
Try ISO-IEC-27001-Lead-Implementer Free Now! Real Exam Question Answers Updated [Jun 20, 2023]
Get Ready to Pass the ISO-IEC-27001-Lead-Implementer exam with PECB Latest Practice Exam
The PECB ISO-IEC-27001-Lead-Implementer certification exam is designed to assess the knowledge and skills of professionals who are responsible for implementing an information security management system (ISMS) based on the ISO/IEC 27001 standard. The exam is administered by the Professional Evaluation and Certification Board (PECB), a leading provider of professional certification programs.
NEW QUESTION # 13
Which of these reliability aspects is "completeness" a part of?
- A. Availability
- B. Confidentiality
- C. Exclusivity
- D. Integrity
Answer: D
NEW QUESTION # 14
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
- B. A code ofconduct specifies how employees are expected to conduct themselves and is the same for all companies.
- C. A code of conduct is a standard part of a labor contract.
Answer: A
NEW QUESTION # 15
What do employees need to know to report a security incident?
- A. The measures that should have been taken to prevent the incident in the first place.
- B. Who is responsible for the incident and whether it was intentional.
- C. How to report an incident and to whom.
- D. Whether the incident has occurred before and what was the resulting damage.
Answer: C
NEW QUESTION # 16
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventoryof threats and risks.
What is the relation between a threat, risk and risk analysis?
- A. A riskanalysis is used to remove the risk of a threat.
- B. A risk analysis identifies threats from the known risks.
- C. A risk analysis is used to clarify which threats are relevant and what risks they involve.
- D. Risk analyses help to find a balance between threats and risks.
Answer: C
NEW QUESTION # 17
Select the controls that correspond to thedomain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)
- A. Return of assets
- B. Management of access rights with special privileges
- C. Restriction of access to information
- D. Withdrawal or adaptation of access rights
Answer: A,C,D
NEW QUESTION # 18
What is an example of a non-human threat to the physical environment?
- A. Corrupted file
- B. Virus
- C. Storm
- D. Fraudulent transaction
Answer: C
NEW QUESTION # 19
What is an example of a good physical security measure?
- A. All employees and visitors carry an access pass.
- B. Printers that are defective or have been replacedare immediately removed and given away as garbage for recycling.
- C. Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.
Answer: A
NEW QUESTION # 20
Responsibilities for information security in projects should be defined and allocated to:
- A. the owner of the involved asset
- B. specified roles defined in the used project management method of the organization
- C. the project manager
- D. the InfoSec officer
Answer: B
NEW QUESTION # 21
Companies use 27002 for compliance for which of the following reasons:
- A. Compliance with ISO 27002 is sufficient to comply with all regulations
- B. Explicit requirements for all regulations
- C. A structured program that helps with security and compliance
Answer: C
NEW QUESTION # 22
It is allowed that employees and contractors are provided with an anonymous reporting channel to report violations of information security policies or procedures ("whistle blowing")
- A. True
- B. False
Answer: A
NEW QUESTION # 23
Which of the following measures is a correctivemeasure?
- A. Incorporating an Intrusion Detection System (IDS) in the design of a computer center
- B. Installing a virus scanner in an information system
- C. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
- D. Making a backup of the data that has been created or altered that day
Answer: C
NEW QUESTION # 24
What is the objective of classifying information?
- A. Displaying on the document who is permitted access
- B. Defining different levels of sensitivity into which information may be arranged
- C. Authorizing the use of an information system
- D. Creating alabel that indicates how confidential the information is
Answer: B
NEW QUESTION # 25
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the company's staff. Which kind of security measure could have prevented this?
- A. physical security measure
- B. An organizational security measure
- C. A technical security measure
Answer: A
NEW QUESTION # 26
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered
- A. True
- B. False
Answer: A
NEW QUESTION # 27
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?
- A. Reports can be developed more easily and with fewer errors.
- B. Everyone can easily see how sensitive the reports' contents are by consulting the grading label.
- C. A determination can be made as to which report should be printed firstand which ones can wait a little longer.
- D. The costs for automating are easier to charge to the responsible departments.
Answer: B
NEW QUESTION # 28
What is an example of a security incident?
- A. A file is saved under an incorrect name.
- B. The lighting in the department no longer works.
- C. A member of staff loses a laptop.
- D. You cannot set the correct fonts in your word processing software.
Answer: C
NEW QUESTION # 29
Which of the following measures is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Shutting down all internet traffic after a hacker has gained access to thecompany systems
- D. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
Answer: A
NEW QUESTION # 30
Who is accountable to classify information assets?
- A. the CISO
- B. the Information Security Team
- C. theasset owner
- D. the CEO
Answer: C
NEW QUESTION # 31
What sort of security does a Public Key Infrastructure (PKI) offer?
- A. By providing agreements, procedures and an organization structure, a PKI defines which person or which system belongs to which specific public key.
- B. Having a PKI shows customers that a web-based business is secure.
- C. A PKI ensures that backups of company data are made on a regular basis.
- D. It provides digital certificates that can be used to digitally signdocuments. Such signatures irrefutably determine from whom a document was sent.
Answer: C
NEW QUESTION # 32
......
Pass Your Next ISO-IEC-27001-Lead-Implementer Certification Exam Easily & Hassle Free: https://lead2pass.examdumpsvce.com/ISO-IEC-27001-Lead-Implementer-valid-exam-dumps.html
