無料でゲット!2023年最新の有効な練習Exin Certification ISFS問題と解答でテストエンジン [Q39-Q63]

Share

無料でゲット!最新の2023年最新の有効な練習Exin Certification ISFS問題と解答でテストエンジン

ISFS問題集PDFで100%合格保証付き

質問 # 39
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?

  • A. Availability, Information Value and Confidentiality
  • B. Timeliness, Accuracy and Completeness
  • C. Availability, Integrity and Confidentiality
  • D. Availability, Integrity and Completeness

正解:C


質問 # 40
You work for a large organization. You notice that you have access to confidential information that you should not be able to access in your position. You report this security incident to the helpdesk. The incident cycle isinitiated. What are the stages of the security incident cycle?

  • A. Threat, Recovery, Incident, Damage
  • B. Threat, Incident, Damage, Recovery
  • C. Threat, Damage, Recovery, Incident
  • D. Threat, Damage, Incident, Recovery

正解:B


質問 # 41
What is the most important reason for applying segregation of duties?

  • A. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
  • B. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
  • C. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
  • D. Segregation of duties makes it clear who is responsible for what.

正解:A


質問 # 42
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization.
What occurs during the first step of this process: identification?

  • A. The first step consists of granting access to the information to which the user is authorized.
  • B. The first step consists of comparing the password with the registered password.
  • C. The first step consists of checking if the user appears on the list of authorized users.
  • D. The first step consists of checking if the user is using the correct certificate.

正解:C


質問 # 43
What is the relationship between data and information?

  • A. Information is the meaning and value assigned to a collection of data.
  • B. Data is structured information.

正解:A

解説:
Explanation


質問 # 44
You are the owner of the courier company SpeeDelivery. On the basis of your risk analysis you have decided to take a number of measures. You have daily backups made of the server, keep the server room locked and install an intrusion alarm system and a sprinkler system. Which of these measures is a detective measure?

  • A. Access restriction to special rooms
  • B. Backup tape
  • C. Sprinkler installation
  • D. Intrusion alarm

正解:D


質問 # 45
Why is air-conditioning placed in the server room?

  • A. When a company wishes to cool its offices, the server room is the best place. This way, no office space needs to be sacrificed for such a large piece of equipment.
  • B. It is not pleasant for the maintenance staff to have to work in a server room that is too warm.
  • C. Backup tapes are made from thin plastic which cannot withstand high temperatures. Therefore, if it gets too hot in a server room, they may get damaged.
  • D. In the server room the air has to be cooled and the heat produced by the equipment has to be extracted. The air in the room is also dehumidified and filtered.

正解:D


質問 # 46
When we are at our desk, we want the information system and the necessary information to be available. We want to be able to work with the computer and access the network and our files.
What is the correct definition of availability?

  • A. The degree to which an information system is available for the users
  • B. The total amount of time that an information system is accessible to the users
  • C. The degree to which the system capacity is enough to allow all users to work with it
  • D. The degree to which the continuity of an organization is guaranteed

正解:A

解説:
Explanation/Reference:


質問 # 47
In the organization where you work, information of a very sensitive nature is processed.
Management is legally obliged to implement the highest-level security measures. What is this kind of risk strategy called?

  • A. Risk bearing
  • B. Risk avoiding
  • C. Risk neutral

正解:B


質問 # 48
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?

  • A. Encrypt the hard drives of laptops and USB sticks
  • B. Set up an access control policy
  • C. Appoint security personnel
  • D. Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)

正解:D


質問 # 49
What action is an unintentional human threat?

  • A. Incorrect use of fire extinguishing equipment
  • B. Theft of a laptop
  • C. Arson
  • D. Social engineering

正解:A


質問 # 50
The consultants at Smith Consultants Inc. work on laptops that are protected by asymmetrical cryptography. To keep the management of the keys cheap, all consultants use the same key pair. What is the companys risk if they operate in this manner?

  • A. If the public key becomes known all laptops must be supplied with new keys.
  • B. If the Public Key Infrastructure (PKI) becomes known all laptops must be supplied with new keys.
  • C. If the private key becomes known all laptops must be supplied with new keys.

