[Jul-2022] ISO-ISMS-LA exam torrent GAQM study guide [Q16-Q34]

Share

[Jul-2022] ISO-ISMS-LA exam torrent GAQM study guide

Use Valid New ISO-ISMS-LA Test Notes & ISO-ISMS-LA Valid Exam Guide

NEW QUESTION 16
Phishing is what type of Information Security Incident?

  • A. Legal Incidents
  • B. Cracker/Hacker Attacks
  • C. Private Incidents
  • D. Technical Vulnerabilities

Answer: B

 

NEW QUESTION 17
The computer room is protected by a pass reader. Only the System Management department has a pass.
What type of security measure is this?

  • A. a corrective security measure
  • B. a physical security measure
  • C. a repressive security measure
  • D. a logical security measure

Answer: B

 

NEW QUESTION 18
Which measure is a preventive measure?

  • A. Shutting down all internet traffic after a hacker has gained access to the company systems
  • B. Installing a logging system that enables changes in a system to be recognized
  • C. Putting sensitive information in a safe

Answer: C

 

NEW QUESTION 19
What is the relationship between data and information?

  • A. Data is structured information.
  • B. Information is the meaning and value assigned to a collection of data.

Answer: B

 

NEW QUESTION 20
What is an example of a human threat?

  • A. thunderstrom
  • B. a lightning strike
  • C. fire
  • D. phishing

Answer: D

 

NEW QUESTION 21
What is the worst possible action that an employee may receive for sharing his or her password or access with others?

  • A. Forced roll off from the project
  • B. Termination
  • C. The lowest rating on his or her performance assessment
  • D. Three days suspension from work

Answer: B

 

NEW QUESTION 22
In order to take out a fire insurance policy, an administration office must determine the value of the data that it manages.
Which factor is [b]not[/b] important for determining the value of data for an organization?

  • A. The degree to which missing, incomplete or incorrect data can be recovered.
  • B. The content of data.
  • C. The importance of the business processes that make use of the data.
  • D. The indispensability of data for the business processes.

Answer: B

 

NEW QUESTION 23
A hacker gains access to a web server and reads the credit card numbers stored on that server. Which security principle is violated?

  • A. Integrity
  • B. Authenticity
  • C. Availability
  • D. Confidentiality

Answer: D

 

NEW QUESTION 24
Why do we need to test a disaster recovery plan regularly, and keep it up to date?

  • A. Otherwise the measures taken and the incident procedures planned may not be adequate
  • B. Otherwise remotely stored backups may no longer be available to the security team
  • C. Otherwise it is no longer up to date with the registration of daily occurring faults

Answer: A

 

NEW QUESTION 25
Which of the following is a preventive security measure?

  • A. Shutting down the Internet connection after an attack
  • B. Storing sensitive information in a data save
  • C. Installing logging and monitoring software

Answer: B

 

NEW QUESTION 26
Which is the glue that ties the triad together

  • A. Process
  • B. People
  • C. Technology
  • D. Collaboration

Answer: A

 

NEW QUESTION 27
A hacker gains access to a webserver and can view a file on the server containing credit card numbers.
Which of the Confidentiality, Integrity, Availability (CIA) principles of the credit card file are violated?

  • A. Integrity
  • B. Availability
  • C. Compliance
  • D. Confidentiality

Answer: D

 

NEW QUESTION 28
An administration office is going to determine the dangers to which it is exposed.
What do we call a possible event that can have a disruptive effect on the reliability of information?

  • A. vulnerability
  • B. dependency
  • C. risk
  • D. threat

Answer: D

 

NEW QUESTION 29
You are the lead auditor of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks.
What is this risk strategy called?

  • A. Risk skipping
  • B. Risk avoidance
  • C. Risk bearing
  • D. Risk neutral

Answer: C

 

NEW QUESTION 30
Integrity of data means

  • A. Accuracy and completeness of the data
  • B. Data should be accessed by only the right people
  • C. Data should be viewable at all times

Answer: A

 

NEW QUESTION 31
Backup media is kept in the same secure area as the servers. What risk may the organisation be exposed to?

  • A. After a fire, the information systems cannot be restored
  • B. Responsibility for the backups is not defined well
  • C. After a server crash, it will take extra time to bring it back up again
  • D. Unauthorised persons will have access to both the servers and backups

Answer: A

 

NEW QUESTION 32
Which is not a requirement of HR prior to hiring?

  • A. Applicant must complete pre-employment documentation requirements
  • B. Must undergo Awareness training on information security.
  • C. Must successfully pass Background Investigation
  • D. Undergo background verification

Answer: B

 

NEW QUESTION 33
What would be the reference for you to know who should have access to data/document?

  • A. Access Control List (ACL)
  • B. Data Classification Label
  • C. Information Rights Management (IRM)
  • D. Masterlist of Project Records (MLPR)

Answer: A

 

NEW QUESTION 34
......

ISO-ISMS-LA Exam questions and answers: https://prepaway.testinsides.top/ISO-ISMS-LA-dumps-review.html