最新の[2023年12月19日]ISO-IEC-27001-Lead-Auditor試験問題集で有効で更新された問題集 [Q61-Q77]

Share

最新の[2023年12月19日]ISO-IEC-27001-Lead-Auditor試験問題集で有効で更新された問題集

無料お試しまもなく終了!100%有効なISO-IEC-27001-Lead-Auditor試験問題集には140問があります


PECB ISO-IEC-27001-Lead-Auditor認定試験は、ISO/IEC 27001標準に基づいたISMSの監査に関連する幅広いトピックをカバーしています。これらのトピックには、情報セキュリティ管理の原則と概念、ISO/IEC 27001標準の要件、監査プロセス、監査技術、報告とフォローアップが含まれます。候補者は、情報セキュリティ管理に関連する関連法規や規格についての知識も持っていることが期待されます。


PECB ISO-IEC-27001-Lead-Auditor試験は、ISO/IEC 27001標準に基づく情報セキュリティ管理システム(ISMS)の監査に熟練することを望むプロフェッショナル向けに設計された認定試験です。この試験は、監査を実施し、監査の結果を評価および分析し、改善のための推奨事項を提供する能力を示したい個人に最適です。


PECB ISO-IEC-27001-Lead-Auditor試験は、ISO/IEC 27001標準に基づく情報セキュリティ管理システム(ISMS)の監査における専門知識を証明したい専門家向けの認定資格です。この認定資格は、ISO標準と認定の分野でリーディングな組織であるProfessional Evaluation and Certification Board(PECB)によって提供されています。ISO-IEC-27001-Lead-Auditor認定資格は、監査人が組織のISMSの効果を評価し、改善すべき領域を特定するために必要な知識とスキルを備えていることを保証します。

 

質問 # 61
What is the name of the system that guarantees the coherence of information security in the organization?

  • A. Rootkit
  • B. Security regulations for special information for the government
  • C. Information Security Management System (ISMS)
  • D. Information Technology Service Management (ITSM)

正解:C


質問 # 62
Which of the following is not a type of Information Security attack?

  • A. Legal Incidents
  • B. Privacy Incidents
  • C. Vehicular Incidents
  • D. Technical Vulnerabilities

正解:C


質問 # 63
What is the relationship between data and information?

  • A. Data is structured information.
  • B. Information is the meaning and value assigned to a collection of data.

正解:B


質問 # 64
What is the purpose of an Information Security policy?

  • A. An information security policy documents the analysis of risks and the search for countermeasures
  • B. An information security policy makes the security plan concrete by providing the necessary details
  • C. An information security policy provides direction and support to the management regarding information security
  • D. An information security policy provides insight into threats and the possible consequences

正解:C


質問 # 65
The following are definitions of Information, except:

  • A. specific and organized data for a purpose
  • B. mature and measurable data
  • C. accurate and timely data
  • D. can lead to understanding and decrease in uncertainty

正解:B

解説:
The definition of information that is not correct is C: mature and measurable data. This is not a valid definition of information, as information does not have to be mature or measurable to be considered as such. Information can be any data that has meaning or value for someone or something in a certain context. Information can be subjective, qualitative, incomplete or uncertain, depending on how it is interpreted or used. Mature and measurable data are characteristics that may apply to some types of information, but not all. The other definitions of information are correct, as they describe different aspects of information, such as accuracy and timeliness (A), specificity and organization (B), and understanding and uncertainty reduction (D). ISO/IEC 27001:2022 defines information as "any data that has meaning" (see clause 3.25). Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course, ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Information?


質問 # 66
Which of the following is a possible event that can have a disruptive effect on the reliability of information?

  • A. Dependency
  • B. Vulnerability
  • C. Threat
  • D. Risk

正解:C

解説:
A possible event that can have a disruptive effect on the reliability of information is a threat. A threat is anything that has the potential to harm an asset or its protection, such as a natural disaster, a human error, a malicious attack, etc. A threat can exploit a vulnerability or weakness in an asset or its protection and cause an adverse impact on the confidentiality, integrity or availability of information. ISO/IEC 27001:2022 defines threat as "potential cause of an unwanted incident, which can result in harm to a system or organization" (see clause 3.48). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Threat?


質問 # 67
You are the lead auditor of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks.
What is this risk strategy called?

