
Get 100% Passing Success With True ISO27-13-001 Exam! [Oct-2021]
GAQM ISO27-13-001 PDF Questions - Exceptional Practice To ISO 27001 : 2013 - Certified Lead Auditor
NEW QUESTION 23
You see a blue color sticker on certain physical assets. What does this signify?
- A. The asset with blue stickers should be kept air conditioned at all times
- B. The asset is high critical and its failure will affect a group/s/project's work in the organization
- C. The asset is very high critical and its failure affects the entire organization
- D. The asset is critical and the impact is restricted to an employee only
Answer: B
NEW QUESTION 24
What is the purpose of an Information Security policy?
- A. An information security policy provides direction and support to the management regarding information security
- B. An information security policy provides insight into threats and the possible consequences
- C. An information security policy makes the security plan concrete by providing the necessary details
- D. An information security policy documents the analysis of risks and the search for countermeasures
Answer: A
NEW QUESTION 25
What type of compliancy standard, regulation or legislation provides a code of practice for information security?
- A. ISO/IEC 27002
- B. Computer criminality act
- C. Personal data protection act
- D. IT Service Management
Answer: A
NEW QUESTION 26
In what part of the process to grant access to a system does the user present a token?
- A. Verification
- B. Authorisation
- C. Authentication
- D. Identification
Answer: D
NEW QUESTION 27
What is the goal of classification of information?
- A. Structuring information according to its sensitivity
- B. Applying labels making the information easier to recognize
- C. To create a manual about how to handle mobile devices
Answer: A
NEW QUESTION 28
Implement plan on a test basis - this comes under which section of PDCA
- A. Plan
- B. Do
- C. Check
- D. Act
Answer: B
NEW QUESTION 29
How is the purpose of information security policy best described?
- A. An information security policy makes the security plan concrete by providing it with the necessary details.
- B. An information security policy provides insight into threats and the possible consequences.
- C. An information security policy documents the analysis of risks and the search for countermeasures.
- D. An information security policy provides direction and support to the management regarding information security.
Answer: D
NEW QUESTION 30
Backup media is kept in the same secure area as the servers. What risk may the organisation be exposed to?
- A. Responsibility for the backups is not defined well
- B. After a server crash, it will take extra time to bring it back up again
- C. Unauthorised persons will have access to both the servers and backups
- D. After a fire, the information systems cannot be restored
Answer: D
NEW QUESTION 31
Phishing is what type of Information Security Incident?
- A. Legal Incidents
- B. Private Incidents
- C. Technical Vulnerabilities
- D. Cracker/Hacker Attacks
Answer: D
NEW QUESTION 32
A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:
- A. Greet and ask him what is his business
- B. Escort him to his destination
- C. Say "hi" and offer coffee
- D. Call the receptionist and inform about the visitor
Answer: C
NEW QUESTION 33
There is a scheduled fire drill in your facility. What should you do?
- A. Excuse yourself by saying you have an urgent deliverable
- B. Call in sick
- C. None of the above
- D. Participate in the drill
Answer: D
NEW QUESTION 34
Cabling Security is associated with Power, telecommunication and network cabling carrying information are protected from interception and damage.
- A. True
- B. False
Answer: A
NEW QUESTION 35
A property of Information that has the ability to prove occurrence of a claimed event.
- A. Availability
- B. Integrity
- C. Accessibility
- D. Electronic chain letters
Answer: B
NEW QUESTION 36
Which threat could occur if no physical measures are taken?
- A. Confidential prints being left on the printer
- B. Hackers entering the corporate network
- C. Unauthorised persons viewing sensitive files
- D. A server shutting down because of overheating
Answer: D
NEW QUESTION 37
What controls can you do to protect sensitive data in your computer when you go out for lunch?
- A. You turn off the monitor
- B. You lock your computer by pressing Windows+L or CTRL-ALT-DELETE and then click "Lock Computer".
- C. You activate your favorite screen-saver
- D. You are confident to leave your computer screen as is since a password protected screensaver is installed and it is set to activate after 10 minutes of inactivity
Answer: B
NEW QUESTION 38
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password.
What kind of threat is this?
- A. Organizational threat
- B. Social Engineering
- C. Arason
- D. Natural threat
Answer: B
NEW QUESTION 39
__________ is a software used or created by hackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems.
- A. Malware
- B. Trojan
- C. Operating System
- D. Virus
Answer: A
NEW QUESTION 40
In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:
- A. Report suspected or known incidents upon discovery through the Servicedesk
- B. Make the information security incident details known to all employees
- C. Cooperate with investigative personnel during investigation if needed
- D. Preserve evidence if necessary
Answer: B
NEW QUESTION 41
Which is the glue that ties the triad together
- A. Process
- B. Collaboration
- C. People
- D. Technology
Answer: A
NEW QUESTION 42
What is we do in ACT - From PDCA cycle
- A. Take actions to continually monitor process performance
- B. Take actions to continually improve people performance
- C. Take actions to continually monitor process performance
- D. Take actions to continually improve process performance
Answer: D
NEW QUESTION 43
Why do we need to test a disaster recovery plan regularly, and keep it up to date?
- A. Otherwise remotely stored backups may no longer be available to the security team
- B. Otherwise the measures taken and the incident procedures planned may not be adequate
- C. Otherwise it is no longer up to date with the registration of daily occurring faults
Answer: B
NEW QUESTION 44
Stages of Information
- A. creation, evolution, maintenance, use, disposition
- B. creation, distribution, maintenance, disposition, use
- C. creation, use, disposition, maintenance, evolution
- D. creation, distribution, use, maintenance, disposition
Answer: D
NEW QUESTION 45
Someone from a large tech company calls you on behalf of your company to check the health of your PC, and therefore needs your user-id and password. What type of threat is this?
- A. Social engineering threat
- B. Malware threat
- C. Organisational threat
- D. Technical threat
Answer: A
NEW QUESTION 46
What is the worst possible action that an employee may receive for sharing his or her password or access with others?
- A. Three days suspension from work
- B. Termination
- C. Forced roll off from the project
- D. The lowest rating on his or her performance assessment
Answer: B
NEW QUESTION 47
A scenario wherein the city or location where the building(s) reside is / are not accessible.
- A. Facility
- B. Component
- C. Country
- D. City
Answer: D
NEW QUESTION 48
......
ISO27-13-001 dumps - Real4Prep - 100% Passing Guarantee: https://www.real4prep.com/ISO27-13-001-exam.html