
[Nov-2021] Verified ISO-IEC-27001-Lead-Implementer dumps Q&As - ISO-IEC-27001-Lead-Implementer dumps with Correct Answers
The Best ISO 27001 Study Guide for the ISO-IEC-27001-Lead-Implementer Exam
NEW QUESTION 29
What is the most important reason for applying the segregation of duties?
- A. Segregation of duties makes it clear who is responsible for what.
- B. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties makes it easier for a person who is readywith his or her part of the work to take time off or to take over the work of another person.
Answer: C
NEW QUESTION 30
What is the best description of a risk analysis?
- A. A risk analysis helps to estimate the risks and develop the appropriate security measures.
- B. A risk analysis is a method of mapping risks without looking at company processes.
- C. A risk analysis calculates the exact financial consequences of damages.
Answer: A
NEW QUESTION 31
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct is a standard part of a labor contract.
- B. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
- C. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
Answer: C
NEW QUESTION 32
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered
- A. True
- B. False
Answer: A
NEW QUESTION 33
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?
- A. Near Field Communication (NFC)
- B. The 4G protocol
- C. Bluetooth
- D. Radio Frequency Identification (RFID)
Answer: A
NEW QUESTION 34
Which of the following measures is a correctivemeasure?
- A. Making a backup of the data that has been created or altered that day
- B. Installing a virus scanner in an information system
- C. Incorporating an Intrusion Detection System (IDS) in the design of a computer center
- D. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
Answer: D
NEW QUESTION 35
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.
- A. metadata
- B. teradata
- C. bridge
Answer: A
NEW QUESTION 36
What is an example of a security incident?
- A. You cannot set the correct fonts in your word processing software.
- B. The lighting in the department no longer works.
- C. A file is saved under an incorrect name.
- D. A member of staff loses a laptop.
Answer: D
NEW QUESTION 37
What is the greatest risk for an organization ifno information security policy has been defined?
- A. Too many measures areimplemented.
- B. If everyone works with the same account, it is impossible to find out who worked on what.
- C. It is not possible for an organization to implement information security in a consistent manner.
- D. Information security activities are carried out by only a few people.
Answer: C
NEW QUESTION 38
What is an example of a good physical security measure?
- A. Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.
- B. Printers that are defective or have been replacedare immediately removed and given away as garbage for recycling.
- C. All employees and visitors carry an access pass.
Answer: C
NEW QUESTION 39
Which of these reliability aspects is "completeness" a part of?
- A. Confidentiality
- B. Exclusivity
- C. Availability
- D. Integrity
Answer: D
NEW QUESTION 40
What sort of security does a Public Key Infrastructure (PKI) offer?
- A. Having a PKI shows customers that a web-based business is secure.
- B. It provides digital certificates that can be used to digitally signdocuments. Such signatures irrefutably determine from whom a document was sent.
- C. By providing agreements, procedures and an organization structure, a PKI defines which person or which system belongs to which specific public key.
- D. A PKI ensures that backups of company data are made on a regular basis.
Answer: D
NEW QUESTION 41
What is the best way to comply with legislation and regulations for personal data protection?
- A. Maintaining an incident register
- B. Appointing the responsibility to someone
- C. Performing a vulnerability analysis
- D. Performing a threat analysis
Answer: B
NEW QUESTION 42
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)
- A. Return of assets
- B. Withdrawal or adaptation of access rights
- C. Restriction of access to information
- D. Management of access rights with special privileges
Answer: A,B,C
NEW QUESTION 43
Which of the following measures is a preventive measure?
- A. Putting sensitive information in a safe
- B. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
- C. Installing a logging system that enables changes in a system to be recognized
- D. Shutting down all internet traffic after a hacker has gained access to thecompany systems
Answer: A
NEW QUESTION 44
You have juststarted working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct helps to prevent the misuse of IT facilities.
- B. A code of conduct prevents a virus outbreak.
- C. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
- D. A code of conduct is alegal obligation that organizations have to meet.
Answer: A
NEW QUESTION 45
Responsibilities for information security in projects should be defined and allocated to:
- A. the project manager
- B. the InfoSec officer
- C. the owner of the involved asset
- D. specified roles defined in the used project management method of the organization
Answer: D
NEW QUESTION 46
Why is compliance important forthe reliability of the information?
- A. By meeting the legislative requirements and theregulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
- B. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- C. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and thereforeit guarantees the reliability of its information.
Answer: A
NEW QUESTION 47
......
ISO-IEC-27001-Lead-Implementer certification guide Q&A from Training Expert Actual4dump: https://www.actual4dump.com/PECB/ISO-IEC-27001-Lead-Implementer-actualtests-dumps.html
ISO-IEC-27001-Lead-Implementer Certification Overview Latest ISO-IEC-27001-Lead-Implementer PDF Dumps: https://drive.google.com/open?id=1XLss6eElvhQXtrL_jpwimCZLkfYvRiLa