[2023年11月]更新のPECB ISO-IEC-27001-Lead-Auditor問題集厳選された問題集でパスして、最短時間を目指そう [Q46-Q69]

Share

[2023年11月]更新のPECB ISO-IEC-27001-Lead-Auditor問題集厳選された問題集でパスして、最短時間を目指そう

PECB ISO-IEC-27001-Lead-Auditor試験問題集で[2023年最新] 練習 高合格率な試験問題集問題


PECB認定ISO/IEC 27001リード監査人になるには、個人がISO/IEC 27001標準の深い理解と、ISO/IEC 19011ガイドラインに従ってISMS監査を計画、実施、報告する能力を示す必要があります。 。この試験では、情報セキュリティ管理の原則、リスク管理、監査手法、コミュニケーションスキルなど、幅広いトピックをカバーしています。

 

質問 # 46
Which reliability aspect of information is compromised when a staff member denies having sent a message?

  • A. Integrity
  • B. Confidentiality
  • C. Correctness
  • D. Availability

正解:A

解説:
The reliability aspect of information that is compromised when a staff member denies having sent a message is integrity. Integrity is the property of information that ensures its accuracy, completeness, consistency and authenticity. When a staff member denies having sent a message, it implies that the message was either altered, forged, deleted or repudiated by someone else, which violates the integrity of the information. ISO/IEC 27001:2022 defines integrity as "the property of accuracy and completeness" (see clause 3.24). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Integrity?


質問 # 47
A scenario wherein the city or location where the building(s) reside is / are not accessible.

  • A. Component
  • B. Facility
  • C. Country
  • D. City

正解:D

解説:
A scenario wherein the city or location where the building(s) reside is / are not accessible is called a city disaster scenario, according to the CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course. This scenario is one of the four types of disaster scenarios that should be considered in the business continuity planning process, along with component, facility and country scenarios. A city scenario may be caused by events such as natural disasters, civil unrest, terrorist attacks or pandemic outbreaks that affect the entire city or region where the organization operates. Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course]


質問 # 48
Which of the following does a lack of adequate security controls represent?

  • A. Impact
  • B. Threat
  • C. Vulnerability
  • D. Asset

正解:C


質問 # 49
Which reliability aspect of information is compromised when a staff member denies having sent a message?

  • A. Integrity
  • B. Confidentiality
  • C. Correctness
  • D. Availability

正解:A


質問 # 50
You have a hard copy of a customer design document that you want to dispose off. What would you do

  • A. Throw it in any dustbin
  • B. Be environment friendly and reuse it for writing
  • C. Give it to the office boy to reuse it for other purposes
  • D. Shred it using a shredder

正解:D

解説:
The best way to dispose of a hard copy of a customer design document is to shred it using a shredder. This is because shredding ensures that the document is destroyed and cannot be reconstructed or accessed by unauthorized persons. A customer design document may contain sensitive or confidential information that could cause harm or damage to the customer or the organization if disclosed. Therefore, it is important to protect the confidentiality and integrity of the document until it is securely disposed of. Throwing it in any dustbin, giving it to the office boy to reuse it for other purposes, or reusing it for writing are not secure ways of disposing of the document, as they could expose the document to unauthorized access, theft, loss or damage. ISO/IEC 27001:2022 requires the organization to implement procedures for the secure disposal of media containing information (see clause A.8.3.2). Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course, ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Secure Disposal?


質問 # 51
You are performing an ISMS initial certification audit at a residential nursing home that provides healthcare services. The next step in your audit plan is to conduct the closing meeting. During the final audit team meeting, as an audit team leader, you agree to report 2 minor nonconformities and 1 opportunity for improvement as below:

Select one option of the recommendation to the audit programme manager you are going to advise to the auditee at the closing meeting.

  • A. Recommend certification after your approval of the proposed corrective action plan Recommend that the findings can be closed out at a surveillance audit in 1 year
  • B. Recommend that a full scope re-audit is required within 6 months
  • C. Recommend certification immediately
  • D. Recommend that a partial audit is required within 3 months
  • E. Recommend that an unannounced audit is carried out at a future date

