2022 Realistic Verified Free PECB ISO-IEC-27001-Lead-Implementer Exam Questions [Q13-Q38]

Share

2022 Realistic Verified Free PECB ISO-IEC-27001-Lead-Implementer Exam Questions

ISO-IEC-27001-Lead-Implementer Real Exam Questions and Answers FREE

NEW QUESTION 13
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?

  • A. Personal data protection legislation
  • B. Intellectual Property Rights
  • C. ISO/IEC 27001:2005
  • D. ISO/IEC 27002:2005

Answer: A

 

NEW QUESTION 14
It is allowed that employees and contractors are provided with an anonymous reporting channel to report violations of information security policies or procedures ("whistle blowing")

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 15
What is the greatest risk for an organization ifno information security policy has been defined?

  • A. Too many measures areimplemented.
  • B. It is not possible for an organization to implement information security in a consistent manner.
  • C. If everyone works with the same account, it is impossible to find out who worked on what.
  • D. Information security activities are carried out by only a few people.

Answer: B

 

NEW QUESTION 16
You are a consultant and areregularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports.
Which reliability aspect of the information in your reports must you protect?

  • A. Confidentiality
  • B. Integrity
  • C. Availability

Answer: A

 

NEW QUESTION 17
Which of the following measures is a preventive measure?

  • A. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
  • B. Putting sensitive information in a safe
  • C. Shutting down all internet traffic after a hacker has gained access to thecompany systems
  • D. Installing a logging system that enables changes in a system to be recognized

Answer: B

 

NEW QUESTION 18
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of theclients is earlier than the start date. What type of measure could prevent this error?

  • A. Technical measure
  • B. Integrity measure
  • C. Availability measure
  • D. Organizational measure

Answer: A

 

NEW QUESTION 19
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?

  • A. The recipient, Rachel
  • B. The sender, Peter
  • C. The person who drafted the insurance terms and conditions
  • D. The manager, Linda

Answer: A

 

NEW QUESTION 20
Who is authorized to change the classification of a document?

  • A. The administrator of the document
  • B. The author of the document
  • C. The manager of the owner of the document
  • D. The owner of the document

Answer: D

 

NEW QUESTION 21
Who is accountable to classify information assets?

  • A. the CEO
  • B. theasset owner
  • C. the CISO
  • D. the Information Security Team

Answer: B

 

NEW QUESTION 22
Which of these reliability aspects is "completeness" a part of?

  • A. Integrity
  • B. Confidentiality
  • C. Exclusivity
  • D. Availability

Answer: A

 

NEW QUESTION 23
What is the objective of classifying information?

  • A. Authorizing the use of an information system
  • B. Defining different levels of sensitivity into which information may be arranged
  • C. Creating alabel that indicates how confidential the information is
  • D. Displaying on the document who is permitted access

Answer: B

 

NEW QUESTION 24
What is the best way to comply with legislation and regulations for personal data protection?

  • A. Performing a vulnerability analysis
  • B. Appointing the responsibility to someone
  • C. Maintaining an incident register
  • D. Performing a threat analysis

Answer: B

 

NEW QUESTION 25
ISO 27002 provides guidance in the following area

  • A. Information handling recommendations
  • B. Framework for an overall security andcompliance program
  • C. Detailed lists of required policies and procedures
  • D. PCI environment scoping

Answer: B

 

NEW QUESTION 26
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?

  • A. Bluetooth
  • B. Near Field Communication (NFC)
  • C. Radio Frequency Identification (RFID)
  • D. The 4G protocol

Answer: B

 

NEW QUESTION 27
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?

  • A. Availability, Information Value and Confidentiality
  • B. Timeliness, Accuracy and Completeness
  • C. Availability, Integrity and Completeness
  • D. Availability, Integrity and Confidentiality

Answer: D

 

NEW QUESTION 28
Why is compliance important forthe reliability of the information?

  • A. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
  • B. By meeting the legislative requirements and theregulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
  • C. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and thereforeit guarantees the reliability of its information.
  • D. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.

Answer: B

 

NEW QUESTION 29
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered

  • A. True
  • B. False

Answer: A

 

NEW QUESTION 30
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?

  • A. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
  • B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
  • C. A code of conduct is a standard part of a labor contract.

Answer: B

 

NEW QUESTION 31
What do employees need to know to report a security incident?

  • A. How to report an incident and to whom.
  • B. Who is responsible for the incident and whether it was intentional.
  • C. Whether the incident has occurred before and what was the resulting damage.
  • D. The measures that should have been taken to prevent the incident in the first place.

Answer: A

 

NEW QUESTION 32
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

  • A. The first step consists of checking if the user appears on the list of authorized users.
  • B. The first step consists of comparing the password with the registered password.
  • C. The first step consists of granting access to the information to which the user is authorized.
  • D. Thefirst step consists of checking if the user is using the correct certificate.

Answer: A

 

NEW QUESTION 33
......

Exam Dumps ISO-IEC-27001-Lead-Implementer Practice Free Latest PECB Practice Tests: https://www.suretorrent.com/ISO-IEC-27001-Lead-Implementer-exam-guide-torrent.html

ISO-IEC-27001-Lead-Implementer Exam Questions | Real ISO-IEC-27001-Lead-Implementer Practice Dumps: https://drive.google.com/open?id=1KyY2fIh9s3z0dZMfeLnusDj1WfUQzOko