
Full ISO-IEC-LI Practice Test and 50 unique questions with explanations waiting just for you!
GAQM certification Dumps ISO-IEC-LI Exam for Full Questions - Exam Study Guide
NEW QUESTION 29
What should be used to protect data on removable media if data confidentiality or integrity are important considerations?
- A. backup on another removable medium
- B. logging
- C. cryptographic techniques
- D. a password
Answer: C
NEW QUESTION 30
Prior to employment, _________ as well as terms & conditions of employment are included as controls in ISO
27002 to ensure that employees and contractors understand their responsibilities and are suitable for the roles for which they are considered.
- A. authorizing
- B. screening
- C. controlling
- D. flexing
Answer: B
NEW QUESTION 31
True or False: Organizations allowing teleworking activities, the physical security of the building and the local environment of the teleworking site should be considered
- A. True
- B. False
Answer: A
NEW QUESTION 32
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The person who drafted the insurance terms and conditions
- B. The manager, Linda
- C. The recipient, Rachel
- D. The sender, Peter
Answer: C
NEW QUESTION 33
Responsibilities for information security in projects should be defined and allocated to:
- A. the owner of the involved asset
- B. the project manager
- C. the InfoSec officer
- D. specified roles defined in the used project management method of the organization
Answer: D
NEW QUESTION 34
Which of these reliability aspects is "completeness" a part of?
- A. Availability
- B. Integrity
- C. Exclusivity
- D. Confidentiality
Answer: B
NEW QUESTION 35
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
- A. Availability, Information Value and Confidentiality
- B. Availability, Integrity and Completeness
- C. Timeliness, Accuracy and Completeness
- D. Availability, Integrity and Confidentiality
Answer: D
NEW QUESTION 36
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
- A. ISO/IEC 27001:2005
- B. ISO/IEC 27002:2005
- C. Personal data protection legislation
- D. Intellectual Property Rights
Answer: C
NEW QUESTION 37
Why is compliance important for the reliability of the information?
- A. By meeting the legislative requirements and the regulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
- B. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- C. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and therefore it guarantees the reliability of its information.
Answer: A
NEW QUESTION 38
Which of the following measures is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
- D. Shutting down all internet traffic after a hacker has gained access to the company systems
Answer: A
NEW QUESTION 39
The identified owner of an asset is always an individual
- A. False
- B. True
Answer: A
NEW QUESTION 40
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. If the risk analysis has not been carried out.
- B. When the organization is located near a river.
- C. When the computer systems are not insured.
- D. When computer systems are kept in a cellar below ground level.
Answer: D
NEW QUESTION 41
One of the ways Internet of Things (IoT) devices can communicate with each other (or 'the outside world') is using a so-called short-range radio protocol. Which kind of short-range radio protocol makes it possible to use your phone as a credit card?
- A. Radio Frequency Identification (RFID)
- B. The 4G protocol
- C. Bluetooth
- D. Near Field Communication (NFC)
Answer: D
NEW QUESTION 42
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct is a standard part of a labor contract.
- B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
- C. A code of conduct specifies how employees are expected to conduct themselves and is the same for all companies.
Answer: B
NEW QUESTION 43
Physical labels and ________ are two common forms of labeling which are mentioned in ISO 27002.
- A. metadata
- B. bridge
- C. teradata
Answer: A
NEW QUESTION 44
Of the following, which is the best organization or set of organizations to contribute to compliance?
- A. IT only
- B. IT, business management, HR and legal
- C. IT and legal
- D. IT and management
Answer: B
NEW QUESTION 45
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of threats and risks.
What is the relation between a threat, risk and risk analysis?
- A. A risk analysis is used to clarify which threats are relevant and what risks they involve.
- B. A risk analysis identifies threats from the known risks.
- C. A risk analysis is used to remove the risk of a threat.
- D. Risk analyses help to find a balance between threats and risks.
Answer: A
NEW QUESTION 46
What do employees need to know to report a security incident?
- A. Whether the incident has occurred before and what was the resulting damage.
- B. Who is responsible for the incident and whether it was intentional.
- C. How to report an incident and to whom.
- D. The measures that should have been taken to prevent the incident in the first place.
Answer: C
NEW QUESTION 47
Which of the following measures is a corrective measure?
- A. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
- B. Installing a virus scanner in an information system
- C. Incorporating an Intrusion Detection System (IDS) in the design of a computer center
- D. Making a backup of the data that has been created or altered that day
Answer: A
NEW QUESTION 48
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
- A. Susan, the sender of the information.
- B. Paul and Susan, the sender and the recipient of the information.
- C. Paul, the recipient of the information.
Answer: C
NEW QUESTION 49
......
Authentic Best resources for ISO-IEC-LI Online Practice Exam: https://www.vcetorrent.com/ISO-IEC-LI-valid-vce-torrent.html