正解:A

解説:
According to ISO/IEC 17021-1:2015, which specifies the requirements for bodies providing audit and certification of management systems, clause 9.4.9 requires the certification body to make a certification decision based on the information obtained during the audit and any other relevant information1. The certification body should also consider the effectiveness of the corrective actions taken by the auditee to address any nonconformities identified during the audit1. Therefore, when making a recommendation to the audit programme manager, an ISMS auditor should consider the nature and severity of the nonconformities and the proposed corrective actions.
Based on the scenario above, the auditor should recommend certification after their approval of the proposed corrective action plan and recommend that the findings can be closed out at a surveillance audit in 1 year. The auditor should provide the following justification for their recommendation:
Justification: This recommendation is appropriate because it reflects the fact that the auditee has only two minor nonconformities and one opportunity for improvement, which do not indicate a significant or systemic failure of their ISMS. A minor nonconformity is defined as a failure to achieve one or more requirements of ISO/IEC 27001:2022 or a situation which raises significant doubt about the ability of an ISMS process to achieve its intended output, but does not affect its overall effectiveness or conformity2. An opportunity for improvement is defined as a suggestion for improvement beyond what is required by ISO/IEC 27001:20222. Therefore, these findings do not prevent or preclude certification, as long as they are addressed by appropriate corrective actions within a reasonable time frame. The auditor should approve the proposed corrective action plan before recommending certification, to ensure that it is realistic, achievable, and effective. The auditor should also recommend that the findings can be closed out at a surveillance audit in 1 year, to verify that the corrective actions have been implemented and are working as intended.
The other options are not valid recommendations for the audit programme manager, as they are either too lenient or too strict for the given scenario. For example:
Recommend certification immediately: This option is not valid because it implies that the auditor ignores or accepts the nonconformities, which is contrary to the audit principles and objectives of ISO 19011:20182, which provides guidelines for auditing management systems. It also contradicts the requirement of ISO/IEC 17021-1:20151, which requires the certification body to consider the effectiveness of the corrective actions taken by the auditee before making a certification decision.
Recommend that a full scope re-audit is required within 6 months: This option is not valid because it implies that the auditor overreacts or exaggerates the nonconformities, which is contrary to the audit principles and objectives of ISO 19011:20182. It also contradicts the requirement of ISO/IEC 17021-1:20151, which requires the certification body to determine whether a re-audit is necessary based on the nature and extent of nonconformities and other relevant factors. A full scope re-audit is usually reserved for major nonconformities or multiple minor nonconformities that indicate a serious or widespread failure of an ISMS.
Recommend that an unannounced audit is carried out at a future date: This option is not valid because it implies that the auditor distrusts or doubts the auditee's commitment or capability to implement corrective actions, which is contrary to the audit principles and objectives of ISO 19011:20182. It also contradicts the requirement of ISO/IEC 17021-1:20151, which requires the certification body to conduct unannounced audits only under certain conditions, such as when there are indications of serious problems with an ISMS or when required by sector-specific schemes.
Recommend that a partial audit is required within 3 months: This option is not valid because it implies that the auditor imposes or prescribes a specific time frame or scope for verifying corrective actions, which is contrary to the audit principles and objectives of ISO 19011:20182. It also contradicts the requirement of ISO/IEC 17021-1:20151, which requires the certification body to determine whether a partial audit is necessary based on the nature and extent of nonconformities and other relevant factors. A partial audit may be appropriate for minor nonconformities, but the time frame and scope should be agreed upon with the auditee and based on the proposed corrective action plan.


質問 # 52
We can leave laptops during weekdays or weekends in locked bins.

  • A. True
  • B. False

正解:B


質問 # 53
A scenario wherein the city or location where the building(s) reside is / are not accessible.

  • A. Component
  • B. Facility
  • C. Country
  • D. City

正解:D


質問 # 54
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.
What is a qualitative risk analysis?

  • A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
  • B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.

正解:A

解説:
A qualitative risk analysis is an analysis that is based on scenarios and situations and produces a subjective view of the possible threats. A qualitative risk analysis does not use precise statistical probability calculations or exact loss estimates, but rather relies on the experience, intuition and judgement of the risk analysts and stakeholders. A qualitative risk analysis can use descriptive scales, such as high, medium or low, to rank the likelihood and impact of risks. A qualitative risk analysis can be useful for identifying and prioritizing risks, especially when there is limited data or time available. ISO/IEC 27001:2022 defines qualitative risk analysis as "risk analysis that uses scenarios based on events and situations" (see clause 3.35). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Qualitative Risk Analysis?


質問 # 55
__________ is a software used or created by hackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems.

