
Verified ISFS dumps Q&As - Pass Guarantee Exam Dumps Test Engine [2022]
ISFS dumps and 80 unique questions
NEW QUESTION 11
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk.
He asks you for your password. What kind of threat is this?
- A. Natural threat
- B. Organizational threat
- C. Social Engineering
Answer: C
NEW QUESTION 12
You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct is a legal obligation that organizations have to meet.
- B. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
- C. A code of conduct prevents a virus outbreak.
- D. A code of conduct helps to prevent the misuse of IT facilities.
Answer: D
NEW QUESTION 13
You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so important to have an information security policy as a starting point?
- A. The information security policy gives direction to the information security efforts.
- B. The information security policy establishes which devices will be protected.
- C. The information security policy supplies instructions for the daily practice of information security.
- D. The information security policy establishes who is responsible for which area of information security.
Answer: A
NEW QUESTION 14
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good. What is an example of the indirect damage caused by this fire?
- A. Melted backup tapes
- B. Burned computer systems
- C. Burned documents
- D. Water damage due to the fire extinguishers
Answer: D
NEW QUESTION 15
A couple of years ago you started your company which has now grown from 1 to 20 employees.
Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be?
You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
Explanation:
Explanation
NEW QUESTION 16
Why do organizations have an information security policy?
- A. In order to demonstrate the operation of the Plan-Do-Check-Act cycle within an organization.
- B. In order to ensure that everyone knows who is responsible for carrying out the backup procedures.
- C. In order to ensure that staff do not break any laws.
- D. In order to give direction to how information security is set up within an organization.
Answer: D
NEW QUESTION 17
What is an example of a physical security measure?
- A. An access control policy with passes that have to be worn visibly
- B. Special fire extinguishers with inert gas, such as Argon
- C. The encryption of confidential information
- D. A code of conduct that requires staff to adhere to the clear desk policy, ensuring that confidential information is not left visibly on the desk at the end of the work day
Answer: B
NEW QUESTION 18
Your company has to ensure that it meets the requirements set down in personal data protection legislation.
What is the first thing you should do?
- A. Make the employees responsible for submitting their personal data.
- B. Translate the personal data protection legislation into a privacy policy that is geared to the company and the contracts with the customers.
- C. Appoint a person responsible for supporting managers in adhering to the policy.
- D. Issue a ban on the provision of personal information.
Answer: B
NEW QUESTION 19
Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?
- A. Loss of a USB stick
- B. Lightning strike
- C. Arson
- D. Flood
Answer: C
NEW QUESTION 20
What is the most important reason for applying segregation of duties?
- A. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
- B. Segregation of duties makes it clear who is responsible for what.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
Answer: C
NEW QUESTION 21
The Information Security Manager (ISM) at Smith Consultants Inc. introduces the following measures to assure information security:
-The security requirements for the network are specified.
-A test environment is set up for the purpose of testing reports coming from the database.
-The various employee functions are assigned corresponding access rights.
-
RFID access passes are introduced for the building. Which one of these measures is not a technical measure?
- A. The specification of requirements for the network
- B. Introducing RFID access passes
- C. Setting up a test environment
- D. Introducing a logical access policy
Answer: B
NEW QUESTION 22
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
- A. ISO/IEC 27001:2005
- B. Personal data protection legislation
- C. Intellectual Property Rights
- D. ISO/IEC 27002:2005
Answer: B
NEW QUESTION 23
Who is authorized to change the classification of a document?
- A. The administrator of the document
- B. The author of the document
- C. The owner of the document
- D. The manager of the owner of the document
Answer: C
NEW QUESTION 24
What is the greatest risk for an organization if no information security policy has been defined?
- A. Too many measures are implemented.
- B. It is not possible for an organization to implement information security in a consistent manner.
- C. Information security activities are carried out by only a few people.
- D. If everyone works with the same account, it is impossible to find out who worked on what.
Answer: B
NEW QUESTION 25
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis.
Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?
- A. Integrity
- B. Confidentiality
- C. Availability
Answer: B
NEW QUESTION 26
What physical security measure is necessary to control access to company information?
- A. Air-conditioning
- B. Prohibiting the use of USB sticks
- C. Username and password
- D. The use of break-resistant glass and doors with the right locks, frames and hinges
Answer: D
NEW QUESTION 27
When we are at our desk, we want the information system and the necessary information to be available. We want to be able to work with the computer and access the network and our files.
What is the correct definition of availability?
- A. The total amount of time that an information system is accessible to the users
- B. The degree to which the system capacity is enough to allow all users to work with it
- C. The degree to which the continuity of an organization is guaranteed
- D. The degree to which an information system is available for the users
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 28
......
How much ISFS Exam Cost
The price of the ISFS exam is $176 USD.
EXIN ISFS Exam Syllabus Topics:
| Topic | Details |
|---|---|
| Topic 1 |
|
| Topic 2 |
|
| Topic 3 |
|
| Topic 4 |
|
| Topic 5 |
|
| Topic 6 |
|
| Topic 7 |
|
| Topic 8 |
|
| Topic 9 |
|
Who should take the ISFS exam
The Exin ISFS certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled in Exin Information Security Management Certification. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The Exin Information Security Foundation based on ISO/IEC 27002 ISFS Exam certification provides proof of this advanced knowledge and skill. If a candidate has knowledge of associated technologies and skills that are required to pass the Exin Information Security Foundation based on ISO/IEC 27002 ISFS Exam then he should take this exam.
ISFS Dumps for Pass Guaranteed - Pass ISFS Exam: https://torrentking.practicematerial.com/ISFS-questions-answers.html

