Get Started ISO-IEC-27001-Lead-Implementer Exam [2022] Dumps PECB PDF Questions [Q17-Q34]

Share

Get Started: ISO-IEC-27001-Lead-Implementer Exam [2022] Dumps PECB PDF Questions

ISO-IEC-27001-Lead-Implementer Premium Exam Engine pdf Download

NEW QUESTION 17
ISO 27002 provides guidance in the following area

  • A. PCI environment scoping
  • B. Information handling recommendations
  • C. Framework for an overall security andcompliance program
  • D. Detailed lists of required policies and procedures

Answer: C

 

NEW QUESTION 18
It is allowed that employees and contractors are provided with an anonymous reporting channel to report violations of information security policies or procedures ("whistle blowing")

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 19
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

  • A. Risk avoiding
  • B. Risk passing
  • C. Risk neutral
  • D. Risk bearing

Answer: C

 

NEW QUESTION 20
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?

  • A. Paul and Susan, the sender and the recipient of the information.
  • B. Paul, therecipient of the information.
  • C. Susan, the sender of the information.

Answer: B

 

NEW QUESTION 21
You are a consultant and areregularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports.
Which reliability aspect of the information in your reports must you protect?

  • A. Integrity
  • B. Confidentiality
  • C. Availability

Answer: B

 

NEW QUESTION 22
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?

  • A. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
  • B. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
  • C. The costs for automating are easier to charge to the responsible departments.
  • D. Reports can be developed more easily and with fewer errors.

Answer: A

 

NEW QUESTION 23
Prior to employment, _________ as well as terms & conditions of employment are included as controls in ISO
27002 to ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.

  • A. screening
  • B. controlling
  • C. authorizing
  • D. flexing

Answer: A

 

NEW QUESTION 24
How many domains does ISO / IEC 27002: 2013 have?

  • A. 0
  • B. 1
  • C. 2
  • D. 3

Answer: A

 

NEW QUESTION 25
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?

  • A. Radio Frequency Identification (RFID)
  • B. Near Field Communication (NFC)
  • C. The 4G protocol
  • D. Bluetooth

Answer: B

 

NEW QUESTION 26
You have juststarted working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?

  • A. A code of conduct is alegal obligation that organizations have to meet.
  • B. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
  • C. A code of conduct prevents a virus outbreak.
  • D. A code of conduct helps to prevent the misuse of IT facilities.

Answer: D

 

NEW QUESTION 27
What is an example of a security incident?

  • A. A member of staff loses a laptop.
  • B. You cannot set the correct fonts in your word processing software.
  • C. A file is saved under an incorrect name.
  • D. The lighting in the department no longer works.

Answer: A

 

NEW QUESTION 28
What is the greatest risk for an organization ifno information security policy has been defined?

  • A. It is not possible for an organization to implement information security in a consistent manner.
  • B. Information security activities are carried out by only a few people.
  • C. Too many measures areimplemented.
  • D. If everyone works with the same account, it is impossible to find out who worked on what.

Answer: A

 

NEW QUESTION 29
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?

  • A. A code of conduct is a standard part of a labor contract.
  • B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
  • C. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.

Answer: B

 

NEW QUESTION 30
Which of these reliability aspects is "completeness" a part of?

  • A. Exclusivity
  • B. Integrity
  • C. Availability
  • D. Confidentiality

Answer: B

 

NEW QUESTION 31
What does the Information Security Policy describe?

  • A. which InfoSec-controls have been selected and taken
  • B. what the implementation-planning of the information security management system is
  • C. how the InfoSec-objectives will be reached
  • D. which Information Security-procedures are selected

Answer: C

 

NEW QUESTION 32
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

  • A. Thefirst step consists of checking if the user is using the correct certificate.
  • B. The first step consists of granting access to the information to which the user is authorized.
  • C. The first step consists of comparing the password with the registered password.
  • D. The first step consists of checking if the user appears on the list of authorized users.

Answer: D

 

NEW QUESTION 33
Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)

  • A. Work in safe areas
  • B. Physical security perimeter
  • C. Cryptographic Controls Use Policy
  • D. Key management

Answer: C,D

 

NEW QUESTION 34
......

Pass Your PECB Exam with ISO-IEC-27001-Lead-Implementer Exam Dumps: https://actualtests.latestcram.com/ISO-IEC-27001-Lead-Implementer-exam-cram-questions.html