2021 ISO-IEC-27001-Lead-Implementer Dumps PDF - ISO-IEC-27001-Lead-Implementer Real Exam Questions Answers [Q17-Q37]

Share

2021 ISO-IEC-27001-Lead-Implementer Dumps PDF - ISO-IEC-27001-Lead-Implementer Real Exam Questions Answers

Valid ISO-IEC-27001-Lead-Implementer Test Answers & PECB ISO-IEC-27001-Lead-Implementer Exam PDF

NEW QUESTION 17
What do employees need to know to report a security incident?

  • A. How to report an incident and to whom.
  • B. Whether the incident has occurred before and what was the resulting damage.
  • C. The measures that should have been taken to prevent the incident in the first place.
  • D. Who is responsible for the incident and whether it was intentional.

Answer: A

 

NEW QUESTION 18
Which of these reliability aspects is "completeness" a part of?

  • A. Exclusivity
  • B. Integrity
  • C. Availability
  • D. Confidentiality

Answer: B

 

NEW QUESTION 19
Of the following, which is the best organization or set of organizations to contribute to compliance?

  • A. IT and legal
  • B. IT,business management, HR and legal
  • C. IT and management
  • D. IT only

Answer: B

 

NEW QUESTION 20
You have juststarted working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?

  • A. A code of conduct is alegal obligation that organizations have to meet.
  • B. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
  • C. A code of conduct prevents a virus outbreak.
  • D. A code of conduct helps to prevent the misuse of IT facilities.

Answer: D

 

NEW QUESTION 21
ISO 27002 provides guidance in the following area

  • A. PCI environment scoping
  • B. Information handling recommendations
  • C. Framework for an overall security andcompliance program
  • D. Detailed lists of required policies and procedures

Answer: C

 

NEW QUESTION 22
What is the objective of classifying information?

  • A. Creating alabel that indicates how confidential the information is
  • B. Displaying on the document who is permitted access
  • C. Authorizing the use of an information system
  • D. Defining different levels of sensitivity into which information may be arranged

Answer: D

 

NEW QUESTION 23
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.

  • A. bridge
  • B. metadata
  • C. teradata

Answer: B

 

NEW QUESTION 24
What is an example of a non-human threat to the physical environment?

  • A. Virus
  • B. Fraudulent transaction
  • C. Storm
  • D. Corrupted file

Answer: C

 

NEW QUESTION 25
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?

  • A. Paul and Susan, the sender and the recipient of the information.
  • B. Paul, therecipient of the information.
  • C. Susan, the sender of the information.

Answer: B

 

NEW QUESTION 26
How many domains does ISO / IEC 27002: 2013 have?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

 

NEW QUESTION 27
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?

  • A. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
  • B. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
  • C. The costs for automating are easier to charge to the responsible departments.
  • D. Reports can be developed more easily and with fewer errors.

Answer: A

 

NEW QUESTION 28
Which of these control objectives are NOT in the domain "12.OPERATIONAL SAFETY"?

  • A. Redundancies
  • B. Test data
  • C. Protection against malicious code
  • D. Technical vulnerability management

Answer: A

 

NEW QUESTION 29
What is the best description of a risk analysis?

  • A. A risk analysis calculates the exact financial consequences of damages.
  • B. A risk analysis helps to estimate the risks and develop the appropriate security measures.
  • C. A risk analysis is a method of mapping risks without looking at company processes.

Answer: B

 

NEW QUESTION 30
Who is accountable to classify information assets?

  • A. the Information Security Team
  • B. the CEO
  • C. theasset owner
  • D. the CISO

Answer: C

 

NEW QUESTION 31
What is the greatest risk for an organization ifno information security policy has been defined?

  • A. It is not possible for an organization to implement information security in a consistent manner.
  • B. Information security activities are carried out by only a few people.
  • C. Too many measures areimplemented.
  • D. If everyone works with the same account, it is impossible to find out who worked on what.

Answer: A

 

NEW QUESTION 32
Which of the following measures is a correctivemeasure?

  • A. Installing a virus scanner in an information system
  • B. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
  • C. Making a backup of the data that has been created or altered that day
  • D. Incorporating an Intrusion Detection System (IDS) in the design of a computer center

Answer: B

 

NEW QUESTION 33
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?

  • A. Radio Frequency Identification (RFID)
  • B. Near Field Communication (NFC)
  • C. The 4G protocol
  • D. Bluetooth

Answer: B

 

NEW QUESTION 34
What should be used to protect data on removable media ifdata confidentiality or integrity are important considerations?

  • A. backup on another removable medium
  • B. cryptographic techniques
  • C. logging
  • D. a password

Answer: B

 

NEW QUESTION 35
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?

  • A. When the organization is located near a river.
  • B. When computer systems are kept in a cellar below ground level.
  • C. When the computer systems are not insured.
  • D. If the riskanalysis has not been carried out.

Answer: B

 

NEW QUESTION 36
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

  • A. Thefirst step consists of checking if the user is using the correct certificate.
  • B. The first step consists of granting access to the information to which the user is authorized.
  • C. The first step consists of comparing the password with the registered password.
  • D. The first step consists of checking if the user appears on the list of authorized users.

Answer: D

 

NEW QUESTION 37
......

ISO-IEC-27001-Lead-Implementer Exam Dumps - PDF Questions and Testing Engine: https://certmagic.surepassexams.com/ISO-IEC-27001-Lead-Implementer-exam-bootcamp.html