Prepare For Realistic ISO-IEC-27001-Lead-Implementer Dumps PDF - 100% Passing Guarantee [Q13-Q36]

Share

Prepare For Realistic ISO-IEC-27001-Lead-Implementer Dumps PDF - 100% Passing Guarantee

Check the Available ISO-IEC-27001-Lead-Implementer Exam Dumps with 50 Q's


PECB ISO-IEC-27001-Lead-Implementer Exam Syllabus Topics:

TopicDetails
Topic 1
  • Monitoring and measurement and Continual improvement of an ISMS based on ISO
  • IEC 27001
  • Interpret the ISO
  • IEC 27001 requirements for an ISMS from the perspective of an implementer
Topic 2
  • Prepare an organization to undergo a third-party certification audit
  • Fundamental principles and concepts of an information security management system (ISMS)
Topic 3
  • Interpret the ISO
  • IEC 27001 requirements for an ISMS from the perspective of an implementer
  • Information security management system (ISMS)

 

NEW QUESTION 13
Companies use 27002 for compliance for which of the following reasons:

  • A. A structured program that helps with security and compliance
  • B. Compliance with ISO 27002 is sufficient to comply with all regulations
  • C. Explicit requirements for all regulations

Answer: A

 

NEW QUESTION 14
What are the data protection principles set out in the GDPR?

  • A. Purpose limitation, pudicity, transparency, data minimisation
  • B. Target group, proportionality, transparency, data minimisation
  • C. Purpose limitation, proportionality, data minimisation, transparency
  • D. Purpose limitation, proportionality, availability, data minimisation

Answer: C

 

NEW QUESTION 15
Who is accountable to classify information assets?

  • A. the CISO
  • B. the Information Security Team
  • C. theasset owner
  • D. the CEO

Answer: C

 

NEW QUESTION 16
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

  • A. Risk neutral
  • B. Risk passing
  • C. Risk avoiding
  • D. Risk bearing

Answer: A

 

NEW QUESTION 17
What should be used to protect data on removable media ifdata confidentiality or integrity are important considerations?

  • A. backup on another removable medium
  • B. logging
  • C. a password
  • D. cryptographic techniques

Answer: D

 

NEW QUESTION 18
In the context ofcontact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.

  • A. Confidential
  • B. Availability
  • C. Authorization
  • D. Authentic

Answer: A

 

NEW QUESTION 19
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of theclients is earlier than the start date. What type of measure could prevent this error?

  • A. Organizational measure
  • B. Integrity measure
  • C. Technical measure
  • D. Availability measure

Answer: C

 

NEW QUESTION 20
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 21
What is the objective of classifying information?

  • A. Defining different levels of sensitivity into which information may be arranged
  • B. Displaying on the document who is permitted access
  • C. Authorizing the use of an information system
  • D. Creating alabel that indicates how confidential the information is

Answer: A

 

NEW QUESTION 22
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

  • A. The first step consists of comparing the password with the registered password.
  • B. The first step consists of granting access to the information to which the user is authorized.
  • C. The first step consists of checking if the user appears on the list of authorized users.
  • D. Thefirst step consists of checking if the user is using the correct certificate.

Answer: C

 

NEW QUESTION 23
Which of these control objectives are NOT in the domain "12.OPERATIONAL SAFETY"?

  • A. Redundancies
  • B. Technical vulnerability management
  • C. Test data
  • D. Protection against malicious code

Answer: A

 

NEW QUESTION 24
What is the most important reason for applying the segregation of duties?

  • A. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
  • B. Segregation of duties makes it easier for a person who is readywith his or her part of the work to take time off or to take over the work of another person.
  • C. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
  • D. Segregation of duties makes it clear who is responsible for what.

Answer: A

 

NEW QUESTION 25
Who is authorized to change the classification of a document?

  • A. The owner of the document
  • B. The administrator of the document
  • C. The author of the document
  • D. The manager of the owner of the document

Answer: A

 

NEW QUESTION 26
What is the ISO / IEC 27002 standard?

  • A. It is a guide that focuses on the critical aspects necessary for the successful design and implementation of an ISMS in accordance with ISO / IEC 27001
  • B. It is a guide for the development and use of applicable metrics and measurement techniques to determine the effectiveness of an ISMS and the controls or groups of controls implemented according to ISO / IEC 27001.
  • C. It is a guide of good practices that describes the controlobjectives and recommended controls regarding information security.

Answer: C

 

NEW QUESTION 27
What is an example of a good physical security measure?

  • A. All employees and visitors carry an access pass.
  • B. Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.
  • C. Printers that are defective or have been replacedare immediately removed and given away as garbage for recycling.

Answer: A

 

NEW QUESTION 28
What is an example of a non-human threat to the physical environment?

  • A. Corrupted file
  • B. Fraudulent transaction
  • C. Storm
  • D. Virus

Answer: C

 

NEW QUESTION 29
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)

  • A. Restriction of access to information
  • B. Withdrawal or adaptation of access rights
  • C. Return of assets
  • D. Management of access rights with special privileges

Answer: A,B,C

 

NEW QUESTION 30
What is the best description of a risk analysis?

  • A. A risk analysis helps to estimate the risks and develop the appropriate security measures.
  • B. A risk analysis calculates the exact financial consequences of damages.
  • C. A risk analysis is a method of mapping risks without looking at company processes.

Answer: A

 

NEW QUESTION 31
Responsibilities for information security in projects should be defined and allocated to:

  • A. the owner of the involved asset
  • B. the project manager
  • C. the InfoSec officer
  • D. specified roles defined in the used project management method of the organization

Answer: D

 

NEW QUESTION 32
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?

  • A. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
  • B. The costs for automating are easier to charge to the responsible departments.
  • C. Reports can be developed more easily and with fewer errors.
  • D. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.

Answer: D

 

NEW QUESTION 33
......

Download ISO-IEC-27001-Lead-Implementer Exam Dumps Questions to get 100% Success: https://www.briandumpsprep.com/ISO-IEC-27001-Lead-Implementer-prep-exam-braindumps.html

100% Accurate Answers! ISO-IEC-27001-Lead-Implementer Actual Real Exam Questions: https://drive.google.com/open?id=1Ha3sSelb1Hk1hTbeVO3DnM5xgiCnzipv