
[Aug 09, 2022] Updates Up to 365 days On Valid ISFS Braindumps
Best QualityISFS Exam Questions EXIN Test To Gain Brilliante Result
NEW QUESTION 17
Which of the following measures is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Shutting down all internet traffic after a hacker has gained access to the company systems
- D. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
Answer: A
NEW QUESTION 18
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What type of measure could prevent this error?
- A. Integrity measure
- B. Availability measure
- C. Organizational measure
- D. Technical measure
Answer: D
NEW QUESTION 19
What is the best description of a risk analysis?
- A. A risk analysis calculates the exact financial consequences of damages.
- B. A risk analysis helps to estimate the risks and develop the appropriate security measures.
- C. A risk analysis is a method of mapping risks without looking at company processes.
Answer: B
NEW QUESTION 20
Why is air-conditioning placed in the server room?
- A. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
- B. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
- C. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
- D. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted. The air in the room is also dehumidified and filtered.
Answer: D
NEW QUESTION 21
You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so important to have an information security policy as a starting point?
- A. The information security policy gives direction to the information security efforts.
- B. The information security policy establishes who is responsible for which area of information security.
- C. The information security policy establishes which devices will be protected.
- D. The information security policy supplies instructions for the daily practice of information security.
Answer: A
NEW QUESTION 22
You have a small office in an industrial areA. You would like to analyze the risks your company faces. The office is in a pretty remote location; therefore, the possibility of arson is not entirely out of the question. What is the relationship between the threat of fire and the risk of fire?
- A. The risk of fire is the threat of fire multiplied by the chance that the fire may occur and the consequences thereof.
- B. The threat of fire is the risk of fire multiplied by the chance that the fire may occur and the consequences thereof.
Answer: A
NEW QUESTION 23
Why do organizations have an information security policy?
- A. In order to give direction to how information security is set up within an organization.
- B. In order to demonstrate the operation of the Plan-Do-Check-Act cycle within an organization.
- C. In order to ensure that staff do not break any laws.
- D. In order to ensure that everyone knows who is responsible for carrying out the backup procedures.
Answer: A
NEW QUESTION 24
When we are at our desk, we want the information system and the necessary information to be available. We want to be able to work with the computer and access the network and our files.
What is the correct definition of availability?
- A. The degree to which the system capacity is enough to allow all users to work with it
- B. The degree to which an information system is available for the users
- C. The total amount of time that an information system is accessible to the users
- D. The degree to which the continuity of an organization is guaranteed
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 25
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequences of this to the reliability of the information?
- A. The confidentiality of the information is no longer guaranteed.
- B. The availability of the information is no longer guaranteed.
- C. The integrity of the information is no longer guaranteed.
Answer: A
NEW QUESTION 26
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The manager, Linda
- B. The sender, Peter
- C. The recipient, Rachel
- D. The person who drafted the insurance terms and conditions
Answer: C
NEW QUESTION 27
At Midwest Insurance, all information is classified. What is the goal of this classification of information?
- A. Structuring information according to its sensitivity
- B. To create a manual about how to handle mobile devices
- C. Applying labels making the information easier to recognize
Answer: A
NEW QUESTION 28
What is an example of a physical security measure?
- A. Special fire extinguishers with inert gas, such as Argon
- B. A code of conduct that requires staff to adhere to the clear desk policy, ensuring that confidential information is not left visibly on the desk at the end of the work day
- C. The encryption of confidential information
- D. An access control policy with passes that have to be worn visibly
Answer: A
NEW QUESTION 29
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk avoiding
- B. Risk neutral
- C. Risk bearing
Answer: B
NEW QUESTION 30
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequences of this to the reliability of the information?
- A. The confidentiality of the information is no longer guaranteed.
- B. The availability of the information is no longer guaranteed.
- C. The integrity of the information is no longer guaranteed.
Answer: A
Explanation:
Explanation
NEW QUESTION 31
Which one of the threats listed below can occur as a result of the absence of a physical measure?
- A. A user can view the files belonging to another user.
- B. Hackers can freely enter the computer network.
- C. A server shuts off because of overheating.
- D. A confidential document is left in the printer.
Answer: C
NEW QUESTION 32
You have an office that designs corporate logos. You have been working on a draft for a large client. Just as you are going to press the <save> button, the screen goes blank. The hard disk is damaged and cannot be repaired. You find an early version of the design in your mail folder and you reproduce the draft for the customer. What is such a measure called?
- A. Preventive measure
- B. Reductive measure
- C. Corrective measure
Answer: C
NEW QUESTION 33
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?
- A. Encrypt the hard drives of laptops and USB sticks
- B. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)
- C. Set up an access control policy
- D. Appoint security personnel
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 34
You are the first to arrive at work in the morning and notice that the CD ROM on which you saved contracts yesterday has disappeared. You were the last to leave yesterday. When should you report this information security incident?
- A. You should first investigate this incident yourself and try to limit the damage.
- B. You should wait a few days before reporting this incident. The CD ROM can still reappear and, in that case, you will have made a fuss for nothing.
- C. This incident should be reported immediately.
Answer: C
NEW QUESTION 35
What action is an unintentional human threat?
- A. Arson
- B. Theft of a laptop
- C. Social engineering
- D. Incorrect use of fire extinguishing equipment
Answer: D
NEW QUESTION 36
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?
- A. The first step consists of checking if the user is using the correct certificate.
- B. The first step consists of comparing the password with the registered password.
- C. The first step consists of checking if the user appears on the list of authorized users.
- D. The first step consists of granting access to the information to which the user is authorized.
Answer: C
NEW QUESTION 37
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- A. Yes
- B. No
Answer: B
Explanation:
Explanation
NEW QUESTION 38
The consultants at Smith Consultants Inc. work on laptops that are protected by asymmetrical cryptography. To keep the management of the keys cheap, all consultants use the same key pair. What is the companys risk if they operate in this manner?
- A. If the public key becomes known all laptops must be supplied with new keys.
- B. If the Public Key Infrastructure (PKI) becomes known all laptops must be supplied with new keys.
- C. If the private key becomes known all laptops must be supplied with new keys.
Answer: C
NEW QUESTION 39
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct specifies how employees are expected to conduct themselves and is the same for all companies.
- B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
- C. A code of conduct is a standard part of a labor contract.
Answer: B
NEW QUESTION 40
......
Focus on ISFS All-in-One Exam Guide For Quick Preparation: https://freedumps.torrentvalid.com/ISFS-valid-braindumps-torrent.html