Summer Sale Limited Time 75% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code = simple75

Pass the PECB ISO 27002 ISO-IEC-27002-Foundation Questions and answers with Dumpstech

Exam ISO-IEC-27002-Foundation Premium Access

View all detail and faqs for the ISO-IEC-27002-Foundation exam

Practice at least 50% of the questions to maximize your chances of passing.
Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions
Questions # 1:

What should be considered, among others, when establishing a remote working policy?

Options:

A.

The threat of unauthorized access to information or resources from other persons in public places

B.

The positioning of information processing facilities handling sensitive data

C.

The maintenance of authorization process and record of all privileges allocated

Questions # 2:

An organization uses an access control software that allows only authorized employees to access sensitive files. What type of control is this?

Options:

A.

Detective

B.

Corrective

C.

Preventive

Questions # 3:

What is risk assessment?

Options:

A.

The process of finding, recognizing, and describing risks

B.

The process to comprehend the nature of risk and to determine the level of risk

C.

The overall process of risk identification, risk analysis, and risk evaluation

Questions # 4:

What is a PII controller?

Options:

A.

A natural person to whom the PII relates

B.

A privacy stakeholder that determines the purpose and means for processing PII besides individuals who use data for personal purposes

C.

A privacy stakeholder that handles PII on behalf of and in accordance with the instructions of a PII controller

Questions # 5:

Which control of ISO/IEC 27002 aims to ensure the correct and secure operation of information processing facilities?

Options:

A.

Control 7.2 Physical entry

B.

Control 5.37 Documented operating procedures

C.

Control 5.35 Independent review of information security

Questions # 6:

What does ISO/IEC 27002 recommend regarding audit testing?

Options:

A.

Audit tests should be planned and agreed upon between the tester and the appropriate management

B.

Audit tests and other assurance activities should be conducted ad hoc to determine the effectiveness of operational systems and business processes

C.

The organization should temporarily stop its operational systems and business processes during audits and other assurance activities

Questions # 7:

What does information security determine?

Options:

A.

What information needs to be protected and why it should be protected

B.

How to protect information and what to protect it from

C.

Both A and B

Questions # 8:

Why should an organization integrate information security into project management?

Options:

A.

To ensure the effective application of ISO/IEC 27001 principles related to projects and deliverables

B.

To ensure information security audits on the project and deliverables are regularly conducted

C.

To ensure information security risks related to projects and deliverables are effectively addressed

Questions # 9:

How can organizations manage the security of large networks?

Options:

A.

By dividing networks into separate network domains and separating them from the public network

B.

By dividing networks into separate network domains and including them into the public network

C.

By avoiding the integration of information services, users, and information systems into large networks

Questions # 10:

What should NOT be taken into account when locating and constructing physical premises?

Options:

A.

Local topography

B.

Urban threats

C.

System requirements

Viewing page 1 out of 2 pages
Viewing questions 1-10 out of questions