[Aug-2021] Get 100% Real ISO-ISMS-LA Exam Questions, Accurate & Verified BraindumpQuiz Dumps in the Real Exam! [Q52-Q77]

Share

[Aug-2021] Get 100% Real ISO-ISMS-LA Exam Questions, Accurate & Verified BraindumpQuiz Dumps in the Real Exam!

Pass Your GAQM: ISO Exams Fast. All Top ISO-ISMS-LA Exam Questions Are Covered.

NEW QUESTION 52
Backup media is kept in the same secure area as the servers. What risk may the organisation be exposed to?

  • A. Responsibility for the backups is not defined well
  • B. After a server crash, it will take extra time to bring it back up again
  • C. Unauthorised persons will have access to both the servers and backups
  • D. After a fire, the information systems cannot be restored

Answer: D

 

NEW QUESTION 53
What type of legislation requires a proper controlled purchase process?

  • A. Computer criminality act
  • B. Personal data protection act
  • C. Government information act
  • D. Intellectual property rights act

Answer: D

 

NEW QUESTION 54
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good.
What is an example of the indirect damage caused by this fire?

  • A. Water damage due to the fire extinguishers
  • B. Melted backup tapes
  • C. Burned documents
  • D. Burned computer systems

Answer: A

 

NEW QUESTION 55
What is the purpose of an Information Security policy?

  • A. An information security policy provides direction and support to the management regarding information security
  • B. An information security policy provides insight into threats and the possible consequences
  • C. An information security policy makes the security plan concrete by providing the necessary details
  • D. An information security policy documents the analysis of risks and the search for countermeasures

Answer: A

 

NEW QUESTION 56
CMM stands for?

  • A. Capacity Maturity Matrix
  • B. Capability Maturity Model
  • C. Capable Mature Model
  • D. Capability Maturity Matrix

Answer: B

 

NEW QUESTION 57
-------------------------is an asset like other important business assets has value to an organization and consequently needs to be protected.

  • A. Infrastructure
  • B. Security
  • C. Information
  • D. Data

Answer: C

 

NEW QUESTION 58
A planning process that introduced the concept of planning as a cycle that forms the basis for continuous improvement is called:

  • A. planning for continuous improvement.
  • B. plan, do, check, act.
  • C. RACI Matrix
  • D. time based planning.

Answer: B

 

NEW QUESTION 59
As a new member of the IT department you have noticed that confidential information has been leaked several times. This may damage the reputation of the company. You have been asked to propose an organisational measure to protect laptop computers. What is the first step in a structured approach to come up with this measure?

  • A. Appoint security staff
  • B. Set up an access control procedure
  • C. Formulate a policy
  • D. Encrypt all sensitive information

Answer: C

 

NEW QUESTION 60
Which reliability aspect of information is compromised when a staff member denies having sent a message?

  • A. Availability
  • B. Integrity
  • C. Confidentiality
  • D. Correctness

Answer: B

 

NEW QUESTION 61
What is social engineering?

  • A. A group planning for a social activity in the organization
  • B. Creating a situation wherein a third party gains confidential information from you
  • C. The organization planning an activity for welfare of the neighborhood

Answer: B

 

NEW QUESTION 62
In order to take out a fire insurance policy, an administration office must determine the value of the data that it manages.
Which factor is [b]not[/b] important for determining the value of data for an organization?

  • A. The content of data.
  • B. The degree to which missing, incomplete or incorrect data can be recovered.
  • C. The importance of the business processes that make use of the data.
  • D. The indispensability of data for the business processes.

Answer: A

 

NEW QUESTION 63
In which order is an Information Security Management System set up?

  • A. Implementation, operation, maintenance, establishment
  • B. Establishment, operation, monitoring, improvement
  • C. Implementation, operation, improvement, maintenance
  • D. Establishment, implementation, operation, maintenance

Answer: D

 

NEW QUESTION 64
You receive the following mail from the IT support team: Dear User,Starting next week, we will be deleting all inactive email accounts in order to create spaceshare the below details in order to continue using your account. In case of no response, Name:
Email ID:
Password:
DOB:
Kindly contact the webmail team for any further support. Thanks for your attention.
Which of the following is the best response?

