EXIN ISFS Real Exam Questions and Answers FREE [Q38-Q53]

Share

EXIN ISFS Real Exam Questions and Answers FREE

Exam Dumps ISFS Practice Free Latest EXIN Practice Tests


EXIN Information Security Foundation based on ISO/IEC 27001 (ISFS) certification exam is a globally recognized credential that validates a comprehensive understanding of information security management fundamentals. The technical qualification is suitable for professionals with little or no prior knowledge of information security management systems (ISMSs). It helps in making a candidate well-versed with the concepts of information security management, information security control, and risk management. Information Security Foundation based on ISO/IEC 27001 certification confirms their ability to comprehend the standard terminology used in the industry.

 

NEW QUESTION # 38
A well executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives. What is not one of the four main objectives of a risk analysis?

  • A. Establishing a balance between the costs of an incident and the costs of a security measure
  • B. Determining relevant vulnerabilities and threats
  • C. Determining the costs of threats
  • D. Identifying assets and their value

Answer: C


NEW QUESTION # 39
What is the greatest risk for an organization if no information security policy has been defined?

  • A. Information security activities are carried out by only a few people.
  • B. If everyone works with the same account, it is impossible to find out who worked on what.
  • C. Too many measures are implemented.
  • D. It is not possible for an organization to implement information security in a consistent manner.

Answer: D


NEW QUESTION # 40
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?

  • A. When the computer systems are not insured.
  • B. When computer systems are kept in a cellar below ground level.
  • C. If the risk analysis has not been carried out.
  • D. When the organization is located near a river.

Answer: B


NEW QUESTION # 41
A couple of years ago you started your company which has now grown from 1 to 20 employees.
Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be?
You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?

  • A. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
  • B. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.

Answer: B

Explanation:
Explanation


NEW QUESTION # 42
Your company has to ensure that it meets the requirements set down in personal data protection legislation.
What is the first thing you should do?

  • A. Make the employees responsible for submitting their personal data.
  • B. Translate the personal data protection legislation into a privacy policy that is geared to the company and the contracts with the customers.
  • C. Issue a ban on the provision of personal information.
  • D. Appoint a person responsible for supporting managers in adhering to the policy.

Answer: B


NEW QUESTION # 43
You are the owner of the courier company SpeeDelivery. On the basis of your risk analysis you have decided to take a number of measures. You have daily backups made of the server, keep the server room locked and install an intrusion alarm system and a sprinkler system. Which of these measures is a detective measure?

  • A. Intrusion alarm
  • B. Sprinkler installation
  • C. Access restriction to special rooms
  • D. Backup tape

Answer: A


NEW QUESTION # 44
A Dutch company requests to be listed on the American Stock Exchange. Which legislation within the scope of information security is relevant in this case?

  • A. Security regulations for the Dutch government
  • B. Sarbanes-Oxley Act
  • C. Public Records Act
  • D. Dutch Tax Law

Answer: B


NEW QUESTION # 45
Which of these is not malicious software?

  • A. Spyware
  • B. Virus
  • C. Worm
  • D. Phishing

Answer: D


NEW QUESTION # 46
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?

  • A. Susan, the sender of the information.
  • B. Paul and Susan, the sender and the recipient of the information.
  • C. Paul, the recipient of the information.

Answer: C


NEW QUESTION # 47
What action is an unintentional human threat?

  • A. Social engineering
  • B. Incorrect use of fire extinguishing equipment
  • C. Arson
  • D. Theft of a laptop

Answer: B

Explanation:
Explanation/Reference:


NEW QUESTION # 48
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis.
Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?

  • A. Confidentiality
  • B. Availability
  • C. Integrity

Answer: A


NEW QUESTION # 49
What is the best way to comply with legislation and regulations for personal data protection?

  • A. Appointing the responsibility to someone
  • B. Performing a threat analysis
  • C. Performing a vulnerability analysis
  • D. Maintaining an incident register

Answer: A


NEW QUESTION # 50
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

  • A. Risk neutral
  • B. Risk avoiding
  • C. Risk bearing

Answer: A


NEW QUESTION # 51
What sort of security does a Public Key Infrastructure (PKI) offer?

  • A. Having a PKI shows customers that a web-based business is secure.
  • B. It provides digital certificates which can be used to digitally sign documents. Such signatures irrefutably determine from whom a document was sent.
  • C. By providing agreements, procedures and an organization structure, a PKI defines which person or which system belongs to which specific public key.
  • D. A PKI ensures that backups of company data are made on a regular basis.

Answer: C


NEW QUESTION # 52
You are the owner of the SpeeDelivery courier service. Last year you had a firewall installed. You now discover that no maintenance has been performed since the installation. What is the biggest risk because of this?

  • A. The risk of a virus outbreak
  • B. The risk of undesired e-mails
  • C. The risk that fire may break out in the server room
  • D. The risk that hackers can do as they wish on the network without detection

Answer: D


NEW QUESTION # 53
......

Verified ISFS Exam Dumps Q&As - Provide ISFS with Correct Answers: https://www.examcost.com/ISFS-practice-exam.html

ISFS Exam Questions | Real ISFS Practice Dumps: https://drive.google.com/open?id=1d7ztc3WdSqQu-yRP9edieXudNDxZjQT5