[2023年11月05日] ISO-IEC-27001-Lead-AuditorのPDF問題集にはあなたに不可欠なISO-IEC-27001-Lead-Auditor試験解答を合格に繋ぐ!
ISO-IEC-27001-Lead-AuditorのPDF解答で完璧な予見ISO-IEC-27001-Lead-Auditor練習試験問題
PECB ISO-IEC-27001-LEAD-Auditor認定試験は、ISO/IEC 27001標準の認定主任監査員になりたい専門家向けに設計されています。この認定は世界的に認識されており、個人が監査チームをリードし、ISO/IEC 27001標準に対して組織の情報セキュリティ管理システム(ISM)を評価するために必要な知識とスキルを持っていることを実証しています。この試験では、リスク管理、セキュリティ管理、コンプライアンス、監査手法など、幅広いトピックをカバーしています。試験に合格した個人には、3年間有効なPECB認定ISO/IEC 27001リード監査人認定が授与されます。
質問 # 31
Who is responsible for Initial asset allocation to the user/custodian of the assets?
- A. Asset Owner
- B. Asset Stakeholder
- C. Asset Manager
- D. Asset Practitioner
正解:A
質問 # 32
Implement plan on a test basis - this comes under which section of PDCA
- A. Check
- B. Plan
- C. Do
- D. Act
正解:C
質問 # 33
What is the difference between a restricted and confidential document?
- A. Restricted - to be shared among named individuals
Confidential - to be shared with friends and family - B. Restricted - to be shared among named individuals
Confidential - to be shared across the organization only - C. Restricted - to be shared among named individuals
Confidential - to be shared among an authorized group - D. Restricted - to be shared among an authorized group
Confidential - to be shared among named individuals
正解:C
解説:
The difference between a restricted and confidential document is that a restricted document is to be shared among named individuals, while a confidential document is to be shared among an authorized group. Restricted and confidential are examples of information classification levels that indicate the sensitivity and value of information and the degree of protection required for it. Restricted documents contain information that could cause serious damage or harm to the organization or its stakeholders if disclosed to unauthorized persons. Therefore, they should only be accessed by specific individuals who have a legitimate need to know and are authorized by the information owner. Confidential documents contain information that could cause damage or harm to the organization or its stakeholders if disclosed to unauthorized persons. Therefore, they should only be accessed by a defined group of people who have a legitimate need to know and are authorized by the information owner. ISO/IEC 27001:2022 requires the organization to classify information in terms of legal requirements, value, criticality and sensitivity to unauthorized disclosure or modification (see clause A.8.2.1). Reference: CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course, ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Information Classification?
質問 # 34
Select the words that best complete the sentence:
To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.
正解:
解説:
質問 # 35
A property of Information that has the ability to prove occurrence of a claimed event.
- A. Availability
- B. Accessibility
- C. Electronic chain letters
- D. Integrity
正解:D
質問 # 36
How is the purpose of information security policy best described?
- A. An information security policy provides direction and support to the management regarding information security.
- B. An information security policy makes the security plan concrete by providing it with the necessary details.
- C. An information security policy provides insight into threats and the possible consequences.
- D. An information security policy documents the analysis of risks and the search for countermeasures.
正解:A
解説:
The purpose of information security policy is best described as providing direction and support to the management regarding information security. An information security policy is a high-level document that defines the organization's vision, objectives, principles and responsibilities for information security. It also sets the scope and context of the information security management system and aligns it with the organization's strategy and culture. An information security policy does not document the analysis of risks or the search for countermeasures, nor does it make the security plan concrete or provide insight into threats and consequences. These are tasks for other documents or processes within the information security management system. ISO/IEC 27001:2022 defines information security policy as "policy that provides direction and support for information security in accordance with business requirements and relevant laws and regulations" (see clause 3.29). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Information Security Policy?
質問 # 37
A hacker gains access to a webserver and can view a file on the server containing credit card numbers.
Which of the Confidentiality, Integrity, Availability (CIA) principles of the credit card file are violated?
- A. Availability
- B. Integrity
- C. Confidentiality
- D. Compliance
正解:C
解説:
Confidentiality is one of the Confidentiality, Integrity, Availability (CIA) principles of information security that states that only authorized parties should have access to information assets. Confidentiality protects the secrecy and privacy of information from unauthorized disclosure or exposure. A hacker gaining access to a web server and viewing a file containing credit card numbers violates the confidentiality principle, as he or she is not an authorized party and has access to sensitive information that belongs to others. Therefore, the correct answer is B. Reference: ISO/IEC 27000:2022, clause 3.8; Defining Security Principles - Pearson IT Certification.
