
Get 2021 Updated Free EXIN ISFS Exam Questions & Answer
ISFS Dumps PDF and Test Engine Exam Questions
Exin Information Security Foundation (based on ISO/IEC 27002) (EX0-105) ISFS Exam
Exin Information Security Foundation (based on ISO/IEC 27002) (EX0-105) ISFS Exam which is related to Exin Information Security Foundation based on ISO/IEC 27002 and credits toward Exin Information Security Management Certification. This exam validates the Candidate knowledge and skills of the concept of Information, relationships between threats, risks and the reliability of the information, importance of measures, physical security, technical measures, measures security policy and security organization.
NEW QUESTION 39
Why is compliance important for the reliability of the information?
- A. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- B. By meeting the legislative requirements and the regulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
- C. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and therefore it guarantees the reliability of its information.
Answer: B
NEW QUESTION 40
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?
- A. The recipient, Rachel
- B. The person who drafted the insurance terms and conditions
- C. The sender, Peter
- D. The manager, Linda
Answer: A
NEW QUESTION 41
What do employees need to know to report a security incident?
- A. Whether the incident has occurred before and what was the resulting damage.
- B. How to report an incident and to whom.
- C. The measures that should have been taken to prevent the incident in the first place.
- D. Who is responsible for the incident and whether it was intentional.
Answer: B
NEW QUESTION 42
What is an example of a security incident?
- A. You cannot set the correct fonts in your word processing software.
- B. The lighting in the department no longer works.
- C. A file is saved under an incorrect name.
- D. A member of staff loses a laptop.
Answer: D
NEW QUESTION 43
Three characteristics determine the reliability of information. Which characteristics are these?
- A. Availability, Nonrepudiation and Confidentiality
- B. Availability, Integrity and Correctness
- C. Availability, Integrity and Confidentiality
Answer: C
NEW QUESTION 44
What action is an unintentional human threat?
- A. Social engineering
- B. Arson
- C. Incorrect use of fire extinguishing equipment
- D. Theft of a laptop
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 45
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
- A. Availability, Integrity and Completeness
- B. Availability, Integrity and Confidentiality
- C. Timeliness, Accuracy and Completeness
- D. Availability, Information Value and Confidentiality
Answer: B
NEW QUESTION 46
Why is air-conditioning placed in the server room?
- A. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
- B. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
- C. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
- D. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted.
The air in the room is also dehumidified and filtered.
Answer: D
NEW QUESTION 47
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. The use of tokens to gain access to information systems
- B. Validation of input and output data in applications
- C. Encryption of information
- D. Information Security Management System
Answer: D
NEW QUESTION 48
Which of these is not malicious software?
- A. Phishing
- B. Worm
- C. Spyware
- D. Virus
Answer: A
NEW QUESTION 49
Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure. What are some other measures?
- A. Detective, repressive and corrective measures
- B. Repressive, adaptive and corrective measures
- C. Partial, adaptive and corrective measures
Answer: A
NEW QUESTION 50
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?
- A. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)
- B. Encrypt the hard drives of laptops and USB sticks
- C. Appoint security personnel
- D. Set up an access control policy
Answer: A
Explanation:
Explanation/Reference:
NEW QUESTION 51
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk.
He asks you for your password. What kind of threat is this?
- A. Organizational threat
- B. Social Engineering
- C. Natural threat
Answer: B
NEW QUESTION 52
Some security measures are optional. Other security measures must always be implemented. Which measure(s) must always be implemented?
- A. Clear Desk Policy
- B. Physical security measures
- C. Measures required by laws and regulations
- D. Logical access security measures
Answer: C
NEW QUESTION 53
Your company has to ensure that it meets the requirements set down in personal data protection legislation.
What is the first thing you should do?
- A. Make the employees responsible for submitting their personal data.
- B. Appoint a person responsible for supporting managers in adhering to the policy.
- C. Translate the personal data protection legislation into a privacy policy that is geared to the company and the contracts with the customers.
- D. Issue a ban on the provision of personal information.
Answer: C
NEW QUESTION 54
You own a small company in a remote industrial areA. Lately, the alarm regularly goes off in the middle of the night. It takes quite a bit of time to respond to it and it seems to be a false alarm every time. You decide to set up a hidden camerA. What is such a measure called?
- A. Preventive measure
- B. Repressive measure
- C. Detective measure
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 55
Who is authorized to change the classification of a document?
- A. The manager of the owner of the document
- B. The administrator of the document
- C. The author of the document
- D. The owner of the document
Answer: D
NEW QUESTION 56
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis.
Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?
- A. Confidentiality
- B. Availability
- C. Integrity
Answer: A
NEW QUESTION 57
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- A. No
- B. Yes
Answer: A
Explanation:
Explanation
NEW QUESTION 58
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk bearing
- B. Risk neutral
- C. Risk avoiding
Answer: B
NEW QUESTION 59
......
EXIN ISFS Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
| Topic 10 |
|
| Topic 11 |
|
| Topic 12 |
|
Verified ISFS exam dumps Q&As with Correct 80 Questions and Answers: https://www.actualpdf.com/ISFS_exam-dumps.html
Get New ISFS Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1Bn5IeSKeyG6PCizZ-DN_1sh9iig_9gyc