  • A. Trojan
  • B. Virus
  • C. Malware
  • D. Operating System

正解:C


質問 # 56
The following are the guidelines to protect your password, except:

  • A. For easy recall, use the same password for company and personal accounts
  • B. Change a temporary password on first log-on
  • C. Don't use the same password for various company system security access
  • D. Do not share passwords with anyone

正解:A、D


質問 # 57
Which of the following does an Asset Register contain? (Choose two)

  • A. Asset Type
  • B. Process ID
  • C. Asset Modifier
  • D. Asset Owner

正解:A、D

解説:
An asset register is a document that contains information about the assets associated with information and information processing facilities within the scope of the information security management system. An asset register should include, among other things, the asset type and the asset owner. The asset type is a category or classification of the asset, such as hardware, software, data, document, service, etc. The asset owner is a person or entity that has been assigned the responsibility for managing and protecting the asset throughout its lifecycle. The asset type and the asset owner are important information for identifying and controlling the assets, as well as for performing risk assessments and applying security controls. ISO/IEC 27001:2022 requires the organization to maintain an inventory of assets within the scope of the information security management system (see clause A.8.1.1). Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course, ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is an Asset Register?


質問 # 58
In order to take out a fire insurance policy, an administration office must determine the value of the data that it manages.
Which factor is [b]not[/b] important for determining the value of data for an organization?

  • A. The degree to which missing, incomplete or incorrect data can be recovered.
  • B. The content of data.
  • C. The indispensability of data for the business processes.
  • D. The importance of the business processes that make use of the data.

正解:B

解説:
The content of data is not an important factor for determining the value of data for an organization. The content of data refers to the representation or format of data, such as text, numbers, images, audio, video, etc. The content of data can change depending on how it is processed, stored, or presented, but the value of data is derived from its meaning and usefulness for the organization. Therefore, the content of data is not relevant for taking out a fire insurance policy, as it does not reflect the potential loss or damage that the organization would suffer if the data was destroyed by fire. The other factors, such as the degree of recoverability, the indispensability, and the importance of data for the business processes, are important for determining the value of data for an organization. These factors indicate how critical the data is for the organization's operations, performance, and competitiveness, and how difficult or costly it would be to restore or replace the data in case of a fire. Therefore, the correct answer is A. Reference: Putting a value on data - PwC UK, page 3; What is Data Value? How to Define the Value of Your Data.


質問 # 59
All are prohibited in acceptable use of information assets, except:

  • A. E-mail copies to non-essential readers
  • B. Electronic chain letters
  • C. Messages with very large attachments or to a large number ofrecipients.
  • D. Company-wide e-mails with supervisor/TL permission.

正解:D


質問 # 60
In what part of the process to grant access to a system does the user present a token?

  • A. Authentication
  • B. Identification
  • C. Verification
  • D. Authorisation

正解:B


質問 # 61
Stages of Information

  • A. creation, use, disposition, maintenance, evolution
  • B. creation, distribution, use, maintenance, disposition
  • C. creation, evolution, maintenance, use, disposition
  • D. creation, distribution, maintenance, disposition, use

正解:B

解説:
The stages of information are creation, distribution, use, maintenance, and disposition. These are the phases that information goes through during its lifecycle, from the moment it is generated to the moment it is destroyed or archived. Each stage of information has different security requirements and risks, and should be managed accordingly. Creation, evolution, maintenance, use, and disposition are not the correct stages of information, as evolution is not a distinct stage, but a process that can occur in any stage. Creation, use, disposition, maintenance, and evolution are not the correct stages of information, as they are not in the right order. Creation, distribution, maintenance, disposition, and use are not the correct stages of information, as they are not in the right order. Reference: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 32. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 12.


質問 # 62
What would be the reference for you to know who should have access to data/document?

  • A. Information Rights Management (IRM)
  • B. Data Classification Label
  • C. Access Control List (ACL)
  • D. Masterlist of Project Records (MLPR)

正解:C


質問 # 63
What controls can you do to protect sensitive data in your computer when you go out for lunch?

  • A. You are confident to leave your computer screen as is since a password protected screensaver is installed and it is set to activate after 10 minutes of inactivity
  • B. You lock your computer by pressing Windows+L or CTRL-ALT-DELETE and then click "Lock Computer".
  • C. You activate your favorite screen-saver
  • D. You turn off the monitor

正解:B

解説:
You should lock your computer by pressing Windows+L or CTRL-ALT-DELETE and then click "Lock Computer", because this is the most effective way to protect sensitive data in your computer when you go out for lunch. By locking your computer, you are preventing unauthorized access to your computer and its contents, as well as complying with the organization's access control policy and information security policy. Locking your computer requires a password or a biometric authentication to unlock it, which adds a layer of security to your data. The other options are not sufficient or reliable, as they do not prevent someone from accessing your computer or viewing your screen. Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, How to lock your PC


質問 # 64
What is a repressive measure in case of a fire?

