Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the PECB ISO 27001 ISO-IEC-27001-Lead-Implementer Questions and answers with ValidTests

Exam ISO-IEC-27001-Lead-Implementer All Questions
Exam ISO-IEC-27001-Lead-Implementer Premium Access

View all detail and faqs for the ISO-IEC-27001-Lead-Implementer exam

Viewing page 9 out of 11 pages
Viewing questions 81-90 out of questions
Questions # 81:

The Incident Response Team (IRT) has been notified of a potential compromise in the organization’s network. Which type of services would be most appropriate for the IRT to provide in this situation?

Options:

A.

Proactive services

B.

Reactive services

C.

Security quality management services

Expert Solution
Questions # 82:

Scenario 7: Incident Response at Texas H&H Inc.

Once they made sure that the attackers do not have access in their system, the security administrators decided to proceed with the forensic analysis. They concluded that their access security system was not designed tor threat detection, including the detection of malicious files which could be the cause of possible future attacks.

Based on these findings. Texas H$H inc, decided to modify its access security system to avoid future incidents and integrate an incident management policy in their Information security policy that could serve as guidance for employees on how to respond to similar incidents.

Based on the scenario above, answer the following question:

Based on scenario 7. what else should Texas H&H Inc. do when responding to the incident?

Options:

A.

Decide to stop using cloud services in order to eliminate the risk of similar incidents happening in the future

B.

Record and document the incident which serves as input for future corrective actions

C.

Communicate the updated Information security policy only to the top management of the company

Expert Solution
Questions # 83:

How can SkyFleet demonstrate its ongoing commitment to continual improvement in information security?

Options:

A.

By letting employees take independent action ensures swift problem resolution

B.

By outsourcing its information security responsibilities to a third-party vendor

C.

By publishing an annual report on information security performance

Expert Solution
Questions # 84:

An employee from Reyae Ltd. unintentionally sent an email containing critical business strategies to a competitor. Which information security principle was compromised in this case?

Options:

A.

Integrity

B.

Availability

C.

Confidentiality

Expert Solution
Questions # 85:

Which of the following statements is accurate regarding the methodology for managing the implementation of an ISMS?

Options:

A.

Organizations must strictly follow a specific methodology to meet the minimum requirements

B.

The sequence of steps must remain fixed throughout the ISMS implementation

C.

Organizations can adapt the methodology to their specific context, and steps can be modified as needed

Expert Solution
Questions # 86:

Which of the following is the information security committee responsible for?

Options:

A.

Ensure smooth running of the ISMS

B.

Set annual objectives and the ISMS strategy

C.

Treat the nonconformities

Expert Solution
Questions # 87:

Scenario 7: InfoSec, based in Boston, MA, is a multinational corporation offering professional electronics, gaming, and entertainment products. Following several information security incidents, InfoSec has decided to establish teams of experts and implement measures to prevent potential incidents in the future.

Emma, Bob, and Anna were hired as the new members of InfoSec's information security team, which consists of a security architecture team, an incident response team (IRT), and a forensics team. Emma’s job is to create information security plans, policies, protocols, and training to prepare InfoSec to respond to incidents effectively. Emma and Bob would be full-time employees of InfoSec, whereas Anna was contracted as an external consultant.

Bob, a network expert, will implement a screened subnet network architecture. This architecture will isolate the demilitarized zone (DMZ), to which hosted public services are attached, and InfoSec's publicly accessible resources from their private network. Thus, InfoSec will be able to block potential attackers from causing unwanted events inside the company's network. Bob is also responsible for ensuring a thorough evaluation of the nature of an unexpected event, including how the event happened and what or whom it might affect.

On the other hand, Anna will create records of the data, reviews, analyses, and reports to keep evidence for disciplinary and legal action and use them to prevent future incidents. To do the work accordingly, she should be aware of the company's information security incident management policy beforehand. Among others, this policy specifies the type of records to be created, the place where they should be kept, and the format and content that specific record types should have.

As part of InfoSec's initiative to strengthen information security measures, Anna will conduct information security risk assessments only when significant changes are proposed and will document the results of these risk assessments. Upon completion of the risk assessment process, Anna is responsible for developing and implementing a plan for treating information security risks and documenting the risk treatment results.

Furthermore, while implementing the communication plan for information security, InfoSec’s top management was responsible for creating a roadmap for new product development. This approach helps the company to align its security measures with the product development efforts, demonstrating a commitment to integrating security into every aspect of its business operations.

InfoSec uses a cloud service model that includes cloud-based apps accessed through the web or an application programming interface (API). All cloud services are provided by the cloud service provider, while data is managed by InfoSec. This introduces unique security considerations and becomes a primary focus for the information security team to ensure data and systems are protected in this environment.

Based on this scenario, answer the following question:

Does InfoSec adhere to the requirements of ISO/IEC 27001 when conducting information security risk assessments?

Options:

A.

Yes, it adhered to ISO/IEC 27001 requirements

B.

No, as it should perform them at planned intervals as well

C.

No, as it should perform them twice a year, regardless of significant changes

Expert Solution
Questions # 88:

Following a repotted event, an Information security event ticket has been completed and its priority has been assigned. Then, the event has been evaluated to determine If it is an information security incident, which phase of the incident management has been completed?

Options:

A.

initial assessment and decision

B.

Detection and reporting

C.

Evaluation and confirmation

Expert Solution
Questions # 89:

According to ISO/IEC 27000, which of the following best describes the possible scope of a management system?

Options:

A.

It should cover the entire organization without exceptions

B.

It can vary to include the entire organization or specific sections, depending on the needs

C.

It is limited to IT infrastructure and cannot include non-technical departments

Expert Solution
Questions # 90:

An organization wants to enable the correlation and analysis of security-related events and other recorded data and to support investigations into information security incidents. Which control should it implement?

Options:

A.

Use of privileged utility programs

B.

Clock synchronization

C.

Installation of software on operational systems

Expert Solution
Viewing page 9 out of 11 pages
Viewing questions 81-90 out of questions