Get 2021 Updated Free EXIN ISFS Exam Questions & Answer [Q39-Q59]

Share

Get 2021 Updated Free EXIN ISFS Exam Questions & Answer

ISFS Dumps PDF and Test Engine Exam Questions


Exin Information Security Foundation (based on ISO/IEC 27002) (EX0-105) ISFS Exam

Exin Information Security Foundation (based on ISO/IEC 27002) (EX0-105) ISFS Exam which is related to Exin Information Security Foundation based on ISO/IEC 27002 and credits toward Exin Information Security Management Certification. This exam validates the Candidate knowledge and skills of the concept of Information, relationships between threats, risks and the reliability of the information, importance of measures, physical security, technical measures, measures security policy and security organization.

 

NEW QUESTION 39
Why is compliance important for the reliability of the information?

  • A. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
  • B. By meeting the legislative requirements and the regulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
  • C. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
  • D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and therefore it guarantees the reliability of its information.

Answer: B

 

NEW QUESTION 40
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the value of the information in the insurance terms and conditions document?

  • A. The recipient, Rachel
  • B. The person who drafted the insurance terms and conditions
  • C. The sender, Peter
  • D. The manager, Linda

Answer: A

 

NEW QUESTION 41
What do employees need to know to report a security incident?

  • A. Whether the incident has occurred before and what was the resulting damage.
  • B. How to report an incident and to whom.
  • C. The measures that should have been taken to prevent the incident in the first place.
  • D. Who is responsible for the incident and whether it was intentional.

Answer: B

 

NEW QUESTION 42
What is an example of a security incident?

  • A. You cannot set the correct fonts in your word processing software.
  • B. The lighting in the department no longer works.
  • C. A file is saved under an incorrect name.
  • D. A member of staff loses a laptop.

Answer: D

 

NEW QUESTION 43
Three characteristics determine the reliability of information. Which characteristics are these?

  • A. Availability, Nonrepudiation and Confidentiality
  • B. Availability, Integrity and Correctness
  • C. Availability, Integrity and Confidentiality

Answer: C

 

NEW QUESTION 44
What action is an unintentional human threat?

  • A. Social engineering
  • B. Arson
  • C. Incorrect use of fire extinguishing equipment
  • D. Theft of a laptop

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 45
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?

  • A. Availability, Integrity and Completeness
  • B. Availability, Integrity and Confidentiality
  • C. Timeliness, Accuracy and Completeness
  • D. Availability, Information Value and Confidentiality

Answer: B

 

NEW QUESTION 46
Why is air-conditioning placed in the server room?

  • A. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
  • B. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
  • C. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
  • D. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted.
    The air in the room is also dehumidified and filtered.

Answer: D

 

NEW QUESTION 47
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?

  • A. The use of tokens to gain access to information systems
  • B. Validation of input and output data in applications
  • C. Encryption of information
  • D. Information Security Management System

Answer: D

 

NEW QUESTION 48
Which of these is not malicious software?

  • A. Phishing
  • B. Worm
  • C. Spyware
  • D. Virus

Answer: A

 

NEW QUESTION 49
Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure. What are some other measures?

  • A. Detective, repressive and corrective measures
  • B. Repressive, adaptive and corrective measures
  • C. Partial, adaptive and corrective measures

Answer: A

 

NEW QUESTION 50
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?

  • A. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)
  • B. Encrypt the hard drives of laptops and USB sticks
  • C. Appoint security personnel
  • D. Set up an access control policy

Answer: A

Explanation:
Explanation/Reference:

 

NEW QUESTION 51
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk.
He asks you for your password. What kind of threat is this?

  • A. Organizational threat
  • B. Social Engineering
  • C. Natural threat

Answer: B

 

NEW QUESTION 52
Some security measures are optional. Other security measures must always be implemented. Which measure(s) must always be implemented?

  • A. Clear Desk Policy
  • B. Physical security measures
  • C. Measures required by laws and regulations
  • D. Logical access security measures

Answer: C

 

NEW QUESTION 53
Your company has to ensure that it meets the requirements set down in personal data protection legislation.
What is the first thing you should do?

  • A. Make the employees responsible for submitting their personal data.
  • B. Appoint a person responsible for supporting managers in adhering to the policy.
  • C. Translate the personal data protection legislation into a privacy policy that is geared to the company and the contracts with the customers.
  • D. Issue a ban on the provision of personal information.

Answer: C

 

NEW QUESTION 54
You own a small company in a remote industrial areA. Lately, the alarm regularly goes off in the middle of the night. It takes quite a bit of time to respond to it and it seems to be a false alarm every time. You decide to set up a hidden camerA. What is such a measure called?

  • A. Preventive measure
  • B. Repressive measure
  • C. Detective measure

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 55
Who is authorized to change the classification of a document?

  • A. The manager of the owner of the document
  • B. The administrator of the document
  • C. The author of the document
  • D. The owner of the document

Answer: D

 

NEW QUESTION 56
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis.
Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?

  • A. Confidentiality
  • B. Availability
  • C. Integrity

Answer: A

 

NEW QUESTION 57
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation

 

NEW QUESTION 58
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

  • A. Risk bearing
  • B. Risk neutral
  • C. Risk avoiding

Answer: B

 

NEW QUESTION 59
......


EXIN ISFS Exam Syllabus Topics:

TopicDetails
Topic 1
  • Describe the measures that can be used against malware, phishing,and spam
  • Give examples of regulations related to information security
Topic 2
  • Describe the effects of escalation within the organization
  • Explain the relationship between a threat and a risk
Topic 3
  • Explain the relationship between risks and security measures
  • Describe the risks involved with insufficient physical security measures
Topic 4
  • Explain the consequences of not reporting security incidents
  • Explain the objective of the classification of information
Topic 5
  • Describe the risks involved with insufficient technical security measures
  • Describe how the value of data and information can influence organizations
Topic 6
  • Describe the concepts identification, authentication,and authorization
  • Describe the value of data and information for organizations
Topic 7
  • Describe various ways in which security measures may be structured or arranged
  • Summarize how security incidents are reported and what information is required
Topic 8
  • Explain why legislation and regulations are important for the reliability of information
  • Explain the difference between data and information
Topic 9
  • Understand the concepts cryptography, digital signature,and certificate
  • Explain the concepts threat, risk and risk analysis
Topic 10
  • Give examples of legislation related to information security
  • Outline the objectives and the content of a security policy
Topic 11
  • Explain the importance to an organization of a well set-up business continuity management
  • Outline the objectives and the content of a security organization
Topic 12
  • Describe access security measures such as the segregation of duties and the use of passwords
  • Name the most important roles in the security organization

 

Verified ISFS exam dumps Q&As with Correct 80 Questions and Answers: https://www.actualpdf.com/ISFS_exam-dumps.html

Get New ISFS Certification – Valid Exam Dumps Questions: https://drive.google.com/open?id=1Bn5IeSKeyG6PCizZ-DN_1sh9iig_9gyc