正解:C


質問 # 51
Under which condition is an employer permitted to check if Internet and email services in the workplace are being used for private purposes?

  • A. The employer is permitted to check this if the employee is informed after each instance of checking.
  • B. The employer is permitted to check this if the employees are aware that this could happen.
  • C. The employer is permitted to check this if a firewall is also installed.
  • D. The employer is in no way permitted to check the use of IT services by employees.

正解:B


質問 # 52
What is an example of a security incident?

  • A. A member of staff loses a laptop.
  • B. A file is saved under an incorrect name.
  • C. The lighting in the department no longer works.
  • D. You cannot set the correct fonts in your word processing software.

正解:A


質問 # 53
Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure. What are some other measures?

  • A. Detective, repressive and corrective measures
  • B. Repressive, adaptive and corrective measures
  • C. Partial, adaptive and corrective measures

正解:A


質問 # 54
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?

  • A. No
  • B. Yes

正解:A

解説:
Explanation


質問 # 55
What is an example of a physical security measure?

  • A. Special fire extinguishers with inert gas, such as Argon
  • B. A code of conduct that requires staff to adhere to the clear desk policy, ensuring that confidential information is not left visibly on the desk at the end of the work day
  • C. The encryption of confidential information
  • D. An access control policy with passes that have to be worn visibly

正解:A


質問 # 56
Which type of malware builds a network of contaminated computers?

  • A. Storm Worm or Botnet
  • B. Logic Bomb
  • C. Trojan
  • D. Virus

正解:A


質問 # 57
Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of which are used for a call centre 24 hours per day. Five workstations must always be available. What physical security measures must be taken in order to ensure this?

  • A. Obtain an extra office and connect all 10 new workstations to an emergency power supply and UPS (Uninterruptible Power Supply). Adjust the access control system to the working hours of the new staff.
    Inform the building security personnel that work will also be carried out in the evenings and at night.
  • B. Obtain an extra office and provide a UPS (Uninterruptible Power Supply) for the five most important workstations.
  • C. Obtain an extra office and set up 10 workstations. Ensure that there are security personnel both in the evenings and at night, so that staff can work there safely and securely.
  • D. Obtain an extra office and set up 10 workstations. You would therefore have spare equipment that can be used to replace any non-functioning equipment.

正解:A


質問 # 58
Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?

  • A. Lightning strike
  • B. Arson
  • C. Flood
  • D. Loss of a USB stick

正解:B


質問 # 59
In the organization where you work, information of a very sensitive nature is processed. Management is legally obliged to implement the highest-level security measures. What is this kind of risk strategy called?

  • A. Risk bearing
  • B. Risk avoiding
  • C. Risk neutral

正解:B


質問 # 60
What is a risk analysis used for?

  • A. A risk analysis is used to express the value of information for an organization in monetary terms.
  • B. A risk analysis is used in conjunction with security measures to reduce risks to an acceptable level.
  • C. A risk analysis is used to clarify to management their responsibilities.
  • D. A risk analysis is used to ensure that security measures are deployed in a cost-effective and timely fashion.

正解:D


質問 # 61
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an inventory of the threats and risks. What is the relation between a threat, risk and risk analysis?

  • A. A risk analysis is used to remove the risk of a threat.
  • B. A risk analysis is used to clarify which threats are relevant and what risks they involve.
  • C. Risk analyses help to find a balance between threats and risks.
  • D. A risk analysis identifies threats from the known risks.

正解:B


質問 # 62
What is an example of a good physical security measure?

  • A. Maintenance staff can be given quick and unimpeded access to the server area in the event of disaster.
  • B. Printers that are defective or have been replaced are immediately removed and given away as garbage for recycling.
  • C. All employees and visitors carry an access pass.

正解:C


質問 # 63
......

ISFSブレーン問題集リアル試験最新問題2023年10月11日には80問題:https://www.passtest.jp/EXIN/ISFS-shiken.html

最新ISFS問題集リアル無料テストPDF本日更新です:https://drive.google.com/open?id=1CQnQ_aptv3QAyUi7FZFd7rAMmbDRaoPX