合格できるPECB ISO-IEC-27001-Lead-AuditorのPDF問題集!最近更新された140問あります [Q55-Q79]

Share

合格できるPECB ISO-IEC-27001-Lead-AuditorのPDF問題集!最近更新された140問あります

更新されたテストエンジンISO-IEC-27001-Lead-Auditor練習問題集と練習試験合格させます


PECB ISO-IEC-27001-LEAD-AUDITOR試験は、ISO/IEC 27001の主任監査人になりたい個人にとって優れた認定です。この認定は世界的に認識されており、雇用主によって高く評価されています。これは、個人が組織のISMを効果的に監査し、ISO/IEC 27001標準に準拠していることを保証するために必要なスキルと知識を開発できるように設計されています。この認定は、リスク管理、情報セキュリティ管理、監査手法など、さまざまなトピックをカバーしており、複数の言語で利用できます。


この認証プログラムは、情報セキュリティ管理システムと監査原則を深く理解している専門家を対象に設計されています。PECB ISO-IEC-27001-Lead-Auditor試験は、情報セキュリティ管理システムの標準、監査技術、リスク管理、法的および規制要件の遵守など、様々なトピックをカバーしています。試験では、ISO/IEC 27001標準に従ってISMSの監査を計画、実施、報告、およびフォローアップする能力も試されます。

 

質問 # 55
In order to take out a fire insurance policy, an administration office must determine the value of the data that it manages.
Which factor is [b]not[/b] important for determining the value of data for an organization?

  • A. The indispensability of data for the business processes.
  • B. The importance of the business processes that make use of the data.
  • C. The degree to which missing, incomplete or incorrect data can be recovered.
  • D. The content of data.

正解:D


質問 # 56
Select a word from the following options that best completes the sentence:
To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

正解:

解説:


質問 # 57
Below is Purpose of "Integrity", which is one of the Basic Components of Information Security

  • A. the property of safeguarding the accuracy and completeness of assets.
  • B. the property that information is not made available or disclosed to unauthorized individuals
  • C. the property that information is not made available or disclosed to unauthorized individuals
  • D. the property of being accessible and usable upon demand by an authorized entity.

正解:A


質問 # 58
Which two of the following statements are true?

  • A. As part of a certification body audit the auditor is resporable for verifying the organisation's legal compliance status
  • B. The role of a certification body auditor involves evaluating the organisation's processes for ensuring compliance with their legal requirements
  • C. Curing a third-party audit, the auditor evaluates how the organisation ensures that 4 6 made aware of changes to the legal requirements

正解:B、C

解説:
The following statements are true:
The role of a certification body auditor involves evaluating the organization's processes for ensuring compliance with their legal requirements. This is part of the auditor's responsibility to assess the effectiveness and conformity of the organization's ISMS against the ISO/IEC 27001:2022 standard and the applicable legal and regulatory requirements.
During a third-party audit, the auditor evaluates how the organization ensures that they are made aware of changes to the legal requirements. This is part of the auditor's responsibility to verify that the organization has established and maintained a process for identifying and updating their legal and other requirements related to information security. The following statement is false:
As part of a certification body audit, the auditor is responsible for verifying the organization's legal compliance status. This is not true, as the auditor is not authorized or qualified to provide legal advice or judgment on the organization's compliance status. The auditor can only report on the evidence of compliance or noncompliance observed during the audit, but the ultimate responsibility for ensuring legal compliance lies with the organization. Reference: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 66. : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 67. : ISO/IEC 27001 LEAD AUDITOR - PECB, page 22.


質問 # 59
Which is the glue that ties the triad together

  • A. Collaboration
  • B. Process
  • C. People
  • D. Technology

正解:D

解説:
The triad refers to the three elements of information security: confidentiality, integrity and availability3. Technology is the glue that ties the triad together, as it provides the means to implement various controls and measures to protect information from unauthorized access, modification or loss3. Reference: ISO/IEC 27001:2022 Lead Auditor Training Course - BSI


質問 # 60
Which threat could occur if no physical measures are taken?

