[Nov-2021] ISO-IEC-27001-Lead-Auditor Dumps are Available for Instant Access using TrainingDump [Q44-Q69]

Share

[Nov-2021] ISO-IEC-27001-Lead-Auditor Dumps are Available for Instant Access using  TrainingDump 

ISO-IEC-27001-Lead-Auditor Dumps 2021 - New PECB ISO-IEC-27001-Lead-Auditor Exam Questions

NEW QUESTION 44
As a new member of the IT department you have noticed that confidential information has been leaked several times. This may damage the reputation of the company. You have been asked to propose an organisational measure to protect laptop computers. What is the first step in a structured approach to come up with this measure?

  • A. Formulate a policy
  • B. Encrypt all sensitive information
  • C. Set up an access control procedure
  • D. Appoint security staff

Answer: A

 

NEW QUESTION 45
Which of the following is a technical security measure?

  • A. Safe storage of backups
  • B. User role profiles.
  • C. Security policy
  • D. Encryption

Answer: D

 

NEW QUESTION 46
A hacker gains access to a webserver and can view a file on the server containing credit card numbers.
Which of the Confidentiality, Integrity, Availability (CIA) principles of the credit card file are violated?

  • A. Compliance
  • B. Confidentiality
  • C. Availability
  • D. Integrity

Answer: B

 

NEW QUESTION 47
Information or data that are classified as ______ do not require labeling.

  • A. Internal
  • B. Public
  • C. Highly Confidential
  • D. Confidential

Answer: B

 

NEW QUESTION 48
Does the security have the right to ask you to display your ID badges and check your bags?

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 49
You see a blue color sticker on certain physical assets. What does this signify?

  • A. The asset is critical and the impact is restricted to an employee only
  • B. The asset with blue stickers should be kept air conditioned at all times
  • C. The asset is high critical and its failure will affect a group/s/project's work in the organization
  • D. The asset is very high critical and its failure affects the entire organization

Answer: C

 

NEW QUESTION 50
__________ is a software used or created by hackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems.

  • A. Malware
  • B. Virus
  • C. Trojan
  • D. Operating System

Answer: A

 

NEW QUESTION 51
Which of the following factors does NOT contribute to the value of data for an organisation?

  • A. The importance of data for processes
  • B. The content of data
  • C. The correctness of data
  • D. The indispensability of data

Answer: B

 

NEW QUESTION 52
What is we do in ACT - From PDCA cycle

  • A. Take actions to continually improve process performance
  • B. Take actions to continually monitor process performance
  • C. Take actions to continually monitor process performance
  • D. Take actions to continually improve people performance

Answer: A

 

NEW QUESTION 53
What is social engineering?

  • A. The organization planning an activity for welfare of the neighborhood
  • B. A group planning for a social activity in the organization
  • C. Creating a situation wherein a third party gains confidential information from you

Answer: C

 

NEW QUESTION 54
What controls can you do to protect sensitive data in your computer when you go out for lunch?

  • A. You lock your computer by pressing Windows+L or CTRL-ALT-DELETE and then click "Lock Computer".
  • B. You turn off the monitor
  • C. You activate your favorite screen-saver
  • D. You are confident to leave your computer screen as is since a password protected screensaver is installed and it is set to activate after 10 minutes of inactivity

Answer: A

 

NEW QUESTION 55
-------------------------is an asset like other important business assets has value to an organization and consequently needs to be protected.

  • A. Information
  • B. Infrastructure
  • C. Data
  • D. Security

Answer: A

 

NEW QUESTION 56
A well-executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives.
What is not one of the four main objectives of a risk analysis?

  • A. Implementing counter measures
  • B. Identifying assets and their value
  • C. Determining relevant vulnerabilities and threats
  • D. Establishing a balance between the costs of an incident and the costs of a security measure

Answer: A

 

NEW QUESTION 57
How are data and information related?

  • A. When meaning and value are assigned to data, it becomes information
  • B. Data is a collection of structured and unstructured information
  • C. Information consists of facts and statistics collected together for reference or analysis

Answer: A

 

NEW QUESTION 58
What type of legislation requires a proper controlled purchase process?

  • A. Government information act
  • B. Intellectual property rights act
  • C. Personal data protection act
  • D. Computer criminality act

Answer: B

 

NEW QUESTION 59
Which is not a requirement of HR prior to hiring?

  • A. Must undergo Awareness training on information security.
  • B. Undergo background verification
  • C. Applicant must complete pre-employment documentation requirements
  • D. Must successfully pass Background Investigation

Answer: A

 

NEW QUESTION 60
You are the lead auditor of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks.
What is this risk strategy called?

  • A. Risk skipping
  • B. Risk neutral
  • C. Risk bearing
  • D. Risk avoidance

Answer: C

 

NEW QUESTION 61
Which of the following statements are correct for Clean Desk Policy?

  • A. Don't leave valuable items on your desk if you are not in your work area.
  • B. Don't leave laptops without cable lock.
  • C. Don't leave highly confidential items.
  • D. Don't leave confidential documents on your desk.

Answer: A,C,D

 

NEW QUESTION 62
There is a network printer in the hallway of the company where you work. Many employees don't pick up their printouts immediately and leave them on the printer.
What are the consequences of this to the reliability of the information?

  • A. The confidentiality of the information is no longer guaranteed.
  • B. The integrity of the information is no longer guaranteed.
  • C. The Security of the information is no longer guaranteed.
  • D. The availability of the information is no longer guaranteed.

Answer: D

 

NEW QUESTION 63
In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:

  • A. Make the information security incident details known to all employees
  • B. Report suspected or known incidents upon discovery through the Servicedesk
  • C. Cooperate with investigative personnel during investigation if needed
  • D. Preserve evidence if necessary

Answer: A

 

NEW QUESTION 64
Access Control System, CCTV and security guards are form of:

  • A. Compliance
  • B. Environment Security
  • C. Access Control
  • D. Physical Security

Answer: D

 

NEW QUESTION 65
Who is responsible for Initial asset allocation to the user/custodian of the assets?

  • A. Asset Owner
  • B. Asset Stakeholder
  • C. Asset Manager
  • D. Asset Practitioner

Answer: A

 

NEW QUESTION 66
After a devastating office fire, all staff are moved to other branches of the company. At what moment in the incident management process is this measure effectuated?

  • A. Between classification and escalation
  • B. Between recovery and normal operations
  • C. Between detection and classification
  • D. Between incident and damage

Answer: D

 

NEW QUESTION 67
In acceptable use of Information Assets, which is the best practice?

  • A. Playing any computer games during office hours
  • B. Access to information and communication systems are provided for business purpose only
  • C. Interfering with or denying service to any user other than the employee's host
  • D. Accessing phone or network transmissions, including wireless or wifi transmissions

Answer: B

 

NEW QUESTION 68
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself.
You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?

  • A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
  • B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.

Answer: A

 

NEW QUESTION 69
......

PECB ISO-IEC-27001-Lead-Auditor Exam Practice Test Questions: https://www.trainingdump.com/PECB/ISO-IEC-27001-Lead-Auditor-practice-exam-dumps.html

Free ISO-IEC-27001-Lead-Auditor Braindumps Download Updated: https://drive.google.com/open?id=1Bnmoo4TAvobohf8gIPIlgkoTpGXymo4s

0
0
0
0