ISO-IEC-27001-Lead-Auditor Practice Exam and Study Guides - Verified By ActualTorrent Updated 99 Questions [Q47-Q69]

Share

ISO-IEC-27001-Lead-Auditor Practice Exam and Study Guides - Verified By ActualTorrent Updated 99 Questions

2021 Updated Verified Pass ISO-IEC-27001-Lead-Auditor Study Guides & Best Courses

NEW QUESTION 47
Which department maintain's contacts with law enforcement authorities, regulatory bodies, information service providers and telecommunications service providers depending on the service required.

  • A. MRO
  • B. COO
  • C. CISO
  • D. CSM

Answer: C

 

NEW QUESTION 48
Why do we need to test a disaster recovery plan regularly, and keep it up to date?

  • A. Otherwise remotely stored backups may no longer be available to the security team
  • B. Otherwise the measures taken and the incident procedures planned may not be adequate
  • C. Otherwise it is no longer up to date with the registration of daily occurring faults

Answer: B

 

NEW QUESTION 49
What is the relationship between data and information?

  • A. Information is the meaning and value assigned to a collection of data.
  • B. Data is structured information.

Answer: A

 

NEW QUESTION 50
Cabling Security is associated with Power, telecommunication and network cabling carrying information are protected from interception and damage.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 51
What is the name of the system that guarantees the coherence of information security in the organization?

  • A. Information Security Management System (ISMS)
  • B. Rootkit
  • C. Information Technology Service Management (ITSM)
  • D. Security regulations for special information for the government

Answer: A

 

NEW QUESTION 52
Which is not a requirement of HR prior to hiring?

  • A. Undergo background verification
  • B. Must undergo Awareness training on information security.
  • C. Applicant must complete pre-employment documentation requirements
  • D. Must successfully pass Background Investigation

Answer: B

 

NEW QUESTION 53
Changes on project-managed applications or database should undergo the change control process as documented.

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 54
Which of the following is a possible event that can have a disruptive effect on the reliability of information?

  • A. Dependency
  • B. Threat
  • C. Vulnerability
  • D. Risk

Answer: B

 

NEW QUESTION 55
A property of Information that has the ability to prove occurrence of a claimed event.

  • A. Accessibility
  • B. Availability
  • C. Electronic chain letters
  • D. Integrity

Answer: D

 

NEW QUESTION 56
What is the standard definition of ISMS?

  • A. A project-based approach to achieve business objectives for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security
  • B. Is an information security systematic approach to achieve business objectives for implementation, establishing, reviewing,operating and maintaining organization's reputation.
  • C. A systematic approach for establishing, implementing, operating,monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives.
  • D. A company wide business objectives to achieve information security awareness for establishing, implementing, operating, monitoring, reviewing, maintaining and improving

Answer: C

 

NEW QUESTION 57
In acceptable use of Information Assets, which is the best practice?

  • A. Playing any computer games during office hours
  • B. Access to information and communication systems are provided for business purpose only
  • C. Interfering with or denying service to any user other than the employee's host
  • D. Accessing phone or network transmissions, including wireless or wifi transmissions

Answer: B

 

NEW QUESTION 58
A planning process that introduced the concept of planning as a cycle that forms the basis for continuous improvement is called:

  • A. plan, do, check, act.
  • B. planning for continuous improvement.
  • C. RACI Matrix
  • D. time based planning.

Answer: A

 

NEW QUESTION 59
What is a reason for the classification of information?

  • A. To structure the information according to its sensitivity
  • B. Creating a manual describing the BYOD policy
  • C. To provide clear identification tags

Answer: A

 

NEW QUESTION 60
What is the goal of classification of information?

  • A. Structuring information according to its sensitivity
  • B. To create a manual about how to handle mobile devices
  • C. Applying labels making the information easier to recognize

Answer: A

 

NEW QUESTION 61
A well-executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives.
What is not one of the four main objectives of a risk analysis?

  • A. Establishing a balance between the costs of an incident and the costs of a security measure
  • B. Implementing counter measures
  • C. Identifying assets and their value
  • D. Determining relevant vulnerabilities and threats

Answer: B

 

NEW QUESTION 62
How is the purpose of information security policy best described?

  • A. An information security policy documents the analysis of risks and the search for countermeasures.
  • B. An information security policy provides insight into threats and the possible consequences.
  • C. An information security policy provides direction and support to the management regarding information security.
  • D. An information security policy makes the security plan concrete by providing it with the necessary details.

Answer: C

 

NEW QUESTION 63
Does the security have the right to ask you to display your ID badges and check your bags?

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 64
Four types of Data Classification (Choose two)

  • A. Restricted Data, Confidential Data
  • B. Unrestricted Data, Highly Confidential Data
  • C. Project Data, Highly Confidential Data
  • D. Financial Data, Highly Confidential Data

Answer: A,B

 

NEW QUESTION 65
Which measure is a preventive measure?

  • A. Putting sensitive information in a safe
  • B. Installing a logging system that enables changes in a system to be recognized
  • C. Shutting down all internet traffic after a hacker has gained access to the company systems

Answer: A

 

NEW QUESTION 66
Information or data that are classified as ______ do not require labeling.

  • A. Highly Confidential
  • B. Internal
  • C. Confidential
  • D. Public

Answer: D

 

NEW QUESTION 67
Stages of Information

  • A. creation, distribution, maintenance, disposition, use
  • B. creation, use, disposition, maintenance, evolution
  • C. creation, distribution, use, maintenance, disposition
  • D. creation, evolution, maintenance, use, disposition

Answer: C

 

NEW QUESTION 68
Who is authorized to change the classification of a document?

  • A. The manager of the owner of the document
  • B. The administrator of the document
  • C. The author of the document
  • D. The owner of the document

Answer: D

 

NEW QUESTION 69
......

Ultimate Guide to the ISO-IEC-27001-Lead-Auditor - Latest Edition Available Now: https://www.actualtorrent.com/ISO-IEC-27001-Lead-Auditor-questions-answers.html

2021 Updated Verified Pass ISO-IEC-27001-Lead-Auditor Exam - Real Questions & Answers: https://drive.google.com/open?id=1DMr-E760OI84b5uRuQVf9qR-jwG0zw0I