  • A. Putting out a fire after it has been detected by a fire detector
  • B. Repairing damage caused by the fire
  • C. Taking out a fire insurance

正解:A


質問 # 65
We can leave laptops during weekdays or weekends in locked bins.

  • A. True
  • B. False

正解:B

解説:
According to ISO/IEC 27001:2022, clause A.11.2.9, the organization should protect mobile devices and media containing sensitive information from unauthorized access, loss or theft. The organization should also implement appropriate encryption techniques and backup procedures for such devices and media. Therefore, leaving laptops in locked bins during weekdays or weekends is not a secure practice, as it exposes them to potential theft or damage. Laptops should be stored in a safe location when not in use, such as a locked cabinet or drawer, and should be protected by passwords or biometric authentication. Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor (Information Security Management Systems) Course Handbook, page 58; [ISO/IEC 27001:2022], clause A.11.2.9.


質問 # 66
A member of staff denies sending a particular message.
Which reliability aspect of information is in danger here?

  • A. confidentiality
  • B. correctness
  • C. availability
  • D. integrity

正解:D

解説:
The reliability aspect of information that is in danger when a member of staff denies sending a particular message is integrity. Integrity implies that information is authentic and can be verified as such. If a member of staff denies sending a message, it means that either the message was forged or the sender is lying, both of which violate the integrity of the information. Availability, correctness and confidentiality are not directly affected by this scenario. ISO/IEC 27001:2022 defines integrity as "property of accuracy and completeness" (see clause 3.24). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Integrity?


質問 # 67
What is the difference between a restricted and confidential document?

  • A. Restricted - to be shared among named individuals
    Confidential - to be shared across the organization only
  • B. Restricted - to be shared among named individuals
    Confidential - to be shared among an authorized group
  • C. Restricted - to be shared among an authorized group
    Confidential - to be shared among named individuals
  • D. Restricted - to be shared among named individuals
    Confidential - to be shared with friends and family

正解:B

解説:
The difference between a restricted and confidential document is that a restricted document is to be shared among named individuals, while a confidential document is to be shared among an authorized group. Restricted and confidential are examples of information classification levels that indicate the sensitivity and value of information and the degree of protection required for it. Restricted documents contain information that could cause serious damage or harm to the organization or its stakeholders if disclosed to unauthorized persons. Therefore, they should only be accessed by specific individuals who have a legitimate need to know and are authorized by the information owner. Confidential documents contain information that could cause damage or harm to the organization or its stakeholders if disclosed to unauthorized persons. Therefore, they should only be accessed by a defined group of people who have a legitimate need to know and are authorized by the information owner. ISO/IEC 27001:2022 requires the organization to classify information in terms of legal requirements, value, criticality and sensitivity to unauthorized disclosure or modification (see clause A.8.2.1). Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course, ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Information Classification?


質問 # 68
An employee caught temporarily storing an MP3 file in his workstation will not receive an IR.

  • A. True
  • B. False

正解:B

解説:
An employee caught temporarily storing an MP3 file in his workstation will receive an IR, because this is also a violation of the organization's information security policy and acceptable use policy. An MP3 file is a type of media file that may contain copyrighted or illegal content, or may introduce malware or viruses into the organization's network. The employee should not store any unauthorized or personal files in his workstation, as this may compromise the confidentiality, integrity and availability of the organization's information assets. Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], [ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements], Example of an information security policy, Example of an acceptable use policy


質問 # 69
......

ISO-IEC-27001-Lead-Auditor試験問題集でPDF合格保証 成功は正確かつ更新された問題:https://www.jpntest.com/shiken/ISO-IEC-27001-Lead-Auditor-mondaishu

ISO-IEC-27001-Lead-Auditor問題集-[最新2023]PECB試験問題集を掴み取れ:https://drive.google.com/open?id=1GhxXqR-oOrRIYg4_abxHTmG7sJE5lNgN

弊社を連絡する

我々は12時間以内ですべてのお問い合わせを答えます。

オンラインサポート時間:( UTC+9 ) 9:00-24:00
月曜日から土曜日まで

サポート:現在連絡