Skip to main content

ISO-27002-LI Real Exam Questions

ISO/IEC 27002 - Lead Implementer

50 questions available · Page 1 of 5

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

What does the Information Security Policy describe?

  1. A

    how the InfoSec-objectives will be reached

  2. B

    which InfoSec-controls have been selected and taken

  3. C

    what the implementation-planning of the information security management system is

  4. D

    which Information Security-procedures are selected

Show answer and explanation

Correct answer: A

Question 2 Single choice

Responsibilities for information security in projects should be defined and allocated to:

  1. A

    the project manager

  2. B

    specified roles defined in the used project management method of the organization

  3. C

    the InfoSec officer

  4. D

    the owner of the involved asset

Show answer and explanation

Correct answer: B

Question 3 Single choice

A non-human threat for computer systems is a flood.
In which situation is a flood always a relevant threat?

  1. A

    If the risk analysis has not been carried out.

  2. B

    When computer systems are kept in a cellar below ground level.

  3. C

    When the computer systems are not insured.

  4. D

    When the organization is located near a river.

Show answer and explanation

Correct answer: B

Question 4 Single choice

What is an example of a security incident?

  1. A

    The lighting in the department no longer works.

  2. B

    A member of staff loses a laptop.

  3. C

    You cannot set the correct fonts in your word processing software.

  4. D

    A file is saved under an incorrect name.

Show answer and explanation

Correct answer: B

Question 5 Single choice

Which of these control objectives are NOT in the domain "12.
OPERATIONAL SAFETY"?

  1. A

    Protection against malicious code

  2. B

    Redundancies

  3. C

    Test data

  4. D

    Technical vulnerability management

Show answer and explanation

Correct answer: B

Question 6 Single choice

Which of these reliability aspects is "completeness" a part of?

  1. A

    Availability

  2. B

    Exclusivity

  3. C

    Integrity

  4. D

    Confidentiality

Show answer and explanation

Correct answer: C

Question 7 Single choice

Of the following, which is the best organization or set of organizations to contribute to compliance?

  1. A

    IT only

  2. B

    IT, business management, HR and legal

  3. C

    IT and management

  4. D

    IT and legal

Show answer and explanation

Correct answer: B

Question 8 Multiple choice

Select risk control activities for domain "10. Encryption" of ISO / 27002: 2013 (Choose two)

  1. A

    Work in safe areas

  2. B

    Cryptographic Controls Use Policy

  3. C

    Physical security perimeter

  4. D

    Key management

Show answer and explanation

Correct answers: B, D

Question 9 Single choice

In the context of contact with special interest groups, any information-sharing agreements should identify requirements for the protection of _________ information.

  1. A

    Availability

  2. B

    Confidential

  3. C

    Authentic

  4. D

    Authorization

Show answer and explanation

Correct answer: B

Question 10 Single choice

What is an example of a good physical security measure?

  1. A

    All employees and visitors carry an access pass.

  2. B

    Printers that are defective or have been replaced are immediately removed and given away as garbage for recycling.

  3. C

    Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.

Show answer and explanation

Correct answer: A