
[Oct 24, 2021] Fully Updated ISO-IEC-27001-Lead-Auditor Dumps - 100% Same Q&A In Your Real Exam
Latest ISO-IEC-27001-Lead-Auditor Exam Dumps - Valid and Updated Dumps
NEW QUESTION 17
A fire breaks out in a branch office of a health insurance company. The personnel are transferred to neighboring branches to continue their work.
Where in the incident cycle is moving to a stand-by arrangements found?
- A. between incident and damage
- B. between threat and incident
- C. between recovery and threat
- D. between damage and recovery
Answer: A
NEW QUESTION 18
What is the security management term for establishing whether someone's identity is correct?
- A. Verification
- B. Authorisation
- C. Identification
- D. Authentication
Answer: D
NEW QUESTION 19
In what part of the process to grant access to a system does the user present a token?
- A. Authentication
- B. Identification
- C. Verification
- D. Authorisation
Answer: B
NEW QUESTION 20
Which of the following is not a type of Information Security attack?
- A. Privacy Incidents
- B. Vehicular Incidents
- C. Legal Incidents
- D. Technical Vulnerabilities
Answer: B
NEW QUESTION 21
Which of the following is an information security management system standard published by the International Organization for Standardization?
- A. ISO27001
- B. ISO5501
- C. ISO22301
- D. ISO9008
Answer: A
NEW QUESTION 22
What is social engineering?
- A. The organization planning an activity for welfare of the neighborhood
- B. A group planning for a social activity in the organization
- C. Creating a situation wherein a third party gains confidential information from you
Answer: C
NEW QUESTION 23
A member of staff denies sending a particular message.
Which reliability aspect of information is in danger here?
- A. confidentiality
- B. correctness
- C. integrity
- D. availability
Answer: C
NEW QUESTION 24
In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:
- A. Make the information security incident details known to all employees
- B. Report suspected or known incidents upon discovery through the Servicedesk
- C. Cooperate with investigative personnel during investigation if needed
- D. Preserve evidence if necessary
Answer: A
NEW QUESTION 25
What is the purpose of an Information Security policy?
- A. An information security policy provides direction and support to the management regarding information security
- B. An information security policy provides insight into threats and the possible consequences
- C. An information security policy makes the security plan concrete by providing the necessary details
- D. An information security policy documents the analysis of risks and the search for countermeasures
Answer: A
NEW QUESTION 26
Which department maintain's contacts with law enforcement authorities, regulatory bodies, information service providers and telecommunications service providers depending on the service required.
- A. MRO
- B. CSM
- C. CISO
- D. COO
Answer: C
NEW QUESTION 27
Which of the following does an Asset Register contain? (Choose two)
- A. Asset Modifier
- B. Asset Owner
- C. Process ID
- D. Asset Type
Answer: B,D
NEW QUESTION 28
Stages of Information
- A. creation, distribution, use, maintenance, disposition
- B. creation, distribution, maintenance, disposition, use
- C. creation, evolution, maintenance, use, disposition
- D. creation, use, disposition, maintenance, evolution
Answer: A
NEW QUESTION 29
Which measure is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Shutting down all internet traffic after a hacker has gained access to the company systems
Answer: A
NEW QUESTION 30
Which is the glue that ties the triad together
- A. Process
- B. Collaboration
- C. Technology
- D. People
Answer: A
NEW QUESTION 31
An employee caught with offense of abusing the internet, such as P2P file sharing or video/audio streaming, will not receive a warning for committing such act but will directly receive an IR.
- A. False
- B. True
Answer: B
NEW QUESTION 32
The following are purposes of Information Security, except:
- A. Minimize Business Risk
- B. Increase Business Assets
- C. Maximize Return on Investment
- D. Ensure Business Continuity
Answer: B
NEW QUESTION 33
What type of compliancy standard, regulation or legislation provides a code of practice for information security?
- A. Personal data protection act
- B. ISO/IEC 27002
- C. IT Service Management
- D. Computer criminality act
Answer: B
NEW QUESTION 34
Which of the following is a technical security measure?
- A. Safe storage of backups
- B. User role profiles.
- C. Security policy
- D. Encryption
Answer: D
NEW QUESTION 35
What type of legislation requires a proper controlled purchase process?
- A. Government information act
- B. Intellectual property rights act
- C. Personal data protection act
- D. Computer criminality act
Answer: B
NEW QUESTION 36
Availability means
- A. Service should not be accessible when required
- B. Service should be accessible at the required time and usable only by the authorized entity
- C. Service should be accessible at the required time and usable by all
Answer: B
NEW QUESTION 37
Which reliability aspect of information is compromised when a staff member denies having sent a message?
- A. Confidentiality
- B. Correctness
- C. Availability
- D. Integrity
Answer: D
NEW QUESTION 38
After a devastating office fire, all staff are moved to other branches of the company. At what moment in the incident management process is this measure effectuated?
- A. Between classification and escalation
- B. Between recovery and normal operations
- C. Between detection and classification
- D. Between incident and damage
Answer: D
NEW QUESTION 39
The following are definitions of Information, except:
- A. accurate and timely data
- B. can lead to understanding and decrease in uncertainty
- C. specific and organized data for a purpose
- D. mature and measurable data
Answer: D
NEW QUESTION 40
You see a blue color sticker on certain physical assets. What does this signify?
- A. The asset is critical and the impact is restricted to an employee only
- B. The asset with blue stickers should be kept air conditioned at all times
- C. The asset is high critical and its failure will affect a group/s/project's work in the organization
- D. The asset is very high critical and its failure affects the entire organization
Answer: C
NEW QUESTION 41
Someone from a large tech company calls you on behalf of your company to check the health of your PC, and therefore needs your user-id and password. What type of threat is this?
- A. Social engineering threat
- B. Malware threat
- C. Technical threat
- D. Organisational threat
Answer: A
NEW QUESTION 42
......
Free Sales Ending Soon - 100% Valid ISO-IEC-27001-Lead-Auditor Exam: https://www.testvalid.com/ISO-IEC-27001-Lead-Auditor-exam-collection.html
Verified ISO-IEC-27001-Lead-Auditor Exam Questions Certain Success: https://drive.google.com/open?id=1LJ4K8K9Hk_Akb6Fb683k52saD8styjgl