
Get PECB ISO-IEC-27001-Lead-Implementer Dumps Questions [2022] To Gain Brilliant Result
ISO-IEC-27001-Lead-Implementer dumps - DumpExam - 100% Passing Guarantee
NEW QUESTION 25
What is an example of a security incident?
- A. You cannot set the correct fonts in your word processing software.
- B. The lighting in the department no longer works.
- C. A file is saved under an incorrect name.
- D. A member of staff loses a laptop.
Answer: D
NEW QUESTION 26
You are a consultant and areregularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports.
Which reliability aspect of the information in your reports must you protect?
- A. Confidentiality
- B. Integrity
- C. Availability
Answer: A
NEW QUESTION 27
Which of the following measures is a preventive measure?
- A. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
- B. Putting sensitive information in a safe
- C. Shutting down all internet traffic after a hacker has gained access to thecompany systems
- D. Installing a logging system that enables changes in a system to be recognized
Answer: B
NEW QUESTION 28
What is the most important reason for applying the segregation of duties?
- A. Segregation of duties makes it easier for a person who is readywith his or her part of the work to take time off or to take over the work of another person.
- B. Segregation of duties makes it clear who is responsible for what.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
Answer: C
NEW QUESTION 29
Responsibilities for information security in projects should be defined and allocated to:
- A. the owner of the involved asset
- B. the project manager
- C. the InfoSec officer
- D. specified roles defined in the used project management method of the organization
Answer: D
NEW QUESTION 30
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The recipient, Rachel
- B. The sender, Peter
- C. The person who drafted the insurance terms and conditions
- D. The manager, Linda
Answer: A
NEW QUESTION 31
What is the greatest risk for an organization ifno information security policy has been defined?
- A. Too many measures areimplemented.
- B. It is not possible for an organization to implement information security in a consistent manner.
- C. If everyone works with the same account, it is impossible to find out who worked on what.
- D. Information security activities are carried out by only a few people.
Answer: B
NEW QUESTION 32
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
- B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
- C. A code of conduct is a standard part of a labor contract.
Answer: B
NEW QUESTION 33
What is the best way to comply with legislation and regulations for personal data protection?
- A. Performing a vulnerability analysis
- B. Appointing the responsibility to someone
- C. Maintaining an incident register
- D. Performing a threat analysis
Answer: B
NEW QUESTION 34
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered
- A. True
- B. False
Answer: A
NEW QUESTION 35
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventoryof threats and risks.
What is the relation between a threat, risk and risk analysis?
- A. A riskanalysis is used to remove the risk of a threat.
- B. A risk analysis identifies threats from the known risks.
- C. Risk analyses help to find a balance between threats and risks.
- D. A risk analysis is used to clarify which threats are relevant and what risks they involve.
Answer: D
NEW QUESTION 36
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)
- A. Withdrawal or adaptation of access rights
- B. Restriction of access to information
- C. Return of assets
- D. Management of access rights with special privileges
Answer: A,B,C
NEW QUESTION 37
Of the following, which is the best organization or set of organizations to contribute to compliance?
- A. IT and management
- B. IT and legal
- C. IT,business management, HR and legal
- D. IT only
Answer: C
NEW QUESTION 38
You have juststarted working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct prevents a virus outbreak.
- B. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
- C. A code of conduct is alegal obligation that organizations have to meet.
- D. A code of conduct helps to prevent the misuse of IT facilities.
Answer: D
NEW QUESTION 39
It is allowed that employees and contractors are provided with an anonymous reporting channel to report violations of information security policies or procedures ("whistle blowing")
- A. True
- B. False
Answer: A
NEW QUESTION 40
......
Get 100% Passing Success With True ISO-IEC-27001-Lead-Implementer Exam: https://braindumps2go.dumpexam.com/ISO-IEC-27001-Lead-Implementer-valid-torrent.html