質問 # 38
There is a network printer in the hallway of the company where you work. Many employees don't pick up their printouts immediately and leave them on the printer.
What are the consequences of this to the reliability of the information?
- A. The Security of the information is no longer guaranteed.
- B. The integrity of the information is no longer guaranteed.
- C. The availability of the information is no longer guaranteed.
- D. The confidentiality of the information is no longer guaranteed.
正解:D
解説:
Confidentiality is one of the Confidentiality, Integrity, Availability (CIA) principles of information security that states that only authorized parties should have access to information assets. Confidentiality protects the secrecy and privacy of information from unauthorized disclosure or exposure. Often, people do not pick up their prints from a shared printer. This can affect the confidentiality of information, as anyone who passes by the printer can see or take the printed documents that may contain confidential or personal information. This can lead to information leakage, identity theft, fraud, or other malicious activities. Therefore, the correct answer is C. Reference: ISO/IEC 27000:2022, clause 3.8; How & Where to Print Sensitive Documents on a Shared Printer.
質問 # 39
A scenario wherein the city or location where the building(s) reside is / are not accessible.
- A. Facility
- B. Component
- C. City
- D. Country
正解:C
解説:
A scenario wherein the city or location where the building(s) reside is / are not accessible is called a city disaster scenario, according to the CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course. This scenario is one of the four types of disaster scenarios that should be considered in the business continuity planning process, along with component, facility and country scenarios. A city scenario may be caused by events such as natural disasters, civil unrest, terrorist attacks or pandemic outbreaks that affect the entire city or region where the organization operates. Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course]
質問 # 40
In which order is an Information Security Management System set up?
- A. Establishment, implementation, operation, maintenance
- B. Establishment, operation, monitoring, improvement
- C. Implementation, operation, improvement, maintenance
- D. Implementation, operation, maintenance, establishment
正解:A
解説:
The establishment phase of an ISMS involves defining the scope, context, objectives, and leadership commitment for information security management within an organization. It also involves identifying and assessing the risks and opportunities related to information security and selecting the appropriate controls to treat them. The implementation phase of an ISMS involves executing the plans and actions to achieve the information security objectives and implement the selected controls. It also involves ensuring the availability of resources and competencies for information security management. The operation phase of an ISMS involves monitoring and measuring the performance and effectiveness of the ISMS and reporting on the results. It also involves addressing nonconformities and taking corrective actions to prevent recurrence. The maintenance phase of an ISMS involves reviewing and evaluating the ISMS at planned intervals and identifying opportunities for improvement. It also involves updating the ISMS as necessary to reflect changes in the internal and external context of the organization. Therefore, an ISMS is set up in the following order: establishment, implementation, operation, maintenance. Reference: ISO/IEC 27001:2022, clauses 6-10; ISO/IEC 27000:2022, clause 4.
質問 # 41
What is the standard definition of ISMS?
- A. A project-based approach to achieve business objectives for establishing, implementing, operating, monitoring, reviewing, maintaining and improving an organization's information security
- B. Is an information security systematic approach to achieve business objectives for implementation, establishing, reviewing,operating and maintaining organization's reputation.
- C. A systematic approach for establishing, implementing, operating,monitoring, reviewing, maintaining and improving an organization's information security to achieve business objectives.
- D. A company wide business objectives to achieve information security awareness for establishing, implementing, operating, monitoring, reviewing, maintaining and improving
正解:C
質問 # 42
The following are the guidelines to protect your password, except:
- A. Change a temporary password on first log-on
- B. Do not share passwords with anyone
- C. For easy recall, use the same password for company and personal accounts
- D. Don't use the same password for various company system security access
正解:B、C
質問 # 43
Which threat could occur if no physical measures are taken?
- A. A server shutting down because of overheating
- B. Confidential prints being left on the printer
- C. Unauthorised persons viewing sensitive files
- D. Hackers entering the corporate network
正解:A
解説:
Which threat could occur if no physical measures are taken? A server shutting down because of overheating could occur if no physical measures are taken. Physical measures are actions or devices that protect information and information processing facilities from physical threats and hazards, such as fire, flood, earthquake, theft, vandalism, etc. Physical measures include locks, alarms, fences, cameras, fire extinguishers, ventilation systems, etc. If no physical measures are taken, the information and information processing facilities could be exposed to environmental damage or interference that could compromise their availability, integrity, or confidentiality. For example, if a server room has no adequate cooling system, the servers could overheat and malfunction or stop working altogether, resulting in loss of data or service. ISO/IEC 27001:2022 requires the organization to implement physical and environmental security controls to prevent unauthorized physical access, damage and interference to the organization's information and information processing facilities (see clause A.11). Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, [What is Physical Security?]
