
[Apr-2023] Verified PECB Exam Dumps with ISO-IEC-27001-Lead-Auditor Exam Study Guide
Best Quality PECB ISO-IEC-27001-Lead-Auditor Exam Questions Actual4Dumps Realistic Practice Exams [2023]
Achieving this certification can be beneficial for individuals who work in the field of information security or those who are looking to pursue a career as an ISMS auditor. It can also be valuable for organizations that want to ensure their information security management system is up to international standards and want to hire certified professionals to conduct their audits.
The PECB ISO-IEC-27001-Lead-Auditor certification is highly respected in the information security industry and is recognized globally as a mark of excellence. Professionals who hold this certification are in high demand, as they have demonstrated their ability to conduct effective ISMS audits and provide valuable insights into an organization's security posture. This certification is ideal for auditors, consultants, or security professionals who want to enhance their skills and advance their careers in the field of information security.
The PECB ISO-IEC-27001-Lead-Auditor certification exam is an internationally recognized exam that focuses on the auditing and management of information security systems. This certification is intended for professionals who are interested in auditing and assessing an organization's information security management system (ISMS) against the ISO/IEC 27001 standard.
NEW QUESTION # 41
Who is authorized to change the classification of a document?
- A. The administrator of the document
- B. The owner of the document
- C. The author of the document
- D. The manager of the owner of the document
Answer: B
NEW QUESTION # 42
In which order is an Information Security Management System set up?
- A. Implementation, operation, improvement, maintenance
- B. Establishment, operation, monitoring, improvement
- C. Implementation, operation, maintenance, establishment
- D. Establishment, implementation, operation, maintenance
Answer: D
NEW QUESTION # 43
Which department maintain's contacts with law enforcement authorities, regulatory bodies, information service providers and telecommunications service providers depending on the service required.
- A. CISO
- B. CSM
- C. MRO
- D. COO
Answer: A
NEW QUESTION # 44
A hacker gains access to a web server and reads the credit card numbers stored on that server. Which security principle is violated?
- A. Authenticity
- B. Integrity
- C. Confidentiality
- D. Availability
Answer: C
NEW QUESTION # 45
What is social engineering?
- A. Creating a situation wherein a third party gains confidential information from you
- B. A group planning for a social activity in the organization
- C. The organization planning an activity for welfare of the neighborhood
Answer: A
NEW QUESTION # 46
Someone from a large tech company calls you on behalf of your company to check the health of your PC, and therefore needs your user-id and password. What type of threat is this?
- A. Organisational threat
- B. Social engineering threat
- C. Technical threat
- D. Malware threat
Answer: B
NEW QUESTION # 47
Integrity of data means
- A. Data should be viewable at all times
- B. Accuracy and completeness of the data
- C. Data should be accessed by only the right people
Answer: B
NEW QUESTION # 48
What is the purpose of an Information Security policy?
- A. An information security policy provides direction and support to the management regarding information security
- B. An information security policy provides insight into threats and the possible consequences
- C. An information security policy documents the analysis of risks and the search for countermeasures
- D. An information security policy makes the security plan concrete by providing the necessary details
Answer: A
NEW QUESTION # 49
A fire breaks out in a branch office of a health insurance company. The personnel are transferred to neighboring branches to continue their work.
Where in the incident cycle is moving to a stand-by arrangements found?
- A. between recovery and threat
- B. between threat and incident
- C. between damage and recovery
- D. between incident and damage
Answer: D
NEW QUESTION # 50
There is a scheduled fire drill in your facility. What should you do?
- A. Participate in the drill
- B. None of the above
- C. Call in sick
- D. Excuse yourself by saying you have an urgent deliverable
Answer: A
NEW QUESTION # 51
Which threat could occur if no physical measures are taken?
- A. Hackers entering the corporate network
- B. A server shutting down because of overheating
- C. Unauthorised persons viewing sensitive files
- D. Confidential prints being left on the printer
Answer: B
NEW QUESTION # 52
You have a hard copy of a customer design document that you want to dispose off. What would you do
- A. Give it to the office boy to reuse it for other purposes
- B. Shred it using a shredder
- C. Be environment friendly and reuse it for writing
- D. Throw it in any dustbin
Answer: B
NEW QUESTION # 53
A well-executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives.
What is not one of the four main objectives of a risk analysis?
- A. Implementing counter measures
- B. Identifying assets and their value
- C. Determining relevant vulnerabilities and threats
- D. Establishing a balance between the costs of an incident and the costs of a security measure
Answer: A
NEW QUESTION # 54
What is the goal of classification of information?
- A. Applying labels making the information easier to recognize
- B. Structuring information according to its sensitivity
- C. To create a manual about how to handle mobile devices
Answer: B
NEW QUESTION # 55
You are the lead auditor of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks.
What is this risk strategy called?
- A. Risk skipping
- B. Risk avoidance
- C. Risk neutral
- D. Risk bearing
Answer: D
NEW QUESTION # 56
We can leave laptops during weekdays or weekends in locked bins.
- A. False
- B. True
Answer: A
NEW QUESTION # 57
What is a reason for the classification of information?
- A. To structure the information according to its sensitivity
- B. Creating a manual describing the BYOD policy
- C. To provide clear identification tags
Answer: A
NEW QUESTION # 58
In acceptable use of Information Assets, which is the best practice?
- A. Interfering with or denying service to any user other than the employee's host
- B. Access to information and communication systems are provided for business purpose only
- C. Accessing phone or network transmissions, including wireless or wifi transmissions
- D. Playing any computer games during office hours
Answer: B
NEW QUESTION # 59
Which of the following is a preventive security measure?
- A. Shutting down the Internet connection after an attack
- B. Storing sensitive information in a data save
- C. Installing logging and monitoring software
Answer: B
NEW QUESTION # 60
Often, people do not pick up their prints from a shared printer. How can this affect the confidentiality of information?
- A. Availability cannot be guaranteed
- B. Integrity cannot be guaranteed
- C. Confidentiality cannot be guaranteed
- D. Authenticity cannot be guaranteed
Answer: C
NEW QUESTION # 61
The computer room is protected by a pass reader. Only the System Management department has a pass.
What type of security measure is this?
- A. a physical security measure
- B. a repressive security measure
- C. a corrective security measure
- D. a logical security measure
Answer: A
NEW QUESTION # 62
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password.
What kind of threat is this?
- A. Natural threat
- B. Organizational threat
- C. Social Engineering
- D. Arason
Answer: C
NEW QUESTION # 63
What would be the reference for you to know who should have access to data/document?
- A. Data Classification Label
- B. Access Control List (ACL)
- C. Masterlist of Project Records (MLPR)
- D. Information Rights Management (IRM)
Answer: B
NEW QUESTION # 64
Changes to the information processing facilities shall be done in controlled manner.
- A. False
- B. True
Answer: B
NEW QUESTION # 65
Why do we need to test a disaster recovery plan regularly, and keep it up to date?
- A. Otherwise it is no longer up to date with the registration of daily occurring faults
- B. Otherwise the measures taken and the incident procedures planned may not be adequate
- C. Otherwise remotely stored backups may no longer be available to the security team
Answer: B
NEW QUESTION # 66
......
Authentic Best resources for ISO-IEC-27001-Lead-Auditor: https://www.actual4dumps.com/ISO-IEC-27001-Lead-Auditor-study-material.html
ISO-IEC-27001-Lead-Auditor Test Engine Practice Exam: https://drive.google.com/open?id=1VZGUsiW0J8BgXmmvw_7l_RTRkY7xu7SY