  • A. Hackers entering the corporate network
  • B. Confidential prints being left on the printer
  • C. Unauthorised persons viewing sensitive files
  • D. A server shutting down because of overheating

正解:D


質問 # 61
Information or data that are classified as ______ do not require labeling.

  • A. Confidential
  • B. Internal
  • C. Public
  • D. Highly Confidential

正解:C

解説:
Information or data that are classified as public do not require labeling. Public information or data are those that are intended for general disclosure and have no impact on the organization's operations or reputation if disclosed. Labeling is a method of implementing classification, which is a process of structuring information according to its sensitivity and value for the organization. Labeling helps to identify the level of protection and handling required for each type of information. Information or data that are classified as internal, confidential, or highly confidential require labeling, as they contain information that is not suitable for public disclosure and may cause harm or loss to the organization if disclosed. Reference: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 34. : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 37. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 14.


質問 # 62
What is the name of the system that guarantees the coherence of information security in the organization?

  • A. Rootkit
  • B. Information Security Management System (ISMS)
  • C. Security regulations for special information for the government
  • D. Information Technology Service Management (ITSM)

正解:B


質問 # 63
You have a hard copy of a customer design document that you want to dispose off. What would you do

  • A. Shred it using a shredder
  • B. Throw it in any dustbin
  • C. Give it to the office boy to reuse it for other purposes
  • D. Be environment friendly and reuse it for writing

正解:A


質問 # 64
What type of system ensures a coherent Information Security organisation?

  • A. Information Exchange Data System (IEDS)
  • B. Information Security Management System (ISMS)
  • C. Information Technology Service Management System (ITSM)
  • D. Federal Information Security Management Act (FISMA)

正解:B


質問 # 65
A property of Information that has the ability to prove occurrence of a claimed event.

  • A. Electronic chain letters
  • B. Availability
  • C. Accessibility
  • D. Integrity

正解:D

解説:
A property of information that has the ability to prove occurrence of a claimed event is integrity. Integrity is one of the three main objectives of information security, along with confidentiality and availability. Integrity ensures that information and systems are not corrupted, modified, or deleted by unauthorized actions or events. Integrity also implies that information and systems can be verified and validated as authentic and accurate. Electronic chain letters are not a property of information, but a type of spam or hoax message that may contain malicious or misleading content. Availability means that service should be accessible at the required time and usable only by the authorized entity. Accessibility is not a property of information, but a characteristic of usability that refers to how easy it is for users to access and interact with information and systems. Reference: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 24. : [ISO/IEC 27001 Brochures | PECB], page 4. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 13.


質問 # 66
What is the name of the system that guarantees the coherence of information security in the organization?

  • A. Rootkit
  • B. Information Security Management System (ISMS)
  • C. Security regulations for special information for the government
  • D. Information Technology Service Management (ITSM)

正解:B

解説:
The name of the system that guarantees the coherence of information security in the organization is Information Security Management System (ISMS). An ISMS is a systematic approach to managing the confidentiality, integrity and availability of information and information assets. An ISMS includes policies, procedures, processes, roles, responsibilities, resources and performance measures that enable the organization to achieve its information security objectives. An ISMS also includes a risk assessment and treatment process that identifies and addresses the information security risks faced by the organization. ISO/IEC 27001:2022 specifies the requirements for establishing, implementing, maintaining and continually improving an ISMS within the context of the organization (see clause 1). Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course, ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is ISMS?


質問 # 67
What type of legislation requires a proper controlled purchase process?

  • A. Computer criminality act
  • B. Personal data protection act
  • C. Intellectual property rights act
  • D. Government information act

正解:C


質問 # 68
A member of staff denies sending a particular message.
Which reliability aspect of information is in danger here?