質問 # 44
There is a scheduled fire drill in your facility. What should you do?
- A. Excuse yourself by saying you have an urgent deliverable
- B. Call in sick
- C. Participate in the drill
- D. None of the above
正解:C
質問 # 45
Backup media is kept in the same secure area as the servers. What risk may the organisation be exposed to?
- A. Unauthorised persons will have access to both the servers and backups
- B. After a server crash, it will take extra time to bring it back up again
- C. Responsibility for the backups is not defined well
- D. After a fire, the information systems cannot be restored
正解:D
解説:
The risk that the organization may be exposed to if backup media is kept in the same secure area as the servers is that after a fire, the information systems cannot be restored. Backup media is a copy of data or information that can be used to restore the original data or information in case of loss, corruption or destruction. Backup media should be stored in a different location from the original data or information, preferably in a remote or off-site location, to ensure its availability and protection from physical threats and hazards. If backup media is kept in the same secure area as the servers, it means that both the original data and the backup data are vulnerable to the same physical threats and hazards, such as fire, flood, theft, etc. If a fire occurs in the secure area, both the servers and the backup media could be damaged or destroyed, making it impossible to restore the information systems and resume normal operations. Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements, What is Backup Media?
質問 # 46
Stages of Information
- A. creation, use, disposition, maintenance, evolution
- B. creation, evolution, maintenance, use, disposition
- C. creation, distribution, maintenance, disposition, use
- D. creation, distribution, use, maintenance, disposition
正解:D
解説:
The stages of information are creation, distribution, use, maintenance, and disposition. These are the phases that information goes through during its lifecycle, from the moment it is generated to the moment it is destroyed or archived. Each stage of information has different security requirements and risks, and should be managed accordingly. Creation, evolution, maintenance, use, and disposition are not the correct stages of information, as evolution is not a distinct stage, but a process that can occur in any stage. Creation, use, disposition, maintenance, and evolution are not the correct stages of information, as they are not in the right order. Creation, distribution, maintenance, disposition, and use are not the correct stages of information, as they are not in the right order. Reference: : CQI & IRCA ISO 27001:2022 Lead Auditor Course Handbook, page 32. : [ISO/IEC 27001 LEAD AUDITOR - PECB], page 12.
質問 # 47
CMM stands for?
- A. Capability Maturity Model
- B. Capability Maturity Matrix
- C. Capacity Maturity Matrix
- D. Capable Mature Model
正解:A
解説:
Capability Maturity Model (CMM) is a framework that describes the key elements of an effective software process. It defines five levels of maturity for software development organizations, from initial to optimized. The CMM helps organizations to assess their current level of process capability and identify the areas for improvement1. Reference: ISO/IEC 27001:2022 Lead Auditor - IECB
質問 # 48
What is the worst possible action that an employee may receive for sharing his or her password or access with others?
- A. Forced roll off from the project
- B. Three days suspension from work
- C. Termination
- D. The lowest rating on his or her performance assessment
正解:C
解説:
The worst possible action that an employee may receive for sharing his or her password or access with others is termination, because this is a serious breach of the organization's information security policy and access control policy. Sharing password or access with others may allow unauthorized users to access sensitive or confidential information, or to perform malicious or fraudulent activities on behalf of the employee. The employee should keep his or her password or access confidential and secure, and should not disclose it to anyone under any circumstances. Reference: [CQI & IRCA Certified ISO/IEC 27001:2022 Lead Auditor Training Course], [ISO/IEC 27001:2022 Information technology - Security techniques - Information security management systems - Requirements], Example of an information security policy, Example of an access control policy
質問 # 49
......
PECB ISO-IEC-27001-LEAD-AUDITOR試験は、ISO/IEC 27001の主任監査人になりたい個人にとって優れた認定です。この認定は世界的に認識されており、雇用主によって高く評価されています。これは、個人が組織のISMを効果的に監査し、ISO/IEC 27001標準に準拠していることを保証するために必要なスキルと知識を開発できるように設計されています。この認定は、リスク管理、情報セキュリティ管理、監査手法など、さまざまなトピックをカバーしており、複数の言語で利用できます。
ISO-IEC-27001-Lead-Auditorリアル試験問題と正確なPECB Certified ISO/IEC 27001 Lead Auditor examのPDF解答:https://www.jpntest.com/shiken/ISO-IEC-27001-Lead-Auditor-mondaishu
リアルPECB試験の素晴らしい練習問題集でISO-IEC-27001-Lead-Auditor試験:https://drive.google.com/open?id=17lg8BQnHf-zyyOM-mo4MV3yUHnH3lxF8