
ISO-IEC-27001-Lead-Auditor Practice Exam and Study Guides - Verified By iPassleader Updated 99 Questions
2021 Updated Verified Pass ISO-IEC-27001-Lead-Auditor Study Guides & Best Courses
NEW QUESTION 17
You have a hard copy of a customer design document that you want to dispose off. What would you do
- A. Be environment friendly and reuse it for writing
- B. Give it to the office boy to reuse it for other purposes
- C. Shred it using a shredder
- D. Throw it in any dustbin
Answer: C
NEW QUESTION 18
Which of the following does a lack of adequate security controls represent?
- A. Threat
- B. Vulnerability
- C. Impact
- D. Asset
Answer: B
NEW QUESTION 19
What type of measure involves the stopping of possible consequences of security incidents?
- A. Preventive
- B. Corrective
- C. Repressive
- D. Detective
Answer: C
NEW QUESTION 20
The following are the guidelines to protect your password, except:
- A. Don't use the same password for various company system security access
- B. For easy recall, use the same password for company and personal accounts
- C. Change a temporary password on first log-on
- D. Do not share passwords with anyone
Answer: B,D
NEW QUESTION 21
A planning process that introduced the concept of planning as a cycle that forms the basis for continuous improvement is called:
- A. planning for continuous improvement.
- B. plan, do, check, act.
- C. RACI Matrix
- D. time based planning.
Answer: B
NEW QUESTION 22
Why do we need to test a disaster recovery plan regularly, and keep it up to date?
- A. Otherwise remotely stored backups may no longer be available to the security team
- B. Otherwise it is no longer up to date with the registration of daily occurring faults
- C. Otherwise the measures taken and the incident procedures planned may not be adequate
Answer: C
NEW QUESTION 23
You receive an E-mail from some unknown person claiming to be representative of your bank and asking for your account number and password so that they can fix your account. Such an attempt of social engineering is called
- A. Phishing
- B. Spoofing
- C. Shoulder Surfing
- D. Mountaineering
Answer: A
NEW QUESTION 24
Below is Purpose of "Integrity", which is one of the Basic Components of Information Security
- A. the property of safeguarding the accuracy and completeness of assets.
- B. the property that information is not made available or disclosed to unauthorized individuals
- C. the property that information is not made available or disclosed to unauthorized individuals
- D. the property of being accessible and usable upon demand by an authorized entity.
Answer: A
NEW QUESTION 25
Someone from a large tech company calls you on behalf of your company to check the health of your PC, and therefore needs your user-id and password. What type of threat is this?
- A. Social engineering threat
- B. Malware threat
- C. Technical threat
- D. Organisational threat
Answer: A
NEW QUESTION 26
A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:
- A. Greet and ask him what is his business
- B. Say "hi" and offer coffee
- C. Escort him to his destination
- D. Call the receptionist and inform about the visitor
Answer: B
NEW QUESTION 27
What would be the reference for you to know who should have access to data/document?
- A. Information Rights Management (IRM)
- B. Data Classification Label
- C. Access Control List (ACL)
- D. Masterlist of Project Records (MLPR)
Answer: C
NEW QUESTION 28
Which of the following does an Asset Register contain? (Choose two)
- A. Asset Modifier
- B. Asset Owner
- C. Process ID
- D. Asset Type
Answer: B,D
NEW QUESTION 29
We can leave laptops during weekdays or weekends in locked bins.
- A. False
- B. True
Answer: A
NEW QUESTION 30
In what part of the process to grant access to a system does the user present a token?
- A. Authentication
- B. Identification
- C. Verification
- D. Authorisation
Answer: B
NEW QUESTION 31
What is a definition of compliance?
- A. Laws, considered collectively or the process of making or enacting laws
- B. The state or fact of according with or meeting rules or standards
- C. A rule or directive made and maintained by an authority.
- D. An official or authoritative instruction
Answer: B
NEW QUESTION 32
What type of system ensures a coherent Information Security organisation?
- A. Information Technology Service Management System (ITSM)
- B. Information Exchange Data System (IEDS)
- C. Information Security Management System (ISMS)
- D. Federal Information Security Management Act (FISMA)
Answer: C
NEW QUESTION 33
Which of the following is not a type of Information Security attack?
- A. Privacy Incidents
- B. Vehicular Incidents
- C. Legal Incidents
- D. Technical Vulnerabilities
Answer: B
NEW QUESTION 34
Often, people do not pick up their prints from a shared printer. How can this affect the confidentiality of information?
- A. Availability cannot be guaranteed
- B. Integrity cannot be guaranteed
- C. Confidentiality cannot be guaranteed
- D. Authenticity cannot be guaranteed
Answer: C
NEW QUESTION 35
......
Ultimate Guide to the ISO-IEC-27001-Lead-Auditor - Latest Edition Available Now: https://www.ipassleader.com/PECB/ISO-IEC-27001-Lead-Auditor-practice-exam-dumps.html
2021 Updated Verified Pass ISO-IEC-27001-Lead-Auditor Exam - Real Questions & Answers: https://drive.google.com/open?id=14mpS8aVLS3ixHf5Dkmqtn8lfSdksL96C