合格できるEXIN Information Security Foundation based on ISO/IEC 27001試験最速合格保証最近更新されたGoShiken問題集! [Q26-Q41]

Share

合格できるEXIN Information Security Foundation based on ISO/IEC 27001試験最速合格保証最近更新されたGoShiken問題集!

合格できるISFS試験の80問題で最適なGoShiken出題問題


Exin ISFS(ISO/IEC 27001に基づく情報セキュリティ財団)認証試験は、情報セキュリティの分野での個人の知識と成果を検証するために設計された世界的に認められた認定です。この試験は、ISO/IEC 27001標準に基づいており、情報セキュリティ管理システム(ISM)のベストプラクティスの概要を説明しています。情報セキュリティの基本概念、定義、および情報セキュリティのさまざまな原則をカバーするため、情報セキュリティの分野に参入したい人にとっては基本的なコースです。


EXIN ISFS試験は複数の言語で利用可能で、オンラインまたはオフラインで受験できます。さらに、国際的に認められ、評価されており、どこにいても情報セキュリティのキャリアに興味を持つ人にとって投資する価値がある試験です。また、40の多肢選択問題で構成され、受験者には60分間の時間が与えられます。試験に合格するには、少なくとも65%のスコアを取得する必要があります。

 

質問 # 26
You read in the newspapers that the ex-employee of a large company systematically deleted files out of revenge on his manager. Recovering these files caused great losses in time and money. What is this kind of threat called?

  • A. Human threat
  • B. Natural threat
  • C. Social Engineering

正解:A


質問 # 27
When we are at our desk, we want the information system and the necessary information to be available. We want to be able to work with the computer and access the network and our files.
What is the correct definition of availability?

  • A. The degree to which an information system is available for the users
  • B. The degree to which the continuity of an organization is guaranteed
  • C. The degree to which the system capacity is enough to allow all users to work with it
  • D. The total amount of time that an information system is accessible to the users

正解:A

解説:
Explanation/Reference:


質問 # 28
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

  • A. No
  • B. Yes

正解:A

解説:
Explanation


質問 # 29
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

  • A. The first step consists of checking if the user appears on the list of authorized users.
  • B. The first step consists of comparing the password with the registered password.
  • C. The first step consists of checking if the user is using the correct certificate.
  • D. The first step consists of granting access to the information to which the user is authorized.

正解:A


質問 # 30
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What type of measure could prevent this error?

  • A. Availability measure
  • B. Integrity measure
  • C. Organizational measure
  • D. Technical measure

正解:D


質問 # 31
What is the objective of classifying information?

  • A. Creating a label that indicates how confidential the information is
  • B. Defining different levels of sensitivity into which information may be arranged
  • C. Displaying on the document who is permitted access
  • D. Authorizing the use of an information system

正解:B


質問 # 32
Why do organizations have an information security policy?

  • A. In order to ensure that staff do not break any laws.
  • B. In order to give direction to how information security is set up within an organization.
  • C. In order to ensure that everyone knows who is responsible for carrying out the backup procedures.
  • D. In order to demonstrate the operation of the Plan-Do-Check-Act cycle within an organization.

正解:B


質問 # 33
In most organizations, access to the computer or the network is granted only after the user has entered a correct username and password. This process consists of 3 steps: identification, authentication and authorization. What is the purpose of the second step, authentication?

  • A. In the second step, you make your identity known, which means you are given access to the system.
  • B. The system determines whether access may be granted by determining whether the token used is authentic.
  • C. The authentication step checks the username against a list of users who have access to the system.
  • D. During the authentication step, the system gives you the rights that you need, such as being able to read the data in the system.

正解:B


質問 # 34
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?

  • A. Intellectual Property Rights
  • B. ISO/IEC 27001:2005
  • C. ISO/IEC 27002:2005
  • D. Personal data protection legislation

正解:D


質問 # 35
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?

  • A. Susan, the sender of the information.
  • B. Paul and Susan, the sender and the recipient of the information.
  • C. Paul, the recipient of the information.

正解:C


質問 # 36
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequences of this to the reliability of the information?

  • A. The confidentiality of the information is no longer guaranteed.
  • B. The availability of the information is no longer guaranteed.
  • C. The integrity of the information is no longer guaranteed.

正解:A

解説:
Explanation


質問 # 37
What is a repressive measure in the case of a fire?

  • A. Repairing damage caused by the fire
  • B. Putting out a fire after it has been detected by a fire detector
  • C. Taking out fire insurance

正解:B


質問 # 38
Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?

  • A. Lightning strike
  • B. Loss of a USB stick
  • C. Arson
  • D. Flood

正解:C


質問 # 39
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?

  • A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
  • B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.

正解:A


質問 # 40
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?

  • A. Encrypt the hard drives of laptops and USB sticks
  • B. Set up an access control policy
  • C. Appoint security personnel
  • D. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)

正解:D

解説:
Explanation/Reference:


質問 # 41
......


ISFS試験は、セキュリティアナリスト、セキュリティスペシャリスト、セキュリティコンサルタント、セキュリティマネージャーなど、情報セキュリティ管理のキャリアを求めている個人を対象としています。この認定は、情報セキュリティの分野でキャリアを始めている専門家と、既存の知識を検証したい人の両方の専門家に利益をもたらすように設計されています。

 

合格突破受験者シミュレーションされたISFS試験問題集:https://www.goshiken.com/EXIN/ISFS-mondaishu.html

無料テストエンジンはInformation Security Foundation based on ISO/IEC 27001認定試験:https://drive.google.com/open?id=1cJw_yrxy-Pjwl0EXYExjn9Bg-KKnWX0U