  • A. Risk bearing
  • B. Risk avoidance
  • C. Risk neutral
  • D. Risk skipping

正解:A

解説:
The risk strategy that involves taking measures for the large risks but not for the small risks is called risk bearing. Risk bearing is a strategy that accepts the existence of risks and their potential consequences without implementing any specific controls to reduce them. Risk bearing is usually applied to risks that have low likelihood and low impact, or when the cost of controls outweighs the benefits. Risk bearing implies that the organization has enough resources and resilience to cope with the risks if they materialize. ISO/IEC 27001:2022 defines risk acceptance as "decision to accept risk" (see clause 3.4). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, [What is Risk Bearing?]


質問 # 68
What type of system ensures a coherent Information Security organisation?

  • A. Information Exchange Data System (IEDS)
  • B. Information Technology Service Management System (ITSM)
  • C. Information Security Management System (ISMS)
  • D. Federal Information Security Management Act (FISMA)

正解:C


質問 # 69
What would be the reference for you to know who should have access to data/document?

  • A. Access Control List (ACL)
  • B. Data Classification Label
  • C. Information Rights Management (IRM)
  • D. Masterlist of Project Records (MLPR)

正解:A


質問 # 70
A planning process that introduced the concept of planning as a cycle that forms the basis for continuous improvement is called:

  • A. time based planning.
  • B. planning for continuous improvement.
  • C. plan, do, check, act.
  • D. RACI Matrix

正解:C

解説:
A planning process that introduced the concept of planning as a cycle that forms the basis for continuous improvement is called plan, do, check, act (PDCA). This is a widely used model for managing and improving processes and systems, and it is also the basis for the structure of ISO/IEC 27001:2022. The PDCA cycle consists of four phases: plan (establish objectives and processes), do (implement and operate), check (monitor and review), and act (maintain and improve). Reference: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 16. : ISO/IEC 27001:2022, clause 4.


質問 # 71
Information or data that are classified as ______ do not require labeling.

  • A. Highly Confidential
  • B. Internal
  • C. Confidential
  • D. Public

正解:D

解説:
Information or data that are classified as public do not require labeling. Public information or data are those that are intended for general disclosure and have no impact on the organization's operations or reputation if disclosed. Labeling is a method of implementing classification, which is a process of structuring information according to its sensitivity and value for the organization. Labeling helps to identify the level of protection and handling required for each type of information. Information or data that are classified as internal, confidential, or highly confidential require labeling, as they contain information that is not suitable for public disclosure and may cause harm or loss to the organization if disclosed. Reference: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 34. : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 37. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 14.


質問 # 72
Why do we need to test a disaster recovery plan regularly, and keep it up to date?

  • A. Otherwise the measures taken and the incident procedures planned may not be adequate
  • B. Otherwise it is no longer up to date with the registration of daily occurring faults
  • C. Otherwise remotely stored backups may no longer be available to the security team

正解:A


質問 # 73
A well-executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives.
What is not one of the four main objectives of a risk analysis?

  • A. Implementing counter measures
  • B. Identifying assets and their value
  • C. Establishing a balance between the costs of an incident and the costs of a security measure
  • D. Determining relevant vulnerabilities and threats

正解:A


質問 # 74
What is a definition of compliance?

  • A. A rule or directive made and maintained by an authority.
  • B. The state or fact of according with or meeting rules or standards
  • C. Laws, considered collectively or the process of making or enacting laws
  • D. An official or authoritative instruction

正解:B

解説:
Compliance is the state or fact of according with or meeting rules or standards1. In the context of information security, compliance means adhering to the applicable laws, regulations, policies, and contractual obligations that affect the organization's information assets2. Compliance is one of the objectives of an information security management system (ISMS) based on ISO/IEC 27001:2022, which requires the organization to identify and evaluate the relevant legal, regulatory, and contractual requirements that apply to its scope and operations3. Reference: Oxford Languages; ISO/IEC 27000:2022, clause 3.9; ISO/IEC 27001:2022, clause 6.1.3.


質問 # 75
Changes on project-managed applications or database should undergo the change control process as documented.

  • A. False
  • B. True

正解:B


質問 # 76
All are prohibited in acceptable use of information assets, except:

  • A. Messages with very large attachments or to a large number ofrecipients.
  • B. Company-wide e-mails with supervisor/TL permission.
  • C. E-mail copies to non-essential readers
  • D. Electronic chain letters

正解:B


質問 # 77
......

ISO-IEC-27001-Lead-Auditor試験問題集で100%高得点させるISO-IEC-27001-Lead-Auditor試験解答がこちら:https://www.jpntest.com/shiken/ISO-IEC-27001-Lead-Auditor-mondaishu

検証済みのISO-IEC-27001-Lead-Auditor試験問題成功確定させます:https://drive.google.com/open?id=1hq0z5lQdNTtW50nxJNv2I9eY_0UaiwNR

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