  • A. integrity
  • B. availability
  • C. confidentiality
  • D. correctness

正解:A

解説:
The reliability aspect of information that is in danger when a member of staff denies sending a particular message is integrity. Integrity implies that information is authentic and can be verified as such. If a member of staff denies sending a message, it means that either the message was forged or the sender is lying, both of which violate the integrity of the information. Availability, correctness and confidentiality are not directly affected by this scenario. ISO/IEC 27001:2022 defines integrity as "property of accuracy and completeness" (see clause 3.24). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Integrity?


質問 # 69
A member of staff denies sending a particular message.
Which reliability aspect of information is in danger here?

  • A. integrity
  • B. availability
  • C. confidentiality
  • D. correctness

正解:A


質問 # 70
Which two activities align with the "Check'' stage of the Plan-Do-Check-Act cycle when applied to the process of managing an internal audit program as described in ISO 19011?

  • A. Retains records of internal audits
  • B. Define audit criteria and scope for each internal audit
  • C. Review trends in internal audit result
  • D. Conduct internal audits
  • E. Verify effectiveness of the internal audit programme
  • F. Establish a risk-based internal audit programme
  • G. Update the internal audit programme

正解:C、E

解説:
The Check stage of the PDCA cycle involves monitoring and measuring the performance of the process and comparing it with the planned objectives and criteria. In the context of managing an internal audit programme, this stage includes verifying the effectiveness of the internal audit programme by evaluating whether it meets its objectives, scope, and criteria, and whether it is implemented in accordance with ISO 19011 guidelines1. It also includes reviewing the trends in internal audit results by analyzing the data collected from the audits, such as audit findings, nonconformities, corrective actions, opportunities for improvement, and customer feedback1. Reference: ISO 19011:2018 - Guidelines for auditing management systems


質問 # 71
What is a repressive measure in case of a fire?

  • A. Putting out a fire after it has been detected by a fire detector
  • B. Taking out a fire insurance
  • C. Repairing damage caused by the fire

正解:A


質問 # 72
Which department maintain's contacts with law enforcement authorities, regulatory bodies, information service providers and telecommunications service providers depending on the service required.

  • A. CISO
  • B. COO
  • C. CSM
  • D. MRO

正解:A


質問 # 73
All are prohibited in acceptable use of information assets, except:

  • A. Electronic chain letters
  • B. Company-wide e-mails with supervisor/TL permission.
  • C. Messages with very large attachments or to a large number ofrecipients.
  • D. E-mail copies to non-essential readers

正解:B

解説:
The only option that is not prohibited in acceptable use of information assets is C: company-wide e-mails with supervisor/TL permission. This option implies that the sender has obtained the necessary authorization from their supervisor or team leader to send an e-mail to all employees in the organization. This could be done for legitimate business purposes, such as announcing important news, events or updates that are relevant to everyone. However, this option should still be used sparingly and responsibly, as it could cause unnecessary disruption or annoyance to the recipients if abused or misused. The other options are prohibited in acceptable use of information assets, as they could violate the information security policies and procedures of the organization, as well as waste resources and bandwidth. Electronic chain letters (A) are messages that urge recipients to forward them to multiple other people, often with false or misleading claims or promises. They are considered spam and could contain malicious links or attachments that could compromise information security. E-mail copies to non-essential readers (B) are messages that are sent to recipients who do not need to receive them or have no interest in them. They are considered unnecessary and could clutter the inbox and distract the recipients from more important messages. Messages with very large attachments or to a large number of recipients (D) are messages that consume a lot of network resources and could affect the performance or availability of the information systems. They could also exceed the storage capacity or quota limits of the recipients' mailboxes and cause problems for them. ISO/IEC 27001:2022 requires the organization to implement rules for acceptable use of assets (see clause A.8.1.3). Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course, ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Acceptable Use?


質問 # 74
Which of the following is a technical security measure?

