
Latest EXIN ISFS First Attempt, Exam real Dumps Updated [Jul-2021]
Get the superior quality ISFS Dumps Questions from Actualtests4sure. Nobody can stop you from getting to your dreams now. Your bright future is just a click away!
NEW QUESTION 40
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?
- A. Set up an access control policy
- B. Appoint security personnel
- C. Encrypt the hard drives of laptops and USB sticks
- D. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)
Answer: D
Explanation:
Explanation/Reference:
NEW QUESTION 41
Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of which are used for a call centre 24 hours per day. Five workstations must always be available. What physical security measures must be taken in order to ensure this?
- A. Obtain an extra office and provide a UPS (Uninterruptible Power Supply) for the five most important workstations.
- B. Obtain an extra office and connect all 10 new workstations to an emergency power supply and UPS (Uninterruptible Power Supply). Adjust the access control system to the working hours of the new staff. Inform the building security personnel that work will also be carried out in the evenings and at night.
- C. Obtain an extra office and set up 10 workstations. You would therefore have spare equipment that can be used to replace any non-functioning equipment.
- D. Obtain an extra office and set up 10 workstations. Ensure that there are security personnel both in the evenings and at night, so that staff can work there safely and securely.
Answer: B
NEW QUESTION 42
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?
- A. Organizational threat
- B. Social Engineering
- C. Natural threat
Answer: B
NEW QUESTION 43
Which of these is not malicious software?
- A. Worm
- B. Spyware
- C. Phishing
- D. Virus
Answer: C
NEW QUESTION 44
Which type of malware builds a network of contaminated computers?
- A. Storm Worm or Botnet
- B. Trojan
- C. Logic Bomb
- D. Virus
Answer: A
NEW QUESTION 45
Why is compliance important for the reliability of the information?
- A. By meeting the legislative requirements and the regulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
- B. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
- C. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
- D. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and therefore it guarantees the reliability of its information.
Answer: A
NEW QUESTION 46
You are the owner of the courier company SpeeDelivery. On the basis of your risk analysis you have decided to take a number of measures. You have daily backups made of the server, keep the server room locked and install an intrusion alarm system and a sprinkler system. Which of these measures is a detective measure?
- A. Backup tape
- B. Sprinkler installation
- C. Intrusion alarm
- D. Access restriction to special rooms
Answer: C
NEW QUESTION 47
What is the most important reason for applying segregation of duties?
- A. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
- B. Segregation of duties makes it clear who is responsible for what.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
Answer: C
NEW QUESTION 48
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- A. No
- B. Yes
Answer: A
Explanation:
Explanation
NEW QUESTION 49
What is the relationship between data and information?
- A. Data is structured information.
- B. Information is the meaning and value assigned to a collection of data.
Answer: B
Explanation:
Explanation
NEW QUESTION 50
What physical security measure is necessary to control access to company information?
- A. Air-conditioning
- B. Username and password
- C. Prohibiting the use of USB sticks
- D. The use of break-resistant glass and doors with the right locks, frames and hinges
Answer: D
NEW QUESTION 51
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequences of this to the reliability of the information?
- A. The confidentiality of the information is no longer guaranteed.
- B. The integrity of the information is no longer guaranteed.
- C. The availability of the information is no longer guaranteed.
Answer: A
NEW QUESTION 52
Who is authorized to change the classification of a document?
- A. The owner of the document
- B. The manager of the owner of the document
- C. The administrator of the document
- D. The author of the document
Answer: A
NEW QUESTION 53
Which of the following measures is a preventive measure?
- A. Putting sensitive information in a safe
- B. Installing a logging system that enables changes in a system to be recognized
- C. Classifying a risk as acceptable because the cost of addressing the threat is higher than the value of the information at risk
- D. Shutting down all internet traffic after a hacker has gained access to the company systems
Answer: A
NEW QUESTION 54
Why is air-conditioning placed in the server room?
- A. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
- B. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
- C. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
- D. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted.
The air in the room is also dehumidified and filtered.
Answer: D
NEW QUESTION 55
A well executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives. What is not one of the four main objectives of a risk analysis?
- A. Identifying assets and their value
- B. Determining relevant vulnerabilities and threats
- C. Determining the costs of threats
- D. Establishing a balance between the costs of an incident and the costs of a security measure
Answer: C
NEW QUESTION 56
Your company has to ensure that it meets the requirements set down in personal data protection legislation. What is the first thing you should do?
- A. Translate the personal data protection legislation into a privacy policy that is geared to the company and the contracts with the customers.
- B. Make the employees responsible for submitting their personal data.
- C. Issue a ban on the provision of personal information.
- D. Appoint a person responsible for supporting managers in adhering to the policy.
Answer: A
NEW QUESTION 57
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good. What is an example of the indirect damage caused by this fire?
- A. Water damage due to the fire extinguishers
- B. Melted backup tapes
- C. Burned documents
- D. Burned computer systems
Answer: A
NEW QUESTION 58
What is a risk analysis used for?
- A. A risk analysis is used to express the value of information for an organization in monetary terms.
- B. A risk analysis is used in conjunction with security measures to reduce risks to an acceptable level.
- C. A risk analysis is used to ensure that security measures are deployed in a cost-effective and timely fashion.
- D. A risk analysis is used to clarify to management their responsibilities.
Answer: C
NEW QUESTION 59
Your company is in the news as a result of an unfortunate action by one of your employees. The phones are ringing off the hook with customers wanting to cancel their contracts. What do we call this type of damage?
- A. Indirect damage
- B. Direct damage
Answer: A
NEW QUESTION 60
Which of the following measures is a corrective measure?
- A. Incorporating an Intrusion Detection System (IDS) in the design of a computer centre
- B. Restoring a backup of the correct database after a corrupt copy of the database was written over the original
- C. Installing a virus scanner in an information system
- D. Making a backup of the data that has been created or altered that day
Answer: B
NEW QUESTION 61
......
EXIN Practice Test Engine with ISFS Questions: https://drive.google.com/open?id=1R7pC5PLoVfO3ZNUveWgUhZYR0njqlDjm
Guaranteed Success with Valid EXIN ISFS Dumps: https://www.actualtests4sure.com/ISFS-test-questions.html

