
[Nov 13, 2021] Download Free PECB ISO-IEC-27001-Lead-Implementer Real Exam Questions
Pass Your Exam With 100% Verified ISO-IEC-27001-Lead-Implementer Exam Questions
NEW QUESTION 29
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of theclients is earlier than the start date. What type of measure could prevent this error?
- A. Organizational measure
- B. Availability measure
- C. Technical measure
- D. Integrity measure
Answer: C
NEW QUESTION 30
Which of these control objectives are NOT in the domain "12.OPERATIONAL SAFETY"?
- A. Technical vulnerability management
- B. Protection against malicious code
- C. Test data
- D. Redundancies
Answer: D
NEW QUESTION 31
What is the objective of classifying information?
- A. Creating alabel that indicates how confidential the information is
- B. Defining different levels of sensitivity into which information may be arranged
- C. Authorizing the use of an information system
- D. Displaying on the document who is permitted access
Answer: B
NEW QUESTION 32
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?
- A. Near Field Communication (NFC)
- B. The 4G protocol
- C. Bluetooth
- D. Radio Frequency Identification (RFID)
Answer: A
NEW QUESTION 33
What is the ISO / IEC 27002 standard?
- A. It is a guide of good practices that describes the controlobjectives and recommended controls regarding information security.
- B. It is a guide for the development and use of applicable metrics and measurement techniques to determine the effectiveness of an ISMS and the controls or groups of controls implemented according to ISO / IEC 27001.
- C. It is a guide that focuses on the critical aspects necessary for the successful design and implementation of an ISMS in accordance with ISO / IEC 27001
Answer: A
NEW QUESTION 34
In the context ofcontact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.
- A. Authentic
- B. Authorization
- C. Confidential
- D. Availability
Answer: C
NEW QUESTION 35
What is the most important reason for applying the segregation of duties?
- A. Segregation of duties makes it clear who is responsible for what.
- B. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties makes it easier for a person who is readywith his or her part of the work to take time off or to take over the work of another person.
Answer: C
NEW QUESTION 36
What is an example of a non-human threat to the physical environment?
- A. Fraudulent transaction
- B. Storm
- C. Corrupted file
- D. Virus
Answer: B
NEW QUESTION 37
Prior to employment, _________ as well as terms & conditions of employment are included as controls in ISO
27002 to ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.
- A. controlling
- B. authorizing
- C. screening
- D. flexing
Answer: C
NEW QUESTION 38
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. The use of tokens to gain access to information systems
- B. Encryption ofinformation
- C. Validation of input and output data in applications
- D. Information Security Management System
Answer: D
NEW QUESTION 39
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the company's staff. Which kind of security measure could have prevented this?
- A. A technical security measure
- B. physical security measure
- C. An organizational security measure
Answer: B
NEW QUESTION 40
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct is a standard part of a labor contract.
- B. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
- C. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
Answer: C
NEW QUESTION 41
Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)
- A. Physical security perimeter
- B. Work in safe areas
- C. Cryptographic Controls Use Policy
- D. Key management
Answer: C,D
NEW QUESTION 42
Who is accountable to classify information assets?
- A. the CEO
- B. the Information Security Team
- C. the CISO
- D. theasset owner
Answer: D
NEW QUESTION 43
You are a consultant and areregularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports.
Which reliability aspect of the information in your reports must you protect?
- A. Confidentiality
- B. Availability
- C. Integrity
Answer: A
NEW QUESTION 44
What is the best description of a risk analysis?
- A. A risk analysis helps to estimate the risks and develop the appropriate security measures.
- B. A risk analysis is a method of mapping risks without looking at company processes.
- C. A risk analysis calculates the exact financial consequences of damages.
Answer: A
NEW QUESTION 45
Responsibilities for information security in projects should be defined and allocated to:
- A. the project manager
- B. the InfoSec officer
- C. the owner of the involved asset
- D. specified roles defined in the used project management method of the organization
Answer: D
NEW QUESTION 46
......
ISO-IEC-27001-Lead-Implementer Dumps 100 Pass Guarantee With Latest Demo: https://www.dumpstorrent.com/ISO-IEC-27001-Lead-Implementer-exam-dumps-torrent.html
ISO-IEC-27001-Lead-Implementer Dumps PDF - ISO-IEC-27001-Lead-Implementer Real Exam Questions Answers: https://drive.google.com/open?id=19dNKgK0qbrNk48PJb68kF_kSUwjS2UyL