
Latest [Oct 28, 2021] ISO-ISMS-LA Exam with Accurate ISO 27001 : 2013 ISMS - Certified Lead Auditor PDF Questions
Take a Leap Forward in Your Career by Earning GAQM 99 Questions
NEW QUESTION 49
What is the purpose of an Information Security policy?
- A. An information security policy provides direction and support to the management regarding information security
- B. An information security policy provides insight into threats and the possible consequences
- C. An information security policy makes the security plan concrete by providing the necessary details
- D. An information security policy documents the analysis of risks and the search for countermeasures
Answer: A
NEW QUESTION 50
What type of compliancy standard, regulation or legislation provides a code of practice for information security?
- A. Personal data protection act
- B. ISO/IEC 27002
- C. IT Service Management
- D. Computer criminality act
Answer: B
NEW QUESTION 51
There is a scheduled fire drill in your facility. What should you do?
- A. None of the above
- B. Call in sick
- C. Excuse yourself by saying you have an urgent deliverable
- D. Participate in the drill
Answer: D
NEW QUESTION 52
Stages of Information
- A. creation, distribution, use, maintenance, disposition
- B. creation, distribution, maintenance, disposition, use
- C. creation, evolution, maintenance, use, disposition
- D. creation, use, disposition, maintenance, evolution
Answer: A
NEW QUESTION 53
Which of the following does a lack of adequate security controls represent?
- A. Threat
- B. Vulnerability
- C. Impact
- D. Asset
Answer: B
NEW QUESTION 54
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself.
You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
NEW QUESTION 55
What type of measure involves the stopping of possible consequences of security incidents?
- A. Preventive
- B. Corrective
- C. Repressive
- D. Detective
Answer: C
NEW QUESTION 56
CEO sends a mail giving his views on the status of the company and the company's future strategy and the CEO's vision and the employee's part in it. The mail should be classified as
- A. Restricted Mail
- B. Public Mail
- C. Internal Mail
- D. Confidential Mail
Answer: C
NEW QUESTION 57
In acceptable use of Information Assets, which is the best practice?
- A. Playing any computer games during office hours
- B. Access to information and communication systems are provided for business purpose only
- C. Interfering with or denying service to any user other than the employee's host
- D. Accessing phone or network transmissions, including wireless or wifi transmissions
Answer: B
NEW QUESTION 58
Which is not a requirement of HR prior to hiring?
- A. Must undergo Awareness training on information security.
- B. Undergo background verification
- C. Applicant must complete pre-employment documentation requirements
- D. Must successfully pass Background Investigation
Answer: A
NEW QUESTION 59
How is the purpose of information security policy best described?
- A. An information security policy provides direction and support to the management regarding information security.
- B. An information security policy makes the security plan concrete by providing it with the necessary details.
- C. An information security policy provides insight into threats and the possible consequences.
- D. An information security policy documents the analysis of risks and the search for countermeasures.
Answer: A
NEW QUESTION 60
Which of the following is a technical security measure?
- A. Safe storage of backups
- B. User role profiles.
- C. Security policy
- D. Encryption
Answer: D
NEW QUESTION 61
Often, people do not pick up their prints from a shared printer. How can this affect the confidentiality of information?
- A. Availability cannot be guaranteed
- B. Integrity cannot be guaranteed
- C. Confidentiality cannot be guaranteed
- D. Authenticity cannot be guaranteed
Answer: C
NEW QUESTION 62
Which of the following does an Asset Register contain? (Choose two)
- A. Asset Modifier
- B. Asset Owner
- C. Process ID
- D. Asset Type
Answer: B,D
NEW QUESTION 63
What is the goal of classification of information?
- A. Structuring information according to its sensitivity
- B. Applying labels making the information easier to recognize
- C. To create a manual about how to handle mobile devices
Answer: A
NEW QUESTION 64
Who are allowed to access highly confidential files?
- A. Non-employees designated with approved access and have signed NDA
- B. Employees with a business need-to-know
- C. Employees with signed NDA have a business need-to-know
- D. Contractors with a business need-to-know
Answer: C
NEW QUESTION 65
Which of the following factors does NOT contribute to the value of data for an organisation?
- A. The importance of data for processes
- B. The content of data
- C. The correctness of data
- D. The indispensability of data
Answer: B
NEW QUESTION 66
......
Authentic Best resources for ISO-ISMS-LA Online Practice Exam: https://www.2pass4sure.com/GAQM-ISO/ISO-ISMS-LA-actual-exam-braindumps.html