
[Sep-2021] ISO-IEC-27001-Lead-Auditor Dumps Full Questions - ISO 27001 Exam Study Guide
Exam Questions and Answers for ISO-IEC-27001-Lead-Auditor Study Guide
NEW QUESTION 35
What is we do in ACT - From PDCA cycle
- A. Take actions to continually monitor process performance
- B. Take actions to continually improve people performance
- C. Take actions to continually monitor process performance
- D. Take actions to continually improve process performance
Answer: D
NEW QUESTION 36
Which reliability aspect of information is compromised when a staff member denies having sent a message?
- A. Availability
- B. Integrity
- C. Confidentiality
- D. Correctness
Answer: B
NEW QUESTION 37
Changes on project-managed applications or database should undergo the change control process as documented.
- A. True
- B. False
Answer: A
NEW QUESTION 38
Which of the following is a technical security measure?
- A. Safe storage of backups
- B. User role profiles.
- C. Encryption
- D. Security policy
Answer: C
NEW QUESTION 39
There is a scheduled fire drill in your facility. What should you do?
- A. Excuse yourself by saying you have an urgent deliverable
- B. Call in sick
- C. None of the above
- D. Participate in the drill
Answer: D
NEW QUESTION 40
After a fire has occurred, what repressive measure can be taken?
- A. Extinguishing the fire after the fire alarm sounds
- B. Buying in a proper fire insurance policy
- C. Repairing all systems after the fire
Answer: A
NEW QUESTION 41
Who is responsible for Initial asset allocation to the user/custodian of the assets?
- A. Asset Manager
- B. Asset Stakeholder
- C. Asset Practitioner
- D. Asset Owner
Answer: D
NEW QUESTION 42
Which of the following does an Asset Register contain? (Choose two)
- A. Asset Type
- B. Asset Modifier
- C. Asset Owner
- D. Process ID
Answer: A,C
NEW QUESTION 43
What is a reason for the classification of information?
- A. To provide clear identification tags
- B. To structure the information according to its sensitivity
- C. Creating a manual describing the BYOD policy
Answer: B
NEW QUESTION 44
Which is not a requirement of HR prior to hiring?
- A. Applicant must complete pre-employment documentation requirements
- B. Undergo background verification
- C. Must undergo Awareness training on information security.
- D. Must successfully pass Background Investigation
Answer: C
NEW QUESTION 45
Who is authorized to change the classification of a document?
- A. The owner of the document
- B. The manager of the owner of the document
- C. The administrator of the document
- D. The author of the document
Answer: A
NEW QUESTION 46
In order to take out a fire insurance policy, an administration office must determine the value of the data that it manages.
Which factor is [b]not[/b] important for determining the value of data for an organization?
- A. The content of data.
- B. The degree to which missing, incomplete or incorrect data can be recovered.
- C. The importance of the business processes that make use of the data.
- D. The indispensability of data for the business processes.
Answer: A
NEW QUESTION 47
Which of the following is an information security management system standard published by the International Organization for Standardization?
- A. ISO27001
- B. ISO22301
- C. ISO5501
- D. ISO9008
Answer: A
NEW QUESTION 48
What is the standard definition of ISMS?
- A. A company wide business objectives to achieve information security awareness for establishing, implementing, operating, monitoring, reviewing, maintaining and improving
- B. Is an information security systematic approach to achieve business objectives for implementation, establishing, reviewing,operating and maintaining organization's reputation.
- C. A systematic approach for establishing, implementing, operating,monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives.
- D. A project-based approach to achieve business objectives for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security
Answer: C
NEW QUESTION 49
Someone from a large tech company calls you on behalf of your company to check the health of your PC, and therefore needs your user-id and password. What type of threat is this?
- A. Social engineering threat
- B. Malware threat
- C. Organisational threat
- D. Technical threat
Answer: A
NEW QUESTION 50
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself.
You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
NEW QUESTION 51
......
PECB Certified ISO/IEC 27001 Lead Auditor exam Free Update With 100% Exam Passing Guarantee: https://www.passleadervce.com/ISO-27001/reliable-ISO-IEC-27001-Lead-Auditor-exam-learning-guide.html
Real Exam Questions & Answers - PECB ISO-IEC-27001-Lead-Auditor Dump is Ready: https://drive.google.com/open?id=1xZ1YiWzt6Ff_9f_u81vRlvEY-eqP08-r