
ISFS Certification – Valid Exam Dumps Questions Study Guide! (Updated 80 Questions)
ISFS Dumps are Available for Instant Access using Prep4King
NEW QUESTION 32
What do employees need to know to report a security incident?
- A. How to report an incident and to whom.
- B. Whether the incident has occurred before and what was the resulting damage.
- C. The measures that should have been taken to prevent the incident in the first place.
- D. Who is responsible for the incident and whether it was intentional.
Answer: A
NEW QUESTION 33
My user profile specifies which network drives I can read and write to. What is the name of the type of logical access management wherein my access and rights are determined centrally?
- A. Public Key Infrastructure (PKI)
- B. Mandatory Access Control (MAC)
- C. Discretionary Access Control (DAC)
Answer: B
NEW QUESTION 34
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk avoiding
- B. Risk neutral
- C. Risk bearing
Answer: B
NEW QUESTION 35
When we are at our desk, we want the information system and the necessary information to be available. We want to be able to work with the computer and access the network and our files. What is the correct definition of availability?
- A. The total amount of time that an information system is accessible to the users
- B. The degree to which the system capacity is enough to allow all users to work with it
- C. The degree to which the continuity of an organization is guaranteed
- D. The degree to which an information system is available for the users
Answer: D
NEW QUESTION 36
You work for a flexible employer who doesnt mind if you work from home or on the road. You regularly take copies of documents with you on a USB memory stick that is not secure. What are the consequences for the reliability of the information if you leave your USB memory stick behind on the train?
- A. The confidentiality of the data on the USB memory stick is no longer guaranteed.
- B. The integrity of the data on the USB memory stick is no longer guaranteed.
- C. The availability of the data on the USB memory stick is no longer guaranteed.
Answer: A
NEW QUESTION 37
What is a human threat to the reliability of the information on your company website?
- A. The computer hosting your website is overloaded and crashes. Your website is offline.
- B. Because of a lack of maintenance, a fire hydrant springs a leak and floods the premises. Your employees cannot come into the office and therefore can not keep the information on the website up to date.
- C. One of your employees commits an error in the price of a product on your website.
Answer: C
NEW QUESTION 38
Which measure assures that valuable information is not left out available for the taking?
- A. Access passes
- B. Clear desk policy
- C. Infra-red detection
Answer: B
NEW QUESTION 39
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?
- A. Integrity
- B. Confidentiality
- C. Availability
Answer: B
NEW QUESTION 40
What is the objective of classifying information?
- A. Displaying on the document who is permitted access
- B. Creating a label that indicates how confidential the information is
- C. Authorizing the use of an information system
- D. Defining different levels of sensitivity into which information may be arranged
Answer: D
NEW QUESTION 41
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
- A. ISO/IEC 27001:2005
- B. Personal data protection legislation
- C. Intellectual Property Rights
- D. ISO/IEC 27002:2005
Answer: B
NEW QUESTION 42
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- A. Yes
- B. No
Answer: B
Explanation:
Explanation
NEW QUESTION 43
Which type of malware builds a network of contaminated computers?
- A. Trojan
- B. Virus
- C. Logic Bomb
- D. Storm Worm or Botnet
Answer: D
NEW QUESTION 44
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good. What is an example of the indirect damage caused by this fire?
- A. Melted backup tapes
- B. Burned computer systems
- C. Burned documents
- D. Water damage due to the fire extinguishers
Answer: D
NEW QUESTION 45
What is the goal of an organization's security policy?
- A. To define all threats to and measures for ensuring information security
- B. To document all incidents that threaten the reliability of information
- C. To provide direction and support to information security
- D. To document all procedures required to maintain information security
Answer: C
NEW QUESTION 46
You are the owner of the SpeeDelivery courier service. Last year you had a firewall installed. You now discover that no maintenance has been performed since the installation. What is the biggest risk because of this?
- A. The risk of undesired e-mails
- B. The risk that fire may break out in the server room
- C. The risk of a virus outbreak
- D. The risk that hackers can do as they wish on the network without detection
Answer: D
NEW QUESTION 47
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
NEW QUESTION 48
Why is air-conditioning placed in the server room?
- A. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
- B. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted.
The air in the room is also dehumidified and filtered. - C. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
- D. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
Answer: B
NEW QUESTION 49
What is the greatest risk for an organization if no information security policy has been defined?
- A. Too many measures are implemented.
- B. It is not possible for an organization to implement information security in a consistent manner.
- C. Information security activities are carried out by only a few people.
- D. If everyone works with the same account, it is impossible to find out who worked on what.
Answer: B
NEW QUESTION 50
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- A. A code of conduct specifies how employees are expected to conduct themselves and is the same for all companies.
- B. A code of conduct is a standard part of a labor contract.
- C. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
Answer: C
NEW QUESTION 51
......
Who should take the ISFS exam
The Exin ISFS certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled in Exin Information Security Management Certification. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The Exin Information Security Foundation based on ISO/IEC 27002 ISFS Exam certification provides proof of this advanced knowledge and skill. If a candidate has knowledge of associated technologies and skills that are required to pass the Exin Information Security Foundation based on ISO/IEC 27002 ISFS Exam then he should take this exam.
EXIN ISFS Exam Practice Test Questions: https://www.prep4king.com/ISFS-exam-prep-material.html
ISFS Dumps 2022 - New EXIN ISFS Exam Questions: https://drive.google.com/open?id=1EMMg59gWJHn5cHXCCIGqTCb38fGn6y1V

