ISO 27001 Real Exam Questions and Answers FREE ISO-IEC-27001-Lead-Auditor Updated on Oct 05, 2021 [Q19-Q36]

Share

ISO 27001 ISO-IEC-27001-Lead-Auditor Real Exam Questions and Answers FREE Updated on Oct 05, 2021

ISO-IEC-27001-Lead-Auditor Ultimate Study Guide -  BraindumpQuiz

NEW QUESTION 19
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself.
You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?

  • A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
  • B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.

Answer: A

 

NEW QUESTION 20
A planning process that introduced the concept of planning as a cycle that forms the basis for continuous improvement is called:

  • A. planning for continuous improvement.
  • B. plan, do, check, act.
  • C. RACI Matrix
  • D. time based planning.

Answer: B

 

NEW QUESTION 21
Which is not a requirement of HR prior to hiring?

  • A. Applicant must complete pre-employment documentation requirements
  • B. Undergo background verification
  • C. Must undergo Awareness training on information security.
  • D. Must successfully pass Background Investigation

Answer: C

 

NEW QUESTION 22
Which threat could occur if no physical measures are taken?

  • A. Confidential prints being left on the printer
  • B. Hackers entering the corporate network
  • C. Unauthorised persons viewing sensitive files
  • D. A server shutting down because of overheating

Answer: D

 

NEW QUESTION 23
Four types of Data Classification (Choose two)

  • A. Restricted Data, Confidential Data
  • B. Unrestricted Data, Highly Confidential Data
  • C. Project Data, Highly Confidential Data
  • D. Financial Data, Highly Confidential Data

Answer: A,B

 

NEW QUESTION 24
You receive an E-mail from some unknown person claiming to be representative of your bank and asking for your account number and password so that they can fix your account. Such an attempt of social engineering is called

  • A. Spoofing
  • B. Shoulder Surfing
  • C. Mountaineering
  • D. Phishing

Answer: D

 

NEW QUESTION 25
Which of the following is a possible event that can have a disruptive effect on the reliability of information?

  • A. Risk
  • B. Threat
  • C. Dependency
  • D. Vulnerability

Answer: B

 

NEW QUESTION 26
Often, people do not pick up their prints from a shared printer. How can this affect the confidentiality of information?

  • A. Integrity cannot be guaranteed
  • B. Availability cannot be guaranteed
  • C. Confidentiality cannot be guaranteed
  • D. Authenticity cannot be guaranteed

Answer: C

 

NEW QUESTION 27
There is a scheduled fire drill in your facility. What should you do?

  • A. Excuse yourself by saying you have an urgent deliverable
  • B. Call in sick
  • C. None of the above
  • D. Participate in the drill

Answer: D

 

NEW QUESTION 28
How are data and information related?

  • A. Information consists of facts and statistics collected together for reference or analysis
  • B. Data is a collection of structured and unstructured information
  • C. When meaning and value are assigned to data, it becomes information

Answer: C

 

NEW QUESTION 29
Information has a number of reliability aspects. Reliability is constantly being threatened. Examples of threats are: a cable becomes loose, someone alters information by accident, data is used privately or is falsified.
Which of these examples is a threat to integrity?

  • A. accidental alteration of data
  • B. private use of data
  • C. a loose cable
  • D. System restart

Answer: A

 

NEW QUESTION 30
Which of the following does an Asset Register contain? (Choose two)

  • A. Asset Type
  • B. Asset Modifier
  • C. Asset Owner
  • D. Process ID

Answer: A,C

 

NEW QUESTION 31
Which of the following is an information security management system standard published by the International Organization for Standardization?

  • A. ISO27001
  • B. ISO22301
  • C. ISO5501
  • D. ISO9008

Answer: A

 

NEW QUESTION 32
What type of measure involves the stopping of possible consequences of security incidents?

  • A. Corrective
  • B. Repressive
  • C. Preventive
  • D. Detective

Answer: B

 

NEW QUESTION 33
What is a definition of compliance?

  • A. A rule or directive made and maintained by an authority.
  • B. An official or authoritative instruction
  • C. Laws, considered collectively or the process of making or enacting laws
  • D. The state or fact of according with or meeting rules or standards

Answer: D

 

NEW QUESTION 34
What is a reason for the classification of information?

  • A. To provide clear identification tags
  • B. To structure the information according to its sensitivity
  • C. Creating a manual describing the BYOD policy

Answer: B

 

NEW QUESTION 35
What type of legislation requires a proper controlled purchase process?

  • A. Computer criminality act
  • B. Personal data protection act
  • C. Government information act
  • D. Intellectual property rights act

Answer: D

 

NEW QUESTION 36
......

Ultimate Guide to Prepare ISO-IEC-27001-Lead-Auditor Certification Exam for ISO 27001: https://www.braindumpquiz.com/ISO-IEC-27001-Lead-Auditor-exam-material.html

Use Real ISO-IEC-27001-Lead-Auditor Dumps - PECB Correct Answers: https://drive.google.com/open?id=1IydxO5FNDem28Nygv-HZkObQ5How_KUX