
ISO-IEC-27001-Lead-Implementer 100% Guarantee Download ISO-IEC-27001-Lead-Implementer Exam PDF Q&A [Sep 15, 2022]
Get ISO-IEC-27001-Lead-Implementer Actual Free Exam Q&As to Prepare for Your PECB Certification
NEW QUESTION 25
Companies use 27002 for compliance for which of the following reasons:
- A. Explicit requirements for all regulations
- B. A structured program that helps with security and compliance
- C. Compliance with ISO 27002 is sufficient to comply with all regulations
Answer: B
NEW QUESTION 26
What sort of security does a Public Key Infrastructure (PKI) offer?
- A. A PKI ensures that backups of company data are made on a regular basis.
- B. By providing agreements, procedures and an organization structure, a PKI defines which person or which system belongs to which specific public key.
- C. It provides digital certificates that can be used to digitally signdocuments. Such signatures irrefutably determine from whom a document was sent.
- D. Having a PKI shows customers that a web-based business is secure.
Answer: A
NEW QUESTION 27
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The recipient, Rachel
- B. The person who drafted the insurance terms and conditions
- C. The sender, Peter
- D. The manager, Linda
Answer: A
NEW QUESTION 28
What is an example of a security incident?
- A. The lighting in the department no longer works.
- B. A member of staff loses a laptop.
- C. A file is saved under an incorrect name.
- D. You cannot set the correct fonts in your word processing software.
Answer: B
NEW QUESTION 29
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?
- A. The first step consists of checking if the user appears on the list of authorized users.
- B. Thefirst step consists of checking if the user is using the correct certificate.
- C. The first step consists of comparing the password with the registered password.
- D. The first step consists of granting access to the information to which the user is authorized.
Answer: A
NEW QUESTION 30
The identified owner of an asset is always an individual
- A. False
- B. True
Answer: A
NEW QUESTION 31
You have juststarted working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct helps to prevent the misuse of IT facilities.
- B. A code of conduct prevents a virus outbreak.
- C. A code of conduct is alegal obligation that organizations have to meet.
- D. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
Answer: A
NEW QUESTION 32
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
- A. Susan, the sender of the information.
- B. Paul and Susan, the sender and the recipient of the information.
- C. Paul, therecipient of the information.
Answer: C
NEW QUESTION 33
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of theclients is earlier than the start date. What type of measure could prevent this error?
- A. Integrity measure
- B. Availability measure
- C. Organizational measure
- D. Technical measure
Answer: D
NEW QUESTION 34
Of the following, which is the best organization or set of organizations to contribute to compliance?
- A. IT,business management, HR and legal
- B. IT and legal
- C. IT only
- D. IT and management
Answer: A
NEW QUESTION 35
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk neutral
- B. Risk passing
- C. Risk bearing
- D. Risk avoiding
Answer: A
NEW QUESTION 36
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. When the organization is located near a river.
- B. When the computer systems are not insured.
- C. If the riskanalysis has not been carried out.
- D. When computer systems are kept in a cellar below ground level.
Answer: D
NEW QUESTION 37
Why is compliance important forthe reliability of the information?
- A. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- B. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and thereforeit guarantees the reliability of its information.
- C. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- D. By meeting the legislative requirements and theregulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
Answer: D
NEW QUESTION 38
Which of the following measures is a preventive measure?
- A. Installing a logging system that enables changes in a system to be recognized
- B. Putting sensitive information in a safe
- C. Shutting down all internet traffic after a hacker has gained access to thecompany systems
- D. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
Answer: B
NEW QUESTION 39
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.
- A. teradata
- B. bridge
- C. metadata
Answer: C
NEW QUESTION 40
In the context ofcontact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.
- A. Authentic
- B. Confidential
- C. Authorization
- D. Availability
Answer: B
NEW QUESTION 41
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. Encryption ofinformation
- B. Information Security Management System
- C. Validation of input and output data in applications
- D. The use of tokens to gain access to information systems
Answer: B
NEW QUESTION 42
What is the ISO / IEC 27002 standard?
- A. It is a guide of good practices that describes the controlobjectives and recommended controls regarding information security.
- B. It is a guide that focuses on the critical aspects necessary for the successful design and implementation of an ISMS in accordance with ISO / IEC 27001
- C. It is a guide for the development and use of applicable metrics and measurement techniques to determine the effectiveness of an ISMS and the controls or groups of controls implemented according to ISO / IEC 27001.
Answer: A
NEW QUESTION 43
ISO 27002 provides guidance in the following area
- A. Framework for an overall security andcompliance program
- B. Information handling recommendations
- C. PCI environment scoping
- D. Detailed lists of required policies and procedures
Answer: A
NEW QUESTION 44
How many domains does ISO / IEC 27002: 2013 have?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: A
NEW QUESTION 45
......
ISO-IEC-27001-Lead-Implementer Questions Truly Valid For Your PECB Exam: https://prep4sure.vce4dumps.com/ISO-IEC-27001-Lead-Implementer-latest-dumps.html