  • A. Ignore the email
  • B. Respond it by saying that one should not share the password with anyone
  • C. One should not respond to these mails and report such email to your supervisor

Answer: C

 

NEW QUESTION 65
Who is authorized to change the classification of a document?

  • A. The owner of the document
  • B. The manager of the owner of the document
  • C. The administrator of the document
  • D. The author of the document

Answer: A

 

NEW QUESTION 66
Which threat could occur if no physical measures are taken?

  • A. Confidential prints being left on the printer
  • B. Hackers entering the corporate network
  • C. Unauthorised persons viewing sensitive files
  • D. A server shutting down because of overheating

Answer: D

 

NEW QUESTION 67
The following are definitions of Information, except:

  • A. mature and measurable data
  • B. specific and organized data for a purpose
  • C. can lead to understanding and decrease in uncertainty
  • D. accurate and timely data

Answer: A

 

NEW QUESTION 68
The computer room is protected by a pass reader. Only the System Management department has a pass.
What type of security measure is this?

  • A. a physical security measure
  • B. a repressive security measure
  • C. a logical security measure
  • D. a corrective security measure

Answer: A

 

NEW QUESTION 69
Below is Purpose of "Integrity", which is one of the Basic Components of Information Security

  • A. the property that information is not made available or disclosed to unauthorized individuals
  • B. the property of safeguarding the accuracy and completeness of assets.
  • C. the property of being accessible and usable upon demand by an authorized entity.
  • D. the property that information is not made available or disclosed to unauthorized individuals

Answer: B

 

NEW QUESTION 70
Someone from a large tech company calls you on behalf of your company to check the health of your PC, and therefore needs your user-id and password. What type of threat is this?

  • A. Social engineering threat
  • B. Malware threat
  • C. Organisational threat
  • D. Technical threat

Answer: A

 

NEW QUESTION 71
What is a definition of compliance?

  • A. A rule or directive made and maintained by an authority.
  • B. An official or authoritative instruction
  • C. Laws, considered collectively or the process of making or enacting laws
  • D. The state or fact of according with or meeting rules or standards

Answer: D

 

NEW QUESTION 72
After a fire has occurred, what repressive measure can be taken?

  • A. Extinguishing the fire after the fire alarm sounds
  • B. Buying in a proper fire insurance policy
  • C. Repairing all systems after the fire

Answer: A

 

NEW QUESTION 73
Which of the following is not a type of Information Security attack?

  • A. Legal Incidents
  • B. Vehicular Incidents
  • C. Technical Vulnerabilities
  • D. Privacy Incidents

Answer: B

 

NEW QUESTION 74
A hacker gains access to a web server and reads the credit card numbers stored on that server. Which security principle is violated?

  • A. Integrity
  • B. Availability
  • C. Confidentiality
  • D. Authenticity

Answer: C

 

NEW QUESTION 75
Availability means

  • A. Service should not be accessible when required
  • B. Service should be accessible at the required time and usable by all
  • C. Service should be accessible at the required time and usable only by the authorized entity

Answer: C

 

NEW QUESTION 76
What is the standard definition of ISMS?

  • A. A company wide business objectives to achieve information security awareness for establishing, implementing, operating, monitoring, reviewing, maintaining and improving
  • B. Is an information security systematic approach to achieve business objectives for implementation, establishing, reviewing,operating and maintaining organization's reputation.
  • C. A systematic approach for establishing, implementing, operating,monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives.
  • D. A project-based approach to achieve business objectives for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security

Answer: C

 

NEW QUESTION 77
......

Penetration testers simulate ISO-ISMS-LA exam: https://www.braindumpquiz.com/ISO-ISMS-LA-exam-material.html