
New 2022 Realistic Free PECB ISO-IEC-27001-Lead-Auditor Exam Dump Questions and Answer
ISO-IEC-27001-Lead-Auditor Practice Test Engine: Try These 99 Exam Questions
NEW QUESTION 27
A hacker gains access to a web server and reads the credit card numbers stored on that server. Which security principle is violated?
- A. Authenticity
- B. Confidentiality
- C. Integrity
- D. Availability
Answer: B
NEW QUESTION 28
What is the relationship between data and information?
- A. Data is structured information.
- B. Information is the meaning and value assigned to a collection of data.
Answer: B
NEW QUESTION 29
Which threat could occur if no physical measures are taken?
- A. Confidential prints being left on the printer
- B. Hackers entering the corporate network
- C. Unauthorised persons viewing sensitive files
- D. A server shutting down because of overheating
Answer: D
NEW QUESTION 30
Which measure is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Shutting down all internet traffic after a hacker has gained access to the company systems
Answer: A
NEW QUESTION 31
An employee caught with offense of abusing the internet, such as P2P file sharing or video/audio streaming, will not receive a warning for committing such act but will directly receive an IR.
- A. True
- B. False
Answer: A
NEW QUESTION 32
You are the lead auditor of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks.
What is this risk strategy called?
- A. Risk bearing
- B. Risk neutral
- C. Risk skipping
- D. Risk avoidance
Answer: A
NEW QUESTION 33
What is social engineering?
- A. Creating a situation wherein a third party gains confidential information from you
- B. A group planning for a social activity in the organization
- C. The organization planning an activity for welfare of the neighborhood
Answer: A
NEW QUESTION 34
In acceptable use of Information Assets, which is the best practice?
- A. Accessing phone or network transmissions, including wireless or wifi transmissions
- B. Access to information and communication systems are provided for business purpose only
- C. Playing any computer games during office hours
- D. Interfering with or denying service to any user other than the employee's host
Answer: B
NEW QUESTION 35
What is a reason for the classification of information?
- A. Creating a manual describing the BYOD policy
- B. To provide clear identification tags
- C. To structure the information according to its sensitivity
Answer: C
NEW QUESTION 36
What is the purpose of an Information Security policy?
- A. An information security policy provides insight into threats and the possible consequences
- B. An information security policy provides direction and support to the management regarding information security
- C. An information security policy documents the analysis of risks and the search for countermeasures
- D. An information security policy makes the security plan concrete by providing the necessary details
Answer: B
NEW QUESTION 37
We can leave laptops during weekdays or weekends in locked bins.
- A. False
- B. True
Answer: A
NEW QUESTION 38
What controls can you do to protect sensitive data in your computer when you go out for lunch?
- A. You are confident to leave your computer screen as is since a password protected screensaver is installed and it is set to activate after 10 minutes of inactivity
- B. You activate your favorite screen-saver
- C. You lock your computer by pressing Windows+L or CTRL-ALT-DELETE and then click "Lock Computer".
- D. You turn off the monitor
Answer: C
NEW QUESTION 39
Information Security is a matter of building and maintaining ________ .
- A. Confidentiality
- B. Protection
- C. Trust
- D. Firewalls
Answer: C
NEW QUESTION 40
What would be the reference for you to know who should have access to data/document?
- A. Access Control List (ACL)
- B. Data Classification Label
- C. Masterlist of Project Records (MLPR)
- D. Information Rights Management (IRM)
Answer: A
NEW QUESTION 41
Who is authorized to change the classification of a document?
- A. The administrator of the document
- B. The author of the document
- C. The manager of the owner of the document
- D. The owner of the document
Answer: D
NEW QUESTION 42
Which of the following is not a type of Information Security attack?
- A. Legal Incidents
- B. Vehicular Incidents
- C. Privacy Incidents
- D. Technical Vulnerabilities
Answer: B
NEW QUESTION 43
The following are purposes of Information Security, except:
- A. Increase Business Assets
- B. Ensure Business Continuity
- C. Maximize Return on Investment
- D. Minimize Business Risk
Answer: A
NEW QUESTION 44
An administration office is going to determine the dangers to which it is exposed.
What do we call a possible event that can have a disruptive effect on the reliability of information?
- A. vulnerability
- B. threat
- C. dependency
- D. risk
Answer: B
NEW QUESTION 45
What is the difference between a restricted and confidential document?
- A. Restricted - to be shared among named individuals
Confidential - to be shared among an authorized group - B. Restricted - to be shared among named individuals
Confidential - to be shared across the organization only - C. Restricted - to be shared among named individuals
Confidential - to be shared with friends and family - D. Restricted - to be shared among an authorized group
Confidential - to be shared among named individuals
Answer: A
NEW QUESTION 46
......
Guaranteed Success in ISO 27001 ISO-IEC-27001-Lead-Auditor Exam Dumps: https://www.testkingit.com/PECB/latest-ISO-IEC-27001-Lead-Auditor-exam-dumps.html
PECB ISO-IEC-27001-Lead-Auditor Daily Practice Exam New 2022 Updated 99 Questions: https://drive.google.com/open?id=1C1Uf-Z7XtwDrgDS0g4axZ4-FdYNPkIIM