Summer Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

An organization does NOT authenticate the identity of persons that enter the server room, so unauthorized persons can easily gain access to the server. Which control of ISO/IEC 27002 should the organization implement to solve this problem?

A.

Control 8.6 Capacity management

B.

Control 7.2 Physical entry

C.

Control 8.4 Access to source code

According to Control 5.1 Policies for information security, regarding which of the following, among others, should an information security policy contain statements?

A.

Regarding the procedures for recovering from a data breach

B.

Regarding the procedures for handling exemptions and exceptions

C.

Regarding the procedures for using automated information systems

An organization has set up a fire alarm. What type of control is this?

A.

Corrective and managerial

B.

Detective and technical

C.

Preventive and legal

What is continual improvement?

A.

The process of increasing the effectiveness and efficiency of the organization to fulfill its policy and objectives

B.

A method of examining the nature of something or of determining its essential features and their relations

C.

The action taken to eliminate a detected nonconformity

Why should an organization integrate information security into project management?

A.

To ensure the effective application of ISO/IEC 27001 principles related to projects and deliverables

B.

To ensure information security audits on the project and deliverables are regularly conducted

C.

To ensure information security risks related to projects and deliverables are effectively addressed

Which situation presented below indicates that the confidentiality of information has been breached?

A.

Employees of all departments of an organization have access to personal data of their colleagues

B.

The Customer Service Department is not able to access customers’ phone numbers due to an equipment failure

C.

One of the employees of the Financial Department of an organization accidentally modified banking information of other staff members

Which of the following controls should the organization implement to ensure that its approach to managing information security continues to be suitable, adequate and effective?

A.

Control 5.4 Management responsibilities

B.

Control 5.35 Independent review of information security

C.

Control 5.24 Information security incident management planning and preparation

What should the organization do with regard to the information security roles and responsibilities of an employee who is leaving or changing the job role?

A.

It should identify and transfer them to another employee

B.

It should document them in the termination of employment policy

C.

It should outsource them to an external party

What, among others, should be considered when using cryptography?

A.

The roles and responsibilities for the key management

B.

Security checkpoints in projects

C.

Restricting and filtering systems connection to the network

What does ISO/IEC 27002 provide?

A.

Guidance for the implementation of information security controls

B.

Requirements for the implementation of information security controls

C.

Guidance for the management of information security risks