あなたを合格させるISFS試験問題集で使おう(更新された80問があります) [Q23-Q45]

Share

あなたを合格させるISFS試験問題集で使おう(更新された80問があります)

ISFS試験問題集でEXIN練習テスト問題

質問 23
Which of these is not malicious software?

  • A. Phishing
  • B. Virus
  • C. Worm
  • D. Spyware

正解: A

 

質問 24
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What type of measure could prevent this error?

  • A. Availability measure
  • B. Organizational measure
  • C. Integrity measure
  • D. Technical measure

正解: D

 

質問 25
You work for a large organization. You notice that you have access to confidential information that you should not be able to access in your position. You report this security incident to the helpdesk. The incident cycle isinitiated. What are the stages of the security incident cycle?

  • A. Threat, Damage, Recovery, Incident
  • B. Threat, Incident, Damage, Recovery
  • C. Threat, Recovery, Incident, Damage
  • D. Threat, Damage, Incident, Recovery

正解: B

 

質問 26
A Dutch company requests to be listed on the American Stock Exchange. Which legislation within the scope of information security is relevant in this case?

  • A. Security regulations for the Dutch government
  • B. Sarbanes-Oxley Act
  • C. Dutch Tax Law
  • D. Public Records Act

正解: B

 

質問 27
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?

  • A. A code of conduct specifies how employees are expected to conduct themselves and is the same for all companies.
  • B. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.
  • C. A code of conduct is a standard part of a labor contract.

正解: B

 

質問 28
Which one of the threats listed below can occur as a result of the absence of a physical measure?

  • A. A confidential document is left in the printer.
  • B. A server shuts off because of overheating.
  • C. A user can view the files belonging to another user.
  • D. Hackers can freely enter the computer network.

正解: B

 

質問 29
A couple of years ago you started your company which has now grown from 1 to 20 employees.
Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be?
You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?

  • A. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
  • B. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.

正解: B

 

質問 30
Why is air-conditioning placed in the server room?

  • A. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
  • B. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
  • C. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
  • D. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted. The air in the room is also dehumidified and filtered.

正解: D

 

質問 31
What action is an unintentional human threat?

  • A. Theft of a laptop
  • B. Social engineering
  • C. Incorrect use of fire extinguishing equipment
  • D. Arson

正解: C

解説:
Explanation/Reference:

 

質問 32
Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of which are used for a call centre 24 hours per day. Five workstations must always be available. What physical security measures must be taken in order to ensure this?

  • A. Obtain an extra office and connect all 10 new workstations to an emergency power supply and UPS (Uninterruptible Power Supply). Adjust the access control system to the working hours of the new staff. Inform the building security personnel that work will also be carried out in the evenings and at night.
  • B. Obtain an extra office and set up 10 workstations. Ensure that there are security personnel both in the evenings and at night, so that staff can work there safely and securely.
  • C. Obtain an extra office and set up 10 workstations. You would therefore have spare equipment that can be used to replace any non-functioning equipment.
  • D. Obtain an extra office and provide a UPS (Uninterruptible Power Supply) for the five most important workstations.

正解: A

 

質問 33
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?

  • A. Availability
  • B. Confidentiality
  • C. Integrity

正解: B

 

質問 34
Which of the following measures is a preventive measure?

  • A. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
  • B. Shutting down all internet traffic after a hacker has gained access to the company systems
  • C. Installing a logging system that enables changes in a system to be recognized
  • D. Putting sensitive information in a safe

正解: D

 

質問 35
What is the greatest risk for an organization if no information security policy has been defined?

  • A. Too many measures are implemented.
  • B. It is not possible for an organization to implement information security in a consistent manner.
  • C. If everyone works with the same account, it is impossible to find out who worked on what.
  • D. Information security activities are carried out by only a few people.

正解: B

 

質問 36
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of the threats and risks. What is the relation between a threat, risk and risk analysis?

  • A. A risk analysis is used to remove the risk of a threat.
  • B. A risk analysis identifies threats from the known risks.
  • C. A risk analysis is used to clarify which threats are relevant and what risks they involve.
  • D. Risk analyses help to find a balance between threats and risks.

正解: C

 

質問 37
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?

  • A. Paul, the recipient of the information.
  • B. Paul and Susan, the sender and the recipient of the information.
  • C. Susan, the sender of the information.

正解: A

 

質問 38
Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure.
What are some other measures?

  • A. Partial, adaptive and corrective measures
  • B. Detective, repressive and corrective measures
  • C. Repressive, adaptive and corrective measures

正解: B

 

質問 39
Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?

  • A. Lightning strike
  • B. Loss of a USB stick
  • C. Flood
  • D. Arson

正解: D

 

質問 40
Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure. What are some other measures?

  • A. Partial, adaptive and corrective measures
  • B. Detective, repressive and corrective measures
  • C. Repressive, adaptive and corrective measures

正解: B

 

質問 41
Some security measures are optional. Other security measures must always be implemented. Which measure(s) must always be implemented?

  • A. Logical access security measures
  • B. Clear Desk Policy
  • C. Physical security measures
  • D. Measures required by laws and regulations

正解: D

 

質問 42
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?

  • A. Social Engineering
  • B. Organizational threat
  • C. Natural threat

正解: A

 

質問 43
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?

  • A. Appoint security personnel
  • B. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)
  • C. Set up an access control policy
  • D. Encrypt the hard drives of laptops and USB sticks

正解: B

解説:
Explanation/Reference:

 

質問 44
What is a risk analysis used for?

  • A. A risk analysis is used to clarify to management their responsibilities.
  • B. A risk analysis is used to ensure that security measures are deployed in a cost-effective and timely fashion.
  • C. A risk analysis is used to express the value of information for an organization in monetary terms.
  • D. A risk analysis is used in conjunction with security measures to reduce risks to an acceptable level.

正解: B

 

質問 45
......


EXIN ISFS 認定試験の出題範囲:

トピック出題範囲
トピック 1
  • Describe the measures that can be used against malware, phishing,and spam
  • Give examples of regulations related to information security
トピック 2
  • Explain why legislation and regulations are important for the reliability of information
  • Explain the difference between data and information
トピック 3
  • Describe various ways in which security measures may be structured or arranged
  • Summarize how security incidents are reported and what information is required
トピック 4
  • Explain the relationship between risks and security measures
  • Describe the risks involved with insufficient physical security measures
トピック 5
  • Give examples of legislation related to information security
  • Outline the objectives and the content of a security policy
トピック 6
  • Explain the importance to an organization of a well set-up business continuity management
  • Outline the objectives and the content of a security organization
トピック 7
  • Explain the consequences of not reporting security incidents
  • Explain the objective of the classification of information
トピック 8
  • Describe the effects of escalation within the organization
  • Explain the relationship between a threat and a risk
トピック 9
  • Understand the concepts cryptography, digital signature,and certificate
  • Explain the concepts threat, risk and risk analysis

 

最新でリアルなISFS試験問題集解答:https://drive.google.com/open?id=1Ius5QH2fSz3e7DbGJaXDwyLDsAdwkpHL

あなたをお手軽に合格させるISFS試験正確なPDF問題:https://www.goshiken.com/EXIN/ISFS-mondaishu.html