
ISO-IEC-27001-Lead-Implementer Exam PDF [2023] Tests Free Updated Today with Correct 50 Questions
PECB ISO-IEC-27001-Lead-Implementer Exam Preparation Guide and PDF Download
NEW QUESTION # 28
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. Encryption ofinformation
- B. Validation of input and output data in applications
- C. The use of tokens to gain access to information systems
- D. Information Security Management System
Answer: D
NEW QUESTION # 29
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)
- A. Return of assets
- B. Restriction of access to information
- C. Withdrawal or adaptation of access rights
- D. Management of access rights with special privileges
Answer: A,B,C
NEW QUESTION # 30
What does the Information Security Policy describe?
- A. which InfoSec-controls have been selected and taken
- B. which Information Security-procedures are selected
- C. what the implementation-planning of the information security management system is
- D. how the InfoSec-objectives will be reached
Answer: D
NEW QUESTION # 31
Who is authorized to change the classification of a document?
- A. The author of the document
- B. The manager of the owner of the document
- C. The administrator of the document
- D. The owner of the document
Answer: D
NEW QUESTION # 32
Which of these reliability aspects is "completeness" a part of?
- A. Confidentiality
- B. Exclusivity
- C. Availability
- D. Integrity
Answer: D
NEW QUESTION # 33
In the context ofcontact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.
- A. Authorization
- B. Authentic
- C. Confidential
- D. Availability
Answer: C
NEW QUESTION # 34
Of the following, which is the best organization or set of organizations to contribute to compliance?
- A. IT,business management, HR and legal
- B. IT and legal
- C. IT only
- D. IT and management
Answer: A
NEW QUESTION # 35
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct is a standard part of a labor contract.
- B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
- C. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
Answer: B
NEW QUESTION # 36
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.
- A. bridge
- B. metadata
- C. teradata
Answer: B
NEW QUESTION # 37
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk avoiding
- B. Risk bearing
- C. Risk neutral
- D. Risk passing
Answer: C
NEW QUESTION # 38
Companies use 27002 for compliance for which of the following reasons:
- A. Compliance with ISO 27002 is sufficient to comply with all regulations
- B. A structured program that helps with security and compliance
- C. Explicit requirements for all regulations
Answer: B
NEW QUESTION # 39
How many domains does ISO / IEC 27002: 2013 have?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION # 40
Why is compliance important forthe reliability of the information?
- A. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- B. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- C. By meeting the legislative requirements and theregulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
- D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and thereforeit guarantees the reliability of its information.
Answer: C
NEW QUESTION # 41
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. When computer systems are kept in a cellar below ground level.
- B. If the riskanalysis has not been carried out.
- C. When the organization is located near a river.
- D. When the computer systems are not insured.
Answer: A
NEW QUESTION # 42
What is the most important reason for applying the segregation of duties?
- A. Segregation of duties makes it easier for a person who is readywith his or her part of the work to take time off or to take over the work of another person.
- B. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
- C. Segregation of duties makes it clear who is responsible for what.
- D. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
Answer: D
NEW QUESTION # 43
What do employees need to know to report a security incident?
- A. Who is responsible for the incident and whether it was intentional.
- B. How to report an incident and to whom.
- C. Whether the incident has occurred before and what was the resulting damage.
- D. The measures that should have been taken to prevent the incident in the first place.
Answer: B
NEW QUESTION # 44
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?
- A. The first step consists of checking if the user appears on the list of authorized users.
- B. Thefirst step consists of checking if the user is using the correct certificate.
- C. The first step consists of comparing the password with the registered password.
- D. The first step consists of granting access to the information to which the user is authorized.
Answer: A
NEW QUESTION # 45
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?
- A. The costs for automating are easier to charge to the responsible departments.
- B. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
- C. Reports can be developed more easily and with fewer errors.
- D. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
Answer: D
NEW QUESTION # 46
What sort of security does a Public Key Infrastructure (PKI) offer?
- A. A PKI ensures that backups of company data are made on a regular basis.
- B. By providing agreements, procedures and an organization structure, a PKI defines which person or which system belongs to which specific public key.
- C. Having a PKI shows customers that a web-based business is secure.
- D. It provides digital certificates that can be used to digitally signdocuments. Such signatures irrefutably determine from whom a document was sent.
Answer: A
NEW QUESTION # 47
Which of the following measures is a correctivemeasure?
- A. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
- B. Incorporating an Intrusion Detection System (IDS) in the design of a computer center
- C. Installing a virus scanner in an information system
- D. Making a backup of the data that has been created or altered that day
Answer: A
NEW QUESTION # 48
......
Verified & Correct ISO-IEC-27001-Lead-Implementer Practice Test Reliable Source Jul 24, 2023 Updated: https://passleader.torrentvalid.com/ISO-IEC-27001-Lead-Implementer-valid-braindumps-torrent.html