[Apr 27, 2023] ISO-IEC-27001-Lead-Auditor Questions Truly Valid For Your PECB Exam! [Q22-Q43]

Share

[Apr 27, 2023] ISO-IEC-27001-Lead-Auditor Questions Truly Valid For Your PECB Exam!

ISO-IEC-27001-Lead-Auditor Actual Questions - Instant Download Tests Free Updated Today!


This certification program is designed for professionals who have a deep understanding of information security management systems and audit principles. The PECB ISO-IEC-27001-Lead-Auditor exam covers various topics, including information security management system standards, audit techniques, risk management, and compliance with legal and regulatory requirements. The exam also tests the candidate's ability to plan, conduct, report, and follow up on an audit of an ISMS in accordance with ISO/IEC 27001 standards.

 

NEW QUESTION # 22
CMM stands for?

  • A. Capability Maturity Matrix
  • B. Capacity Maturity Matrix
  • C. Capable Mature Model
  • D. Capability Maturity Model

Answer: D


NEW QUESTION # 23
In what part of the process to grant access to a system does the user present a token?

  • A. Identification
  • B. Authentication
  • C. Verification
  • D. Authorisation

Answer: A


NEW QUESTION # 24
Which is the glue that ties the triad together

  • A. Process
  • B. Technology
  • C. Collaboration
  • D. People

Answer: A


NEW QUESTION # 25
Availability means

  • A. Service should be accessible at the required time and usable by all
  • B. Service should be accessible at the required time and usable only by the authorized entity
  • C. Service should not be accessible when required

Answer: B


NEW QUESTION # 26
The computer room is protected by a pass reader. Only the System Management department has a pass.
What type of security measure is this?

  • A. a corrective security measure
  • B. a logical security measure
  • C. a physical security measure
  • D. a repressive security measure

Answer: C


NEW QUESTION # 27
How is the purpose of information security policy best described?

  • A. An information security policy documents the analysis of risks and the search for countermeasures.
  • B. An information security policy makes the security plan concrete by providing it with the necessary details.
  • C. An information security policy provides insight into threats and the possible consequences.
  • D. An information security policy provides direction and support to the management regarding information security.

Answer: D


NEW QUESTION # 28
Which reliability aspect of information is compromised when a staff member denies having sent a message?

  • A. Confidentiality
  • B. Integrity
  • C. Availability
  • D. Correctness

Answer: B


NEW QUESTION # 29
After a devastating office fire, all staff are moved to other branches of the company. At what moment in the incident management process is this measure effectuated?

  • A. Between incident and damage
  • B. Between recovery and normal operations
  • C. Between classification and escalation
  • D. Between detection and classification

Answer: A


NEW QUESTION # 30
A well-executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives.
What is not one of the four main objectives of a risk analysis?

  • A. Implementing counter measures
  • B. Determining relevant vulnerabilities and threats
  • C. Establishing a balance between the costs of an incident and the costs of a security measure
  • D. Identifying assets and their value

Answer: A


NEW QUESTION # 31
There is a network printer in the hallway of the company where you work. Many employees don't pick up their printouts immediately and leave them on the printer.
What are the consequences of this to the reliability of the information?

  • A. The availability of the information is no longer guaranteed.
  • B. The confidentiality of the information is no longer guaranteed.
  • C. The integrity of the information is no longer guaranteed.
  • D. The Security of the information is no longer guaranteed.

Answer: A


NEW QUESTION # 32
Four types of Data Classification (Choose two)

  • A. Restricted Data, Confidential Data
  • B. Unrestricted Data, Highly Confidential Data
  • C. Financial Data, Highly Confidential Data
  • D. Project Data, Highly Confidential Data

Answer: A,B


NEW QUESTION # 33
What type of legislation requires a proper controlled purchase process?

  • A. Personal data protection act
  • B. Computer criminality act
  • C. Government information act
  • D. Intellectual property rights act

Answer: D


NEW QUESTION # 34
What is the purpose of an Information Security policy?

  • A. An information security policy provides direction and support to the management regarding information security
  • B. An information security policy makes the security plan concrete by providing the necessary details
  • C. An information security policy provides insight into threats and the possible consequences
  • D. An information security policy documents the analysis of risks and the search for countermeasures

Answer: A


NEW QUESTION # 35
An administration office is going to determine the dangers to which it is exposed.
What do we call a possible event that can have a disruptive effect on the reliability of information?

  • A. vulnerability
  • B. dependency
  • C. risk
  • D. threat

Answer: D


NEW QUESTION # 36
What is social engineering?

  • A. Creating a situation wherein a third party gains confidential information from you
  • B. A group planning for a social activity in the organization
  • C. The organization planning an activity for welfare of the neighborhood

Answer: A


NEW QUESTION # 37
What is the worst possible action that an employee may receive for sharing his or her password or access with others?

  • A. Termination
  • B. Forced roll off from the project
  • C. Three days suspension from work
  • D. The lowest rating on his or her performance assessment

Answer: A


NEW QUESTION # 38
Who is responsible for Initial asset allocation to the user/custodian of the assets?

  • A. Asset Stakeholder
  • B. Asset Practitioner
  • C. Asset Owner
  • D. Asset Manager

Answer: C


NEW QUESTION # 39
Information or data that are classified as ______ do not require labeling.

  • A. Confidential
  • B. Internal
  • C. Highly Confidential
  • D. Public

Answer: D


NEW QUESTION # 40
In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:

  • A. Cooperate with investigative personnel during investigation if needed
  • B. Make the information security incident details known to all employees
  • C. Report suspected or known incidents upon discovery through the Servicedesk
  • D. Preserve evidence if necessary

Answer: B


NEW QUESTION # 41
Which of the following is an information security management system standard published by the International Organization for Standardization?

  • A. ISO22301
  • B. ISO27001
  • C. ISO5501
  • D. ISO9008

Answer: B


NEW QUESTION # 42
After a fire has occurred, what repressive measure can be taken?

  • A. Extinguishing the fire after the fire alarm sounds
  • B. Repairing all systems after the fire
  • C. Buying in a proper fire insurance policy

Answer: A


NEW QUESTION # 43
......

Get instant access of 100% real exam questions with verified answers: https://freecert.test4sure.com/ISO-IEC-27001-Lead-Auditor-exam-materials.html