[Nov-2021] ISFS Exam Dumps - Free Demo & 365 Day Updates [Q26-Q47]

Share

[Nov-2021] ISFS Exam Dumps - Free Demo & 365 Day Updates

Free Sales Ending Soon - Use Real  ISFS PDF Questions


EXIN ISFS Exam Syllabus Topics:

TopicDetails
Topic 1
  • Explain the relationship between risks and security measures
  • Describe the risks involved with insufficient physical security measures
Topic 2
  • Explain why legislation and regulations are important for the reliability of information
  • Explain the difference between data and information
Topic 3
  • Describe various ways in which security measures may be structured or arranged
  • Summarize how security incidents are reported and what information is required
Topic 4
  • Describe the effects of escalation within the organization
  • Explain the relationship between a threat and a risk
Topic 5
  • Describe access security measures such as the segregation of duties and the use of passwords
  • Name the most important roles in the security organization
Topic 6
  • Give examples of legislation related to information security
  • Outline the objectives and the content of a security policy
Topic 7
  • Explain the importance to an organization of a well set-up business continuity management
  • Outline the objectives and the content of a security organization
Topic 9
  • Understand the concepts cryptography, digital signature,and certificate
  • Explain the concepts threat, risk and risk analysis
Topic 10
  • Describe the risks involved with insufficient technical security measures
  • Describe how the value of data and information can influence organizations
Topic 11
  • Describe the concepts identification, authentication,and authorization
  • Describe the value of data and information for organizations
Topic 12
  • Explain the consequences of not reporting security incidents
  • Explain the objective of the classification of information
Topic 13
  • Describe the measures that can be used against malware, phishing,and spam
  • Give examples of regulations related to information security

 

NEW QUESTION 26
You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so important to have an information security policy as a starting point?

  • A. The information security policy supplies instructions for the daily practice of information security.
  • B. The information security policy gives direction to the information security efforts.
  • C. The information security policy establishes who is responsible for which area of information security.
  • D. The information security policy establishes which devices will be protected.

Answer: B

 

NEW QUESTION 27
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis.
Since the assignments are irregular, you outsource the administration of your business to temporary workers.
You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?

  • A. Confidentiality
  • B. Availability
  • C. Integrity

Answer: A

 

NEW QUESTION 28
What action is an unintentional human threat?

  • A. Theft of a laptop
  • B. Arson
  • C. Social engineering
  • D. Incorrect use of fire extinguishing equipment

Answer: D

Explanation:
Explanation/Reference:

 

NEW QUESTION 29
Your company has to ensure that it meets the requirements set down in personal data protection legislation.
What is the first thing you should do?

  • A. Make the employees responsible for submitting their personal data.
  • B. Issue a ban on the provision of personal information.
  • C. Translate the personal data protection legislation into a privacy policy that is geared to the company and the contracts with the customers.
  • D. Appoint a person responsible for supporting managers in adhering to the policy.

Answer: C

 

NEW QUESTION 30
You read in the newspapers that the ex-employee of a large company systematically deleted files out of revenge on his manager. Recovering these files caused great losses in time and money. What is this kind of threat called?

  • A. Human threat
  • B. Social Engineering
  • C. Natural threat

Answer: A

 

NEW QUESTION 31
You are the owner of the courier company SpeeDelivery. You employ a few people who, while waiting to make a delivery, can carry out other tasks. You notice, however, that they use this time to send and read their private mail and surf the Internet. In legal terms, in which way can the use of the Internet and e-mail facilities be best regulated?

  • A. Implementing privacy regulations
  • B. Installing an application that makes certain websites no longer accessible and that filters attachments in e-mails
  • C. Drafting a code of conduct for the use of the Internet and e-mail in which the rights and obligations of both the employer and staff are set down
  • D. Installing a virus scanner

Answer: C

 

NEW QUESTION 32
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

  • A. No
  • B. Yes

Answer: A

 

NEW QUESTION 33
You are the first to arrive at work in the morning and notice that the CD ROM on which you saved contracts yesterday has disappeared. You were the last to leave yesterday. When should you report this information security incident?

  • A. This incident should be reported immediately.
  • B. You should first investigate this incident yourself and try to limit the damage.
  • C. You should wait a few days before reporting this incident. The CD ROM can still reappear and, in that case, you will have made a fuss for nothing.

Answer: A

 

NEW QUESTION 34
Which one of the threats listed below can occur as a result of the absence of a physical measure?

