
[Nov 23, 2021] ISO-IEC-27001-Lead-Implementer Exam Dumps - Try Best ISO-IEC-27001-Lead-Implementer Exam Questions - ITPassLeader
Verified ISO-IEC-27001-Lead-Implementer exam dumps Q&As with Correct 50 Questions and Answers
NEW QUESTION 25
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
- A. Susan, the sender of the information.
- B. Paul and Susan, the sender and the recipient of the information.
- C. Paul, therecipient of the information.
Answer: C
NEW QUESTION 26
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The recipient, Rachel
- B. The person who drafted the insurance terms and conditions
- C. The sender, Peter
- D. The manager, Linda
Answer: A
NEW QUESTION 27
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the company's staff. Which kind of security measure could have prevented this?
- A. physical security measure
- B. A technical security measure
- C. An organizational security measure
Answer: A
NEW QUESTION 28
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
- A. Availability, Information Value and Confidentiality
- B. Availability, Integrity and Completeness
- C. Availability, Integrity and Confidentiality
- D. Timeliness, Accuracy and Completeness
Answer: C
NEW QUESTION 29
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. Information Security Management System
- B. Encryption ofinformation
- C. The use of tokens to gain access to information systems
- D. Validation of input and output data in applications
Answer: A
NEW QUESTION 30
Which of these reliability aspects is "completeness" a part of?
- A. Confidentiality
- B. Availability
- C. Integrity
- D. Exclusivity
Answer: C
NEW QUESTION 31
What is the best description of a risk analysis?
- A. A risk analysis calculates the exact financial consequences of damages.
- B. A risk analysis is a method of mapping risks without looking at company processes.
- C. A risk analysis helps to estimate the risks and develop the appropriate security measures.
Answer: C
NEW QUESTION 32
Which of these control objectives are NOT in the domain "12.OPERATIONAL SAFETY"?
- A. Protection against malicious code
- B. Redundancies
- C. Technical vulnerability management
- D. Test data
Answer: B
NEW QUESTION 33
Which of the following measures is a preventive measure?
- A. Shutting down all internet traffic after a hacker has gained access to thecompany systems
- B. Putting sensitive information in a safe
- C. Installing a logging system that enables changes in a system to be recognized
- D. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
Answer: B
NEW QUESTION 34
Companies use 27002 for compliance for which of the following reasons:
- A. A structured program that helps with security and compliance
- B. Explicit requirements for all regulations
- C. Compliance with ISO 27002 is sufficient to comply with all regulations
Answer: A
NEW QUESTION 35
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. When the organization is located near a river.
- B. When computer systems are kept in a cellar below ground level.
- C. If the riskanalysis has not been carried out.
- D. When the computer systems are not insured.
Answer: B
NEW QUESTION 36
In the context ofcontact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.
- A. Confidential
- B. Availability
- C. Authentic
- D. Authorization
Answer: A
NEW QUESTION 37
You have juststarted working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct is alegal obligation that organizations have to meet.
- B. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
- C. A code of conduct prevents a virus outbreak.
- D. A code of conduct helps to prevent the misuse of IT facilities.
Answer: D
NEW QUESTION 38
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered
- A. False
- B. True
Answer: B
NEW QUESTION 39
The identified owner of an asset is always an individual
- A. False
- B. True
Answer: A
NEW QUESTION 40
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?
- A. Near Field Communication (NFC)
- B. The 4G protocol
- C. Bluetooth
- D. Radio Frequency Identification (RFID)
Answer: A
NEW QUESTION 41
What is the most important reason for applying the segregation of duties?
- A. Segregation of duties makes it clear who is responsible for what.
- B. Segregation of duties makes it easier for a person who is readywith his or her part of the work to take time off or to take over the work of another person.
- C. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
- D. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
Answer: D
NEW QUESTION 42
Who is accountable to classify information assets?
- A. the CEO
- B. theasset owner
- C. the Information Security Team
- D. the CISO
Answer: B
NEW QUESTION 43
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct is a standard part of a labor contract.
- B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
- C. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
Answer: B
NEW QUESTION 44
What is the greatest risk for an organization ifno information security policy has been defined?
- A. If everyone works with the same account, it is impossible to find out who worked on what.
- B. Information security activities are carried out by only a few people.
- C. It is not possible for an organization to implement information security in a consistent manner.
- D. Too many measures areimplemented.
Answer: C
NEW QUESTION 45
......
PECB ISO-IEC-27001-Lead-Implementer Test Engine PDF - All Free Dumps: https://www.itpassleader.com/PECB/ISO-IEC-27001-Lead-Implementer-dumps-pass-exam.html
Get New ISO-IEC-27001-Lead-Implementer Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1NX5OrT_5WxdYNTJn9Yuf_eCJDARCUXsE