
GAQM ISO-IEC-LI Practice Verified Answers - Pass Your Exams For Sure! [2021]
Valid Way To Pass GAQM certification's ISO-IEC-LI Exam
NEW QUESTION 23
Of the following, which is the best organization or set of organizations to contribute to compliance?
- A. IT only
- B. IT, business management, HR and legal
- C. IT and legal
- D. IT and management
Answer: B
NEW QUESTION 24
What is the most important reason for applying the segregation of duties?
- A. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
- B. Segregation of duties makes it clear who is responsible for what.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
Answer: C
NEW QUESTION 25
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What type of measure could prevent this error?
- A. Integrity measure
- B. Availability measure
- C. Technical measure
- D. Organizational measure
Answer: C
NEW QUESTION 26
What is an example of a good physical security measure?
- A. Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.
- B. All employees and visitors carry an access pass.
- C. Printers that are defective or have been replaced are immediately removed and given away as garbage for recycling.
Answer: B
NEW QUESTION 27
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
- A. ISO/IEC 27001:2005
- B. ISO/IEC 27002:2005
- C. Personal data protection legislation
- D. Intellectual Property Rights
Answer: C
NEW QUESTION 28
The identified owner of an asset is always an individual
- A. False
- B. True
Answer: A
NEW QUESTION 29
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The person who drafted the insurance terms and conditions
- B. The manager, Linda
- C. The recipient, Rachel
- D. The sender, Peter
Answer: C
NEW QUESTION 30
What do employees need to know to report a security incident?
- A. Whether the incident has occurred before and what was the resulting damage.
- B. Who is responsible for the incident and whether it was intentional.
- C. How to report an incident and to whom.
- D. The measures that should have been taken to prevent the incident in the first place.
Answer: C
NEW QUESTION 31
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?
- A. The first step consists of granting access to the information to which the user is authorized.
- B. The first step consists of checking if the user appears on the list of authorized users.
- C. The first step consists of comparing the password with the registered password.
- D. The first step consists of checking if the user is using the correct certificate.
Answer: B
NEW QUESTION 32
What are the data protection principles set out in the GDPR?
- A. Purpose limitation, proportionality, availability, data minimisation
- B. Target group, proportionality, transparency, data minimisation
- C. Purpose limitation, proportionality, data minimisation, transparency
- D. Purpose limitation, pudicity, transparency, data minimisation
Answer: C
NEW QUESTION 33
Why is compliance important for the reliability of the information?
- A. By meeting the legislative requirements and the regulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
- B. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- C. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and therefore it guarantees the reliability of its information.
Answer: A
NEW QUESTION 34
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk passing
- B. Risk bearing
- C. Risk avoiding
- D. Risk neutral
Answer: D
NEW QUESTION 35
Responsibilities for information security in projects should be defined and allocated to:
- A. the owner of the involved asset
- B. the project manager
- C. the InfoSec officer
- D. specified roles defined in the used project management method of the organization
Answer: D
NEW QUESTION 36
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered
- A. True
- B. False
Answer: A
NEW QUESTION 37
Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)
- A. Physical security perimeter
- B. Work in safe areas
- C. Cryptographic Controls Use Policy
- D. Key management
Answer: C,D
NEW QUESTION 38
What is the best way to comply with legislation and regulations for personal data protection?
- A. Maintaining an incident register
- B. Appointing the responsibility to someone
- C. Performing a vulnerability analysis
- D. Performing a threat analysis
Answer: B
NEW QUESTION 39
Which of the following measures is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
- D. Shutting down all internet traffic after a hacker has gained access to the company systems
Answer: A
NEW QUESTION 40
Who is authorized to change the classification of a document?
- A. The owner of the document
- B. The manager of the owner of the document
- C. The administrator of the document
- D. The author of the document
Answer: A
NEW QUESTION 41
How many domains does ISO / IEC 27002: 2013 have?
- A. 0
- B. 1
- C. 2
- D. 3
Answer: D
NEW QUESTION 42
What is the objective of classifying information?
- A. Displaying on the document who is permitted access
- B. Creating a label that indicates how confidential the information is
- C. Defining different levels of sensitivity into which information may be arranged
- D. Authorizing the use of an information system
Answer: C
NEW QUESTION 43
......
GAQM ISO-IEC-LI Pre-Exam Practice Tests | BraindumpQuiz: https://www.braindumpquiz.com/ISO-IEC-LI-exam-material.html