
ISO 27001 ISO-IEC-27001-Lead-Implementer Real Exam Questions and Answers FREE Updated on Oct 09, 2021
ISO-IEC-27001-Lead-Implementer Ultimate Study Guide - TestPDF
NEW QUESTION 27
ISO 27002 provides guidance in the following area
- A. Framework for an overall security andcompliance program
- B. Detailed lists of required policies and procedures
- C. Information handling recommendations
- D. PCI environment scoping
Answer: A
NEW QUESTION 28
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?
- A. Thefirst step consists of checking if the user is using the correct certificate.
- B. The first step consists of granting access to the information to which the user is authorized.
- C. The first step consists of checking if the user appears on the list of authorized users.
- D. The first step consists of comparing the password with the registered password.
Answer: C
NEW QUESTION 29
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk passing
- B. Risk bearing
- C. Risk avoiding
- D. Risk neutral
Answer: D
NEW QUESTION 30
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the company's staff. Which kind of security measure could have prevented this?
- A. A technical security measure
- B. physical security measure
- C. An organizational security measure
Answer: B
NEW QUESTION 31
Prior to employment, _________ as well as terms & conditions of employment are included as controls in ISO
27002 to ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.
- A. authorizing
- B. screening
- C. controlling
- D. flexing
Answer: B
NEW QUESTION 32
Which of the following measures is a correctivemeasure?
- A. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
- B. Installing a virus scanner in an information system
- C. Incorporating an Intrusion Detection System (IDS) in the design of a computer center
- D. Making a backup of the data that has been created or altered that day
Answer: A
NEW QUESTION 33
What is the ISO / IEC 27002 standard?
- A. It is a guide of good practices that describes the controlobjectives and recommended controls regarding information security.
- B. It is a guide that focuses on the critical aspects necessary for the successful design and implementation of an ISMS in accordance with ISO / IEC 27001
- C. It is a guide for the development and use of applicable metrics and measurement techniques to determine the effectiveness of an ISMS and the controls or groups of controls implemented according to ISO / IEC 27001.
Answer: A
NEW QUESTION 34
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.
- A. metadata
- B. bridge
- C. teradata
Answer: A
NEW QUESTION 35
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. If the riskanalysis has not been carried out.
- B. When the organization is located near a river.
- C. When the computer systems are not insured.
- D. When computer systems are kept in a cellar below ground level.
Answer: D
NEW QUESTION 36
Which of these control objectives are NOT in the domain "12.OPERATIONAL SAFETY"?
- A. Test data
- B. Technical vulnerability management
- C. Protection against malicious code
- D. Redundancies
Answer: D
NEW QUESTION 37
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)
- A. Restriction of access to information
- B. Return of assets
- C. Withdrawal or adaptation of access rights
- D. Management of access rights with special privileges
Answer: A,B,C
NEW QUESTION 38
The identified owner of an asset is always an individual
- A. False
- B. True
Answer: A
NEW QUESTION 39
What is the greatest risk for an organization ifno information security policy has been defined?
- A. It is not possible for an organization to implement information security in a consistent manner.
- B. Information security activities are carried out by only a few people.
- C. Too many measures areimplemented.
- D. If everyone works with the same account, it is impossible to find out who worked on what.
Answer: A
NEW QUESTION 40
What sort of security does a Public Key Infrastructure (PKI) offer?
- A. By providing agreements, procedures and an organization structure, a PKI defines which person or which system belongs to which specific public key.
- B. A PKI ensures that backups of company data are made on a regular basis.
- C. Having a PKI shows customers that a web-based business is secure.
- D. It provides digital certificates that can be used to digitally signdocuments. Such signatures irrefutably determine from whom a document was sent.
Answer: B
NEW QUESTION 41
What should be used to protect data on removable media ifdata confidentiality or integrity are important considerations?
- A. backup on another removable medium
- B. logging
- C. cryptographic techniques
- D. a password
Answer: C
NEW QUESTION 42
......
Ultimate Guide to Prepare ISO-IEC-27001-Lead-Implementer Certification Exam for ISO 27001: https://www.testpdf.com/ISO-IEC-27001-Lead-Implementer-exam-braindumps.html
Use Real ISO-IEC-27001-Lead-Implementer Dumps - PECB Correct Answers: https://drive.google.com/open?id=1FEcwm370VnBKIKvolMV0g7iOHXlMEDBM
