
Free 2021 GAQM certification ISO-IEC-LI dumps are available on Google Drive shared by TestPassKing
Welcome to download the newest TestPassKing ISO-IEC-LI PDF dumps: https://www.testpassking.com/ISO-IEC-LI-exam-testking-pass.html ( 50 Q&As)
NEW QUESTION 15
Of the following, which is the best organization or set of organizations to contribute to compliance?
- A. IT only
- B. IT, business management, HR and legal
- C. IT and legal
- D. IT and management
Answer: B
NEW QUESTION 16
Prior to employment, _________ as well as terms & conditions of employment are included as controls in ISO
27002 to ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.
- A. authorizing
- B. screening
- C. controlling
- D. flexing
Answer: B
NEW QUESTION 17
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the same access as the passes of the company's staff. Which kind of security measure could have prevented this?
- A. A technical security measure
- B. physical security measure
- C. An organizational security measure
Answer: B
NEW QUESTION 18
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
- A. Availability, Information Value and Confidentiality
- B. Availability, Integrity and Completeness
- C. Timeliness, Accuracy and Completeness
- D. Availability, Integrity and Confidentiality
Answer: D
NEW QUESTION 19
Which of the following measures is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
- D. Shutting down all internet traffic after a hacker has gained access to the company systems
Answer: A
NEW QUESTION 20
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. Encryption of information
- B. Validation of input and output data in applications
- C. The use of tokens to gain access to information systems
- D. Information Security Management System
Answer: D
NEW QUESTION 21
Why is compliance important for the reliability of the information?
- A. By meeting the legislative requirements and the regulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
- B. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- C. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and therefore it guarantees the reliability of its information.
Answer: A
NEW QUESTION 22
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. If the risk analysis has not been carried out.
- B. When the organization is located near a river.
- C. When the computer systems are not insured.
- D. When computer systems are kept in a cellar below ground level.
Answer: D
NEW QUESTION 23
What is the best way to comply with legislation and regulations for personal data protection?
- A. Maintaining an incident register
- B. Appointing the responsibility to someone
- C. Performing a vulnerability analysis
- D. Performing a threat analysis
Answer: B
NEW QUESTION 24
What do employees need to know to report a security incident?
- A. Whether the incident has occurred before and what was the resulting damage.
- B. Who is responsible for the incident and whether it was intentional.
- C. How to report an incident and to whom.
- D. The measures that should have been taken to prevent the incident in the first place.
Answer: C
NEW QUESTION 25
What is the greatest risk for an organization if no information security policy has been defined?
- A. It is not possible for an organization to implement information security in a consistent manner.
- B. Information security activities are carried out by only a few people.
- C. Too many measures are implemented.
- D. If everyone works with the same account, it is impossible to find out who worked on what.
Answer: A
NEW QUESTION 26
Responsibilities for information security in projects should be defined and allocated to:
- A. the owner of the involved asset
- B. the project manager
- C. the InfoSec officer
- D. specified roles defined in the used project management method of the organization
Answer: D
NEW QUESTION 27
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The person who drafted the insurance terms and conditions
- B. The manager, Linda
- C. The recipient, Rachel
- D. The sender, Peter
Answer: C
NEW QUESTION 28
What is the objective of classifying information?
- A. Displaying on the document who is permitted access
- B. Creating a label that indicates how confidential the information is
- C. Defining different levels of sensitivity into which information may be arranged
- D. Authorizing the use of an information system
Answer: C
NEW QUESTION 29
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?
- A. Radio Frequency Identification (RFID)
- B. The 4G protocol
- C. Bluetooth
- D. Near Field Communication (NFC)
Answer: D
NEW QUESTION 30
Who is accountable to classify information assets?
- A. the asset owner
- B. the CISO
- C. the CEO
- D. the Information Security Team
Answer: A
NEW QUESTION 31
What are the data protection principles set out in the GDPR?
- A. Purpose limitation, proportionality, availability, data minimisation
- B. Target group, proportionality, transparency, data minimisation
- C. Purpose limitation, proportionality, data minimisation, transparency
- D. Purpose limitation, pudicity, transparency, data minimisation
Answer: C
NEW QUESTION 32
Select the controls that correspond to the domain "9. ACCESS CONTROL" of ISO / 27002 (Choose three)
- A. Restriction of access to information
- B. Return of assets
- C. Withdrawal or adaptation of access rights
- D. Management of access rights with special privileges
Answer: A,B,C
NEW QUESTION 33
The identified owner of an asset is always an individual
- A. False
- B. True
Answer: A
NEW QUESTION 34
What is an example of a non-human threat to the physical environment?
- A. Storm
- B. Corrupted file
- C. Fraudulent transaction
- D. Virus
Answer: A
NEW QUESTION 35
......
Tested Material Used To ISO-IEC-LI: https://www.testpassking.com/ISO-IEC-LI-exam-testking-pass.html