedare immediately removed and given away as garbage for recycling.
  • C. All employees and visitors carry an access pass.

Answer: C

 

NEW QUESTION 22
Of the following, which is the best organization or set of organizations to contribute to compliance?

  • A. IT and management
  • B. IT and legal
  • C. IT,business management, HR and legal
  • D. IT only

Answer: C

 

NEW QUESTION 23
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventoryof threats and risks.
What is the relation between a threat, risk and risk analysis?

  • A. A riskanalysis is used to remove the risk of a threat.
  • B. A risk analysis identifies threats from the known risks.
  • C. A risk analysis is used to clarify which threats are relevant and what risks they involve.
  • D. Risk analyses help to find a balance between threats and risks.

Answer: C

 

NEW QUESTION 24
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?

  • A. Information Security Management System
  • B. Encryption ofinformation
  • C. The use of tokens to gain access to information systems
  • D. Validation of input and output data in applications

Answer: A

 

NEW QUESTION 25
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

  • A. Risk passing
  • B. Risk neutral
  • C. Risk avoiding
  • D. Risk bearing

Answer: B

 

NEW QUESTION 26
What is the ISO / IEC 27002 standard?

  • A. It is a guide for the development and use of applicable metrics and measurement techniques to determine the effectiveness of an ISMS and the controls or groups of controls implemented according to ISO / IEC 27001.
  • B. It is a guide that focuses on the critical aspects necessary for the successful design and implementation of an ISMS in accordance with ISO / IEC 27001
  • C. It is a guide of good practices that describes the controlobjectives and recommended controls regarding information security.

Answer: C

 

NEW QUESTION 27
What is the best way to comply with legislation and regulations for personal data protection?

  • A. Performing a threat analysis
  • B. Performing a vulnerability analysis
  • C. Maintaining an incident register
  • D. Appointing the responsibility to someone

Answer: D

 

NEW QUESTION 28
What do employees need to know to report a security incident?

  • A. Who is responsible for the incident and whether it was intentional.
  • B. The measures that should have been taken to prevent the incident in the first place.
  • C. How to report an incident and to whom.
  • D. Whether the incident has occurred before and what was the resulting damage.

Answer: C

 

NEW QUESTION 29
What is the best description of a risk analysis?

  • A. A risk analysis calculates the exact financial consequences of damages.
  • B. A risk analysis is a method of mapping risks without looking at company processes.
  • C. A risk analysis helps to estimate the risks and develop the appropriate security measures.

Answer: C

 

NEW QUESTION 30
You are a consultant and areregularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports.
Which reliability aspect of the information in your reports must you protect?

  • A. Confidentiality
  • B. Availability
  • C. Integrity

Answer: A

 

NEW QUESTION 31
......

Dumps MoneyBack Guarantee - ISO-IEC-27001-Lead-Implementer Dumps Approved Dumps: https://www.itexamdownload.com/ISO-IEC-27001-Lead-Implementer-valid-questions.html

2021 Updated Verified Pass ISO-IEC-27001-Lead-Implementer Exam - Real Questions & Answers: https://drive.google.com/open?id=1FdRxus1ef3oFU8zs8pQLI6HImrAtftqn