
Pass GAQM ISO / IEC 27002 - Lead Implementer Exam in First Attempt Guaranteed Updated Dump from Pass4SureQuiz!
Pass ISO-IEC-LI Exam with 50 Questions - Verified By Pass4SureQuiz
NEW QUESTION 19
You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
- B. A code of conduct prevents a virus outbreak.
- C. A code of conduct helps to prevent the misuse of IT facilities.
- D. A code of conduct is a legal obligation that organizations have to meet.
Answer: C
NEW QUESTION 20
What is the most important reason for applying the segregation of duties?
- A. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
- B. Segregation of duties makes it clear who is responsible for what.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
Answer: C
NEW QUESTION 21
What is the greatest risk for an organization if no information security policy has been defined?
- A. It is not possible for an organization to implement information security in a consistent manner.
- B. Information security activities are carried out by only a few people.
- C. Too many measures are implemented.
- D. If everyone works with the same account, it is impossible to find out who worked on what.
Answer: A
NEW QUESTION 22
Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)
- A. Physical security perimeter
- B. Work in safe areas
- C. Cryptographic Controls Use Policy
- D. Key management
Answer: C,D
NEW QUESTION 23
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?
- A. Radio Frequency Identification (RFID)
- B. The 4G protocol
- C. Bluetooth
- D. Near Field Communication (NFC)
Answer: D
NEW QUESTION 24
The identified owner of an asset is always an individual
- A. False
- B. True
Answer: A
NEW QUESTION 25
What is the objective of classifying information?
- A. Displaying on the document who is permitted access
- B. Creating a label that indicates how confidential the information is
- C. Defining different levels of sensitivity into which information may be arranged
- D. Authorizing the use of an information system
Answer: C
NEW QUESTION 26
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.
- A. metadata
- B. bridge
- C. teradata
Answer: A
NEW QUESTION 27
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?
- A. The first step consists of granting access to the information to which the user is authorized.
- B. The first step consists of checking if the user appears on the list of authorized users.
- C. The first step consists of comparing the password with the registered password.
- D. The first step consists of checking if the user is using the correct certificate.
Answer: B
NEW QUESTION 28
What are the data protection principles set out in the GDPR?
- A. Purpose limitation, proportionality, availability, data minimisation
- B. Target group, proportionality, transparency, data minimisation
- C. Purpose limitation, proportionality, data minimisation, transparency
- D. Purpose limitation, pudicity, transparency, data minimisation
Answer: C
NEW QUESTION 29
What is the best description of a risk analysis?
- A. A risk analysis calculates the exact financial consequences of damages.
- B. A risk analysis helps to estimate the risks and develop the appropriate security measures.
- C. A risk analysis is a method of mapping risks without looking at company processes.
Answer: B
NEW QUESTION 30
Companies use 27002 for compliance for which of the following reasons:
- A. Compliance with ISO 27002 is sufficient to comply with all regulations
- B. A structured program that helps with security and compliance
- C. Explicit requirements for all regulations
Answer: B
NEW QUESTION 31
What sort of security does a Public Key Infrastructure (PKI) offer?
- A. By providing agreements, procedures and an organization structure, a PKI defines which person or which system belongs to which specific public key.
- B. A PKI ensures that backups of company data are made on a regular basis.
- C. It provides digital certificates that can be used to digitally sign documents. Such signatures irrefutably determine from whom a document was sent.
- D. Having a PKI shows customers that a web-based business is secure.
Answer: B
NEW QUESTION 32
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The person who drafted the insurance terms and conditions
- B. The manager, Linda
- C. The recipient, Rachel
- D. The sender, Peter
Answer: C
NEW QUESTION 33
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
- A. Susan, the sender of the information.
- B. Paul and Susan, the sender and the recipient of the information.
- C. Paul, the recipient of the information.
Answer: C
NEW QUESTION 34
In the context of contact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.
- A. Authorization
- B. Authentic
- C. Availability
- D. Confidential
Answer: D
NEW QUESTION 35
It is allowed that employees and contractors are provided with an anonymous reporting channel to report violations of information security policies or procedures ("whistle blowing")
- A. True
- B. False
Answer: A
NEW QUESTION 36
Which of these reliability aspects is "completeness" a part of?
- A. Availability
- B. Integrity
- C. Exclusivity
- D. Confidentiality
Answer: B
NEW QUESTION 37
What is the best way to comply with legislation and regulations for personal data protection?
- A. Maintaining an incident register
- B. Appointing the responsibility to someone
- C. Performing a vulnerability analysis
- D. Performing a threat analysis
Answer: B
NEW QUESTION 38
What is an example of a security incident?
- A. The lighting in the department no longer works.
- B. A file is saved under an incorrect name.
- C. A member of staff loses a laptop.
- D. You cannot set the correct fonts in your word processing software.
Answer: C
NEW QUESTION 39
......
Penetration testers simulate ISO-IEC-LI exam: https://www.pass4surequiz.com/ISO-IEC-LI-exam-quiz.html