
Steps Necessary To Pass The ISO-IEC-27001-Lead-Auditor Exam from Training Expert Exams4sures
Valid Way To Pass ISO 27001's ISO-IEC-27001-Lead-Auditor Exam
NEW QUESTION 39
How is the purpose of information security policy best described?
- A. An information security policy provides direction and support to the management regarding information security.
- B. An information security policy makes the security plan concrete by providing it with the necessary details.
- C. An information security policy provides insight into threats and the possible consequences.
- D. An information security policy documents the analysis of risks and the search for countermeasures.
Answer: A
NEW QUESTION 40
Who is responsible for Initial asset allocation to the user/custodian of the assets?
- A. Asset Owner
- B. Asset Stakeholder
- C. Asset Manager
- D. Asset Practitioner
Answer: A
NEW QUESTION 41
Availability means
- A. Service should not be accessible when required
- B. Service should be accessible at the required time and usable only by the authorized entity
- C. Service should be accessible at the required time and usable by all
Answer: B
NEW QUESTION 42
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password.
What kind of threat is this?
- A. Social Engineering
- B. Arason
- C. Natural threat
- D. Organizational threat
Answer: A
NEW QUESTION 43
Which of the following is a preventive security measure?
- A. Shutting down the Internet connection after an attack
- B. Installing logging and monitoring software
- C. Storing sensitive information in a data save
Answer: C
NEW QUESTION 44
What is the worst possible action that an employee may receive for sharing his or her password or access with others?
- A. The lowest rating on his or her performance assessment
- B. Termination
- C. Three days suspension from work
- D. Forced roll off from the project
Answer: B
NEW QUESTION 45
An employee caught with offense of abusing the internet, such as P2P file sharing or video/audio streaming, will not receive a warning for committing such act but will directly receive an IR.
- A. False
- B. True
Answer: B
NEW QUESTION 46
Which of the following does an Asset Register contain? (Choose two)
- A. Asset Modifier
- B. Asset Owner
- C. Process ID
- D. Asset Type
Answer: B,D
NEW QUESTION 47
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good.
What is an example of the indirect damage caused by this fire?
- A. Burned computer systems
- B. Melted backup tapes
- C. Water damage due to the fire extinguishers
- D. Burned documents
Answer: C
NEW QUESTION 48
What is the goal of classification of information?
- A. Structuring information according to its sensitivity
- B. Applying labels making the information easier to recognize
- C. To create a manual about how to handle mobile devices
Answer: A
NEW QUESTION 49
There is a scheduled fire drill in your facility. What should you do?
- A. None of the above
- B. Call in sick
- C. Excuse yourself by saying you have an urgent deliverable
- D. Participate in the drill
Answer: D
NEW QUESTION 50
Which reliability aspect of information is compromised when a staff member denies having sent a message?
- A. Confidentiality
- B. Correctness
- C. Availability
- D. Integrity
Answer: D
NEW QUESTION 51
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself.
You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
NEW QUESTION 52
What is the standard definition of ISMS?
- A. Is an information security systematic approach to achieve business objectives for implementation, establishing, reviewing,operating and maintaining organization's reputation.
- B. A company wide business objectives to achieve information security awareness for establishing, implementing, operating, monitoring, reviewing, maintaining and improving
- C. A systematic approach for establishing, implementing, operating,monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives.
- D. A project-based approach to achieve business objectives for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security
Answer: C
NEW QUESTION 53
Integrity of data means
- A. Data should be accessed by only the right people
- B. Data should be viewable at all times
- C. Accuracy and completeness of the data
Answer: C
NEW QUESTION 54
All are prohibited in acceptable use of information assets, except:
- A. Messages with very large attachments or to a large number ofrecipients.
- B. Company-wide e-mails with supervisor/TL permission.
- C. E-mail copies to non-essential readers
- D. Electronic chain letters
Answer: B
NEW QUESTION 55
An employee caught temporarily storing an MP3 file in his workstation will not receive an IR.
- A. False
- B. True
Answer: A
NEW QUESTION 56
Often, people do not pick up their prints from a shared printer. How can this affect the confidentiality of information?
- A. Availability cannot be guaranteed
- B. Integrity cannot be guaranteed
- C. Confidentiality cannot be guaranteed
- D. Authenticity cannot be guaranteed
Answer: C
NEW QUESTION 57
A scenario wherein the city or location where the building(s) reside is / are not accessible.
- A. City
- B. Component
- C. Facility
- D. Country
Answer: A
NEW QUESTION 58
A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:
- A. Greet and ask him what is his business
- B. Say "hi" and offer coffee
- C. Escort him to his destination
- D. Call the receptionist and inform about the visitor
Answer: B
NEW QUESTION 59
Which of the following does a lack of adequate security controls represent?
- A. Threat
- B. Vulnerability
- C. Impact
- D. Asset
Answer: B
NEW QUESTION 60
What type of system ensures a coherent Information Security organisation?
- A. Information Technology Service Management System (ITSM)
- B. Information Exchange Data System (IEDS)
- C. Information Security Management System (ISMS)
- D. Federal Information Security Management Act (FISMA)
Answer: C
NEW QUESTION 61
Information has a number of reliability aspects. Reliability is constantly being threatened. Examples of threats are: a cable becomes loose, someone alters information by accident, data is used privately or is falsified.
Which of these examples is a threat to integrity?
- A. accidental alteration of data
- B. private use of data
- C. a loose cable
- D. System restart
Answer: A
NEW QUESTION 62
......
All ISO-IEC-27001-Lead-Auditor Dumps and PECB Certified ISO/IEC 27001 Lead Auditor exam Training Courses: https://www.exams4sures.com/PECB/ISO-IEC-27001-Lead-Auditor-practice-exam-dumps.html
Free Test Engine For PECB Certified ISO/IEC 27001 Lead Auditor exam Certification Exams: https://drive.google.com/open?id=1t5MbQ6UvaJT2tm4buCSPbtYYdPQend90