  • A. User role profiles.
  • B. Security policy
  • C. Safe storage of backups
  • D. Encryption

正解:D

解説:
A technical security measure is a measure that uses technology to protect information assets from unauthorized access, modification, disclosure, or destruction. Examples of technical security measures include encryption, firewalls, antivirus software, authentication systems, and access control mechanisms. Encryption is a technical security measure that transforms information into an unreadable format using a secret key or algorithm. Encryption protects the confidentiality, integrity, and availability of information by preventing unauthorized parties from accessing or altering it. Therefore, encryption is the correct answer to this question. Reference: ISO/IEC 27000:2022, clause 3.48; ISO/IEC 27002:2022, clause 10.1.


質問 # 75
During discussions with the individual(s) managing the audit programme of a certification body, the Management System Representative of the client organisation asks for a specific auditor for the certification audit. Select two of the following options for how the individual(s) managing the audit programme should respond.

  • A. Advise the Management System Representative that the audit team selection is a decision that the audit programme manager needs to make based on the resources available
  • B. Suggest asking the certification body management to permit the request
  • C. Advise the Management System Representative that his request can be accepted
  • D. State that his request will be considered but may not be taken up
  • E. Suggest that the Management System Representative chooses another certification body

正解:A、D

解説:
According to ISO/IEC 17021-1, which specifies the requirements for bodies providing audit and certification of management systems, a certification body should ensure that its auditors are competent, impartial, and independent from the auditee organization2. Therefore, if a Management System Representative of a client organization asks for a specific auditor for the certification audit, the individual(s) managing the audit programme should respond in a way that does not compromise these principles or create any conflict of interest or undue influence2. Two possible ways to respond are to state that his request will be considered but may not be taken up, as there may be other factors that affect the auditor selection process; or to advise him that the audit team selection is a decision that the audit programme manager needs to make based on the resources available, such as auditor availability, competence, location, etc2. The other options are not suitable ways to respond in this situation. For example, advising him that his request can be accepted may raise doubts about the objectivity and credibility of the auditor and the certification body; suggesting that he chooses another certification body may imply that his request is unreasonable or unethical; and suggesting asking the certification body management to permit his request may suggest that there is room for negotiation or manipulation in auditor selection2. Reference: ISO/IEC 17021-1:2015 - Conformity assessment - Requirements for bodies providing audit and certification of management systems - Part 1: Requirements


質問 # 76
What controls can you do to protect sensitive data in your computer when you go out for lunch?

  • A. You activate your favorite screen-saver
  • B. You are confident to leave your computer screen as is since a password protected screensaver is installed and it is set to activate after 10 minutes of inactivity
  • C. You turn off the monitor
  • D. You lock your computer by pressing Windows+L or CTRL-ALT-DELETE and then click "Lock Computer".

正解:D


質問 # 77
How is the purpose of information security policy best described?

  • A. An information security policy documents the analysis of risks and the search for countermeasures.
  • B. An information security policy provides direction and support to the management regarding information security.
  • C. An information security policy makes the security plan concrete by providing it with the necessary details.
  • D. An information security policy provides insight into threats and the possible consequences.

正解:B


質問 # 78
Which is not a requirement of HR prior to hiring?

  • A. Applicant must complete pre-employment documentation requirements
  • B. Must undergo Awareness training on information security.
  • C. Undergo background verification
  • D. Must successfully pass Background Investigation

正解:B

解説:
According to ISO/IEC 27001:2022, clause 7.2.2, the organization shall ensure that all persons who have access to information are aware of the information security policy and their contribution to the effectiveness of the ISMS, including the benefits of improved information security performance2. Therefore, awareness training on information security is a requirement for all persons, not just new hires. Reference: ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) | CQI | IRCA


質問 # 79
......

PECB ISO-IEC-27001-Lead-Auditor問題集でカバー率リアル試験問題:https://www.jpntest.com/shiken/ISO-IEC-27001-Lead-Auditor-mondaishu

問題集お試しセットISO-IEC-27001-Lead-Auditorテストエンジン問題集トレーニングには140問あります:https://drive.google.com/open?id=1GhxXqR-oOrRIYg4_abxHTmG7sJE5lNgN

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