
[Apr 16, 2023] ISO-IEC-27001-Lead-Auditor PDF Recently Updated Questions Dumps to Improve Exam Score
ISO-IEC-27001-Lead-Auditor Dumps Full Questions with Free PDF Questions to Pass
PECB ISO-IEC-27001-Lead-Auditor Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
NEW QUESTION 24
Backup media is kept in the same secure area as the servers. What risk may the organisation be exposed to?
- A. Unauthorised persons will have access to both the servers and backups
- B. After a fire, the information systems cannot be restored
- C. Responsibility for the backups is not defined well
- D. After a server crash, it will take extra time to bring it back up again
Answer: B
NEW QUESTION 25
What is an example of a human threat?
- A. fire
- B. a lightning strike
- C. phishing
- D. thunderstrom
Answer: C
NEW QUESTION 26
In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:
- A. Cooperate with investigative personnel during investigation if needed
- B. Preserve evidence if necessary
- C. Make the information security incident details known to all employees
- D. Report suspected or known incidents upon discovery through the Servicedesk
Answer: C
NEW QUESTION 27
Four types of Data Classification (Choose two)
- A. Project Data, Highly Confidential Data
- B. Restricted Data, Confidential Data
- C. Financial Data, Highly Confidential Data
- D. Unrestricted Data, Highly Confidential Data
Answer: B,D
NEW QUESTION 28
Integrity of data means
- A. Data should be viewable at all times
- B. Accuracy and completeness of the data
- C. Data should be accessed by only the right people
Answer: B
NEW QUESTION 29
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself.
You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
NEW QUESTION 30
In order to take out a fire insurance policy, an administration office must determine the value of the data that it manages.
Which factor is [b]not[/b] important for determining the value of data for an organization?
- A. The content of data.
- B. The degree to which missing, incomplete or incorrect data can be recovered.
- C. The indispensability of data for the business processes.
- D. The importance of the business processes that make use of the data.
Answer: A
NEW QUESTION 31
__________ is a software used or created by hackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems.
- A. Malware
- B. Operating System
- C. Trojan
- D. Virus
Answer: A
NEW QUESTION 32
A planning process that introduced the concept of planning as a cycle that forms the basis for continuous improvement is called:
- A. planning for continuous improvement.
- B. RACI Matrix
- C. plan, do, check, act.
- D. time based planning.
Answer: C
NEW QUESTION 33
You receive an E-mail from some unknown person claiming to be representative of your bank and asking for your account number and password so that they can fix your account. Such an attempt of social engineering is called
- A. Shoulder Surfing
- B. Mountaineering
- C. Spoofing
- D. Phishing
Answer: D
NEW QUESTION 34
There is a scheduled fire drill in your facility. What should you do?
- A. Participate in the drill
- B. None of the above
- C. Call in sick
- D. Excuse yourself by saying you have an urgent deliverable
Answer: A
NEW QUESTION 35
Which reliability aspect of information is compromised when a staff member denies having sent a message?
- A. Correctness
- B. Integrity
- C. Availability
- D. Confidentiality
Answer: B
NEW QUESTION 36
Changes on project-managed applications or database should undergo the change control process as documented.
- A. True
- B. False
Answer: A
NEW QUESTION 37
CEO sends a mail giving his views on the status of the company and the company's future strategy and the CEO's vision and the employee's part in it. The mail should be classified as
- A. Restricted Mail
- B. Confidential Mail
- C. Public Mail
- D. Internal Mail
Answer: D
NEW QUESTION 38
What is the difference between a restricted and confidential document?
- A. Restricted - to be shared among named individuals
Confidential - to be shared with friends and family - B. Restricted - to be shared among an authorized group
Confidential - to be shared among named individuals - C. Restricted - to be shared among named individuals
Confidential - to be shared among an authorized group - D. Restricted - to be shared among named individuals
Confidential - to be shared across the organization only
Answer: C
NEW QUESTION 39
What would be the reference for you to know who should have access to data/document?
- A. Data Classification Label
- B. Information Rights Management (IRM)
- C. Masterlist of Project Records (MLPR)
- D. Access Control List (ACL)
Answer: D
NEW QUESTION 40
What is the goal of classification of information?
- A. To create a manual about how to handle mobile devices
- B. Applying labels making the information easier to recognize
- C. Structuring information according to its sensitivity
Answer: C
NEW QUESTION 41
Access Control System, CCTV and security guards are form of:
- A. Access Control
- B. Environment Security
- C. Physical Security
- D. Compliance
Answer: C
NEW QUESTION 42
What is social engineering?
- A. Creating a situation wherein a third party gains confidential information from you
- B. A group planning for a social activity in the organization
- C. The organization planning an activity for welfare of the neighborhood
Answer: A
NEW QUESTION 43
Below is Purpose of "Integrity", which is one of the Basic Components of Information Security
- A. the property that information is not made available or disclosed to unauthorized individuals
- B. the property that information is not made available or disclosed to unauthorized individuals
- C. the property of safeguarding the accuracy and completeness of assets.
- D. the property of being accessible and usable upon demand by an authorized entity.
Answer: C
NEW QUESTION 44
As a new member of the IT department you have noticed that confidential information has been leaked several times. This may damage the reputation of the company. You have been asked to propose an organisational measure to protect laptop computers. What is the first step in a structured approach to come up with this measure?
- A. Encrypt all sensitive information
- B. Formulate a policy
- C. Set up an access control procedure
- D. Appoint security staff
Answer: B
NEW QUESTION 45
All are prohibited in acceptable use of information assets, except:
- A. E-mail copies to non-essential readers
- B. Electronic chain letters
- C. Company-wide e-mails with supervisor/TL permission.
- D. Messages with very large attachments or to a large number ofrecipients.
Answer: C
NEW QUESTION 46
Information Security is a matter of building and maintaining ________ .
- A. Trust
- B. Firewalls
- C. Confidentiality
- D. Protection
Answer: A
NEW QUESTION 47
Which of the following statements are correct for Clean Desk Policy?
- A. Don't leave laptops without cable lock.
- B. Don't leave confidential documents on your desk.
- C. Don't leave valuable items on your desk if you are not in your work area.
- D. Don't leave highly confidential items.
Answer: B,C,D
NEW QUESTION 48
Cabling Security is associated with Power, telecommunication and network cabling carrying information are protected from interception and damage.
- A. True
- B. False
Answer: A
NEW QUESTION 49
......
100% Updated PECB ISO-IEC-27001-Lead-Auditor Enterprise PDF Dumps: https://freedumps.actual4exams.com/ISO-IEC-27001-Lead-Auditor-real-braindumps.html