
Latest ISFS Practice Test Questions Verified Answers As Experienced in the Actual Test!
Pass EXIN ISFS Exam in First Attempt Easily
NEW QUESTION 10
You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- A. A code of conduct helps to prevent the misuse of IT facilities.
- B. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
- C. A code of conduct prevents a virus outbreak.
- D. A code of conduct is a legal obligation that organizations have to meet.
Answer: A
NEW QUESTION 11
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk.
He asks you for your password. What kind of threat is this?
- A. Social Engineering
- B. Organizational threat
- C. Natural threat
Answer: A
NEW QUESTION 12
What action is an unintentional human threat?
- A. Social engineering
- B. Arson
- C. Theft of a laptop
- D. Incorrect use of fire extinguishing equipment
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 13
Your company has to ensure that it meets the requirements set down in personal data protection legislation. What is the first thing you should do?
- A. Make the employees responsible for submitting their personal data.
- B. Appoint a person responsible for supporting managers in adhering to the policy.
- C. Translate the personal data protection legislation into a privacy policy that is geared to the company and the contracts with the customers.
- D. Issue a ban on the provision of personal information.
Answer: C
NEW QUESTION 14
You are the owner of the courier company SpeeDelivery. You employ a few people who, while waiting to make a delivery, can carry out other tasks. You notice, however, that they use this time to send and read their private mail and surf the Internet. In legal terms, in which way can the use of the Internet and e-mail facilities be best regulated?
- A. Installing an application that makes certain websites no longer accessible and that filters attachments in e-mails
- B. Installing a virus scanner
- C. Drafting a code of conduct for the use of the Internet and e-mail in which the rights and obligations of both the employer and staff are set down
- D. Implementing privacy regulations
Answer: C
NEW QUESTION 15
What is the objective of classifying information?
- A. Creating a label that indicates how confidential the information is
- B. Defining different levels of sensitivity into which information may be arranged
- C. Displaying on the document who is permitted access
- D. Authorizing the use of an information system
Answer: B
NEW QUESTION 16
You work for a flexible employer who doesnt mind if you work from home or on the road. You regularly take copies of documents with you on a USB memory stick that is not secure. What are the consequences for the reliability of the information if you leave your USB memory stick behind on the train?
- A. The confidentiality of the data on the USB memory stick is no longer guaranteed.
- B. The availability of the data on the USB memory stick is no longer guaranteed.
- C. The integrity of the data on the USB memory stick is no longer guaranteed.
Answer: A
NEW QUESTION 17
A couple of years ago you started your company which has now grown from 1 to 20 employees.
Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be?
You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
Explanation:
Explanation
NEW QUESTION 18
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of the threats and risks.
What is the relation between a threat, risk and risk analysis?
- A. A risk analysis is used to clarify which threats are relevant and what risks they involve.
- B. A risk analysis is used to remove the risk of a threat.
- C. A risk analysis identifies threats from the known risks.
- D. Risk analyses help to find a balance between threats and risks.
Answer: A
NEW QUESTION 19
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
NEW QUESTION 20
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- A. No
- B. Yes
Answer: A
NEW QUESTION 21
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?
- A. Social Engineering
- B. Organizational threat
- C. Natural threat
Answer: A
NEW QUESTION 22
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization.
What occurs during the first step of this process: identification?
- A. The first step consists of granting access to the information to which the user is authorized.
- B. The first step consists of comparing the password with the registered password.
- C. The first step consists of checking if the user appears on the list of authorized users.
- D. The first step consists of checking if the user is using the correct certificate.
Answer: C
NEW QUESTION 23
Your company is in the news as a result of an unfortunate action by one of your employees. The phones are ringing off the hook with customers wanting to cancel their contracts. What do we call this type of damage?
- A. Direct damage
- B. Indirect damage
Answer: B
NEW QUESTION 24
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- A. When computer systems are kept in a cellar below ground level.
- B. When the computer systems are not insured.
- C. When the organization is located near a river.
- D. If the risk analysis has not been carried out.
Answer: A
NEW QUESTION 25
The consultants at Smith Consultants Inc. work on laptops that are protected by asymmetrical cryptography. To keep the management of the keys cheap, all consultants use the same key pair. What is the companys risk if they operate in this manner?
- A. If the private key becomes known all laptops must be supplied with new keys.
- B. If the public key becomes known all laptops must be supplied with new keys.
- C. If the Public Key Infrastructure (PKI) becomes known all laptops must be supplied with new keys.
Answer: A
NEW QUESTION 26
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
- A. Paul and Susan, the sender and the recipient of the information.
- B. Paul, the recipient of the information.
- C. Susan, the sender of the information.
Answer: B
NEW QUESTION 27
......
We offers you the latest free online ISFS dumps to practice: https://www.surepassexams.com/ISFS-exam-bootcamp.html
The Most Efficient ISFS Pdf Dumps For Assured Success : https://drive.google.com/open?id=1D1Xk2R5fEKqrDlZtDVpLJthnIRgDn4wT