100% Free Real Updated ISO-IEC-27001-Lead-Auditor Questions & Answers Pass Your Exam Easily [Q10-Q34]

Share

100% Free Real Updated ISO-IEC-27001-Lead-Auditor Questions & Answers Pass Your Exam Easily

Easily To Pass New ISO-IEC-27001-Lead-Auditor Verified & Correct Answers

NEW QUESTION 10
Which is not a requirement of HR prior to hiring?

  • A. Must successfully pass Background Investigation
  • B. Undergo background verification
  • C. Must undergo Awareness training on information security.
  • D. Applicant must complete pre-employment documentation requirements

Answer: C

 

NEW QUESTION 11
In what part of the process to grant access to a system does the user present a token?

  • A. Authorisation
  • B. Verification
  • C. Authentication
  • D. Identification

Answer: D

 

NEW QUESTION 12
Who is authorized to change the classification of a document?

  • A. The manager of the owner of the document
  • B. The owner of the document
  • C. The author of the document
  • D. The administrator of the document

Answer: B

 

NEW QUESTION 13
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself.
You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?

  • A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
  • B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.

Answer: A

 

NEW QUESTION 14
After a devastating office fire, all staff are moved to other branches of the company. At what moment in the incident management process is this measure effectuated?

  • A. Between incident and damage
  • B. Between classification and escalation
  • C. Between detection and classification
  • D. Between recovery and normal operations

Answer: A

 

NEW QUESTION 15
Which of the following statements are correct for Clean Desk Policy?

  • A. Don't leave laptops without cable lock.
  • B. Don't leave valuable items on your desk if you are not in your work area.
  • C. Don't leave highly confidential items.
  • D. Don't leave confidential documents on your desk.

Answer: B,C,D

 

NEW QUESTION 16
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good.
What is an example of the indirect damage caused by this fire?

  • A. Melted backup tapes
  • B. Burned documents
  • C. Water damage due to the fire extinguishers
  • D. Burned computer systems

Answer: C

 

NEW QUESTION 17
Changes to the information processing facilities shall be done in controlled manner.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 18
What type of system ensures a coherent Information Security organisation?

  • A. Information Exchange Data System (IEDS)
  • B. Federal Information Security Management Act (FISMA)
  • C. Information Security Management System (ISMS)
  • D. Information Technology Service Management System (ITSM)

Answer: C

 

NEW QUESTION 19
A hacker gains access to a webserver and can view a file on the server containing credit card numbers.
Which of the Confidentiality, Integrity, Availability (CIA) principles of the credit card file are violated?

  • A. Confidentiality
  • B. Compliance
  • C. Integrity
  • D. Availability

Answer: A

 

NEW QUESTION 20
Someone from a large tech company calls you on behalf of your company to check the health of your PC, and therefore needs your user-id and password. What type of threat is this?

  • A. Technical threat
  • B. Malware threat
  • C. Organisational threat
  • D. Social engineering threat

Answer: D

 

NEW QUESTION 21
Which reliability aspect of information is compromised when a staff member denies having sent a message?

  • A. Integrity
  • B. Availability
  • C. Correctness
  • D. Confidentiality

Answer: A

 

NEW QUESTION 22
Which of the following is not a type of Information Security attack?

  • A. Legal Incidents
  • B. Vehicular Incidents
  • C. Technical Vulnerabilities
  • D. Privacy Incidents

Answer: B

 

NEW QUESTION 23
Which measure is a preventive measure?

  • A. Putting sensitive information in a safe
  • B. Installing a logging system that enables changes in a system to be recognized
  • C. Shutting down all internet traffic after a hacker has gained access to the company systems

Answer: A

 

NEW QUESTION 24
You see a blue color sticker on certain physical assets. What does this signify?

  • A. The asset is high critical and its failure will affect a group/s/project's work in the organization
  • B. The asset is very high critical and its failure affects the entire organization
  • C. The asset with blue stickers should be kept air conditioned at all times
  • D. The asset is critical and the impact is restricted to an employee only

Answer: A

 

NEW QUESTION 25
Which department maintain's contacts with law enforcement authorities, regulatory bodies, information service providers and telecommunications service providers depending on the service required.

  • A. CSM
  • B. COO
  • C. MRO
  • D. CISO

Answer: D

 

NEW QUESTION 26
An administration office is going to determine the dangers to which it is exposed.
What do we call a possible event that can have a disruptive effect on the reliability of information?

  • A. risk
  • B. dependency
  • C. vulnerability
  • D. threat

Answer: D

 

NEW QUESTION 27
-------------------------is an asset like other important business assets has value to an organization and consequently needs to be protected.

  • A. Information
  • B. Security
  • C. Data
  • D. Infrastructure

Answer: A

 

NEW QUESTION 28
What type of compliancy standard, regulation or legislation provides a code of practice for information security?

  • A. IT Service Management
  • B. ISO/IEC 27002
  • C. Computer criminality act
  • D. Personal data protection act

Answer: B

 

NEW QUESTION 29
In acceptable use of Information Assets, which is the best practice?

  • A. Accessing phone or network transmissions, including wireless or wifi transmissions
  • B. Access to information and communication systems are provided for business purpose only
  • C. Playing any computer games during office hours
  • D. Interfering with or denying service to any user other than the employee's host

Answer: B

 

NEW QUESTION 30
Changes on project-managed applications or database should undergo the change control process as documented.

  • A. False
  • B. True

Answer: B

 

NEW QUESTION 31
What is the worst possible action that an employee may receive for sharing his or her password or access with others?

  • A. The lowest rating on his or her performance assessment
  • B. Three days suspension from work
  • C. Termination
  • D. Forced roll off from the project

Answer: C

 

NEW QUESTION 32
All are prohibited in acceptable use of information assets, except:

  • A. E-mail copies to non-essential readers
  • B. Messages with very large attachments or to a large number ofrecipients.
  • C. Electronic chain letters
  • D. Company-wide e-mails with supervisor/TL permission.

Answer: D

 

NEW QUESTION 33
Availability means

  • A. Service should not be accessible when required
  • B. Service should be accessible at the required time and usable by all
  • C. Service should be accessible at the required time and usable only by the authorized entity

Answer: C

 

NEW QUESTION 34
......

Free ISO-IEC-27001-Lead-Auditor Exam Files Downloaded Instantly: https://www.real4dumps.com/ISO-IEC-27001-Lead-Auditor_examcollection.html

Verified & Latest ISO-IEC-27001-Lead-Auditor Dump Q&As with Correct Answers: https://drive.google.com/open?id=1RxvpCeUF2DHO2LbqypcxBVJXV5zSDSKg