  • A. A user can view the files belonging to another user.
  • B. A server shuts off because of overheating.
  • C. A confidential document is left in the printer.
  • D. Hackers can freely enter the computer network.

Answer: B

 

NEW QUESTION 35
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

  • A. No
  • B. Yes

Answer: A

Explanation:
Explanation

 

NEW QUESTION 36
What is the definition of the Annual Loss Expectancy?

  • A. The Annual Loss Expectancy is the size of the damage claims resulting from not having carried out risk analyses effectively.
  • B. The Annual Loss Expectancy is the amount of damage that can occur as a result of an incident during the year.
  • C. The Annual Loss Expectancy is the average damage calculated by insurance companies for businesses in a country.
  • D. The Annual Loss Expectancy is the minimum amount for which an organization must insure itself.

Answer: B

 

NEW QUESTION 37
Three characteristics determine the reliability of information. Which characteristics are these?

  • A. Availability, Integrity and Correctness
  • B. Availability, Nonrepudiation and Confidentiality
  • C. Availability, Integrity and Confidentiality

Answer: C

Explanation:
Explanation/Reference:

 

NEW QUESTION 38
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequences of this to the reliability of the information?

  • A. The availability of the information is no longer guaranteed.
  • B. The integrity of the information is no longer guaranteed.
  • C. The confidentiality of the information is no longer guaranteed.

Answer: C

 

NEW QUESTION 39
You have a small office in an industrial areA. You would like to analyze the risks your company faces. The office is in a pretty remote location; therefore, the possibility of arson is not entirely out of the question. What is the relationship between the threat of fire and the risk of fire?

  • A. The threat of fire is the risk of fire multiplied by the chance that the fire may occur and the consequences thereof.
  • B. The risk of fire is the threat of fire multiplied by the chance that the fire may occur and the consequences thereof.

Answer: B

 

NEW QUESTION 40
A couple of years ago you started your company which has now grown from 1 to 20 employees.
Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be?
You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?

  • A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
  • B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.

Answer: A

Explanation:
Explanation

 

NEW QUESTION 41
Under which condition is an employer permitted to check if Internet and email services in the workplace are being used for private purposes?

  • A. The employer is permitted to check this if the employee is informed after each instance of checking.
  • B. The employer is in no way permitted to check the use of IT services by employees.
  • C. The employer is permitted to check this if the employees are aware that this could happen.
  • D. The employer is permitted to check this if a firewall is also installed.

Answer: C

 

NEW QUESTION 42
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?

  • A. Confidentiality
  • B. Availability
  • C. Integrity

Answer: A

 

NEW QUESTION 43
What is a human threat to the reliability of the information on your company website?

  • A. Because of a lack of maintenance, a fire hydrant springs a leak and floods the premises. Your employees cannot come into the office and therefore can not keep the information on the website up to date.
  • B. The computer hosting your website is overloaded and crashes. Your website is offline.
  • C. One of your employees commits an error in the price of a product on your website.

Answer: C

 

NEW QUESTION 44
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?

  • A. Personal data protection legislation
  • B. Intellectual Property Rights
  • C. ISO/IEC 27002:2005
  • D. ISO/IEC 27001:2005

Answer: A

 

NEW QUESTION 45
Who is authorized to change the classification of a document?

  • A. The owner of the document
  • B. The manager of the owner of the document
  • C. The author of the document
  • D. The administrator of the document

Answer: A

 

NEW QUESTION 46
What is the objective of classifying information?

  • A. Creating a label that indicates how confidential the information is
  • B. Defining different levels of sensitivity into which information may be arranged
  • C. Authorizing the use of an information system
  • D. Displaying on the document who is permitted access

Answer: B

 

NEW QUESTION 47
......


Who should take the ISFS exam

The Exin ISFS certification is an internationally-recognized validation that identifies persons who earn it as possessing skilled in Exin Information Security Management Certification. If a candidate wants significant improvement in career growth needs enhanced knowledge, skills, and talents. The Exin Information Security Foundation based on ISO/IEC 27002 ISFS Exam certification provides proof of this advanced knowledge and skill. If a candidate has knowledge of associated technologies and skills that are required to pass the Exin Information Security Foundation based on ISO/IEC 27002 ISFS Exam then he should take this exam.

 

ISFS Dumps - Pass Your Certification Exam: https://www.itexamreview.com/ISFS-exam-dumps.html

Latest Real EXIN ISFS Exam Dumps Questions: https://drive.google.com/open?id=1y7ZvFzlzoSM_-xuQi3zLOHhpF4f3FehB