
Authentic EXIN ISFS Exam Dumps PDF - Aug-2022 Updated
ISFS Dumps Special Discount for limited time Try FOR FREE
What is the duration of the ISFS Exam
- Length of Examination: 1 hour
- Number of Questions: 40
- Format: Multiple choices, multiple answers
- Passing Score: 65%
For more info visit:
NEW QUESTION 10
A couple of years ago you started your company which has now grown from 1 to 20 employees.
Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be?
You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
Explanation:
Explanation
NEW QUESTION 11
At Midwest Insurance, all information is classified. What is the goal of this classification of information?
- A. To create a manual about how to handle mobile devices
- B. Applying labels making the information easier to recognize
- C. Structuring information according to its sensitivity
Answer: C
NEW QUESTION 12
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?
- A. Risk avoiding
- B. Risk neutral
- C. Risk bearing
Answer: B
NEW QUESTION 13
The Information Security Manager (ISM) at Smith Consultants Inc. introduces the following measures to assure information security:
-The security requirements for the network are specified.
-A test environment is set up for the purpose of testing reports coming from the database.
-The various employee functions are assigned corresponding access rights.
-
RFID access passes are introduced for the building. Which one of these measures is not a technical measure?
- A. Introducing a logical access policy
- B. The specification of requirements for the network
- C. Setting up a test environment
- D. Introducing RFID access passes
Answer: D
NEW QUESTION 14
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What type of measure could prevent this error?
- A. Organizational measure
- B. Integrity measure
- C. Technical measure
- D. Availability measure
Answer: C
NEW QUESTION 15
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?
- A. Encryption of information
- B. Validation of input and output data in applications
- C. The use of tokens to gain access to information systems
- D. Information Security Management System
Answer: D
NEW QUESTION 16
What is an example of a physical security measure?
- A. Special fire extinguishers with inert gas, such as Argon
- B. The encryption of confidential information
- C. An access control policy with passes that have to be worn visibly
- D. A code of conduct that requires staff to adhere to the clear desk policy, ensuring that confidential information is not left visibly on the desk at the end of the work day
Answer: A
NEW QUESTION 17
Three characteristics determine the reliability of information. Which characteristics are these?
- A. Availability, Integrity and Confidentiality
- B. Availability, Nonrepudiation and Confidentiality
- C. Availability, Integrity and Correctness
Answer: A
NEW QUESTION 18
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- A. No
- B. Yes
Answer: A
NEW QUESTION 19
What action is an unintentional human threat?
- A. Theft of a laptop
- B. Social engineering
- C. Incorrect use of fire extinguishing equipment
- D. Arson
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 20
What is the most important reason for applying segregation of duties?
- A. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
- B. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- C. Segregation of duties makes it clear who is responsible for what.
- D. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
Answer: B
NEW QUESTION 21
Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of which are used for a call centre 24 hours per day. Five workstations must always be available. What physical security measures must be taken in order to ensure this?
- A. Obtain an extra office and set up 10 workstations. Ensure that there are security personnel both in the evenings and at night, so that staff can work there safely and securely.
- B. Obtain an extra office and connect all 10 new workstations to an emergency power supply and UPS (Uninterruptible Power Supply). Adjust the access control system to the working hours of the new staff.
Inform the building security personnel that work will also be carried out in the evenings and at night. - C. Obtain an extra office and provide a UPS (Uninterruptible Power Supply) for the five most important workstations.
- D. Obtain an extra office and set up 10 workstations. You would therefore have spare equipment that can be used to replace any non-functioning equipment.
Answer: B
NEW QUESTION 22
In most organizations, access to the computer or the network is granted only after the user has entered a correct username and password. This process consists of 3 steps: identification, authentication and authorization. What is the purpose of the second step, authentication?
- A. During the authentication step, the system gives you the rights that you need, such as being able to read the data in the system.
- B. In the second step, you make your identity known, which means you are given access to the system.
- C. The system determines whether access may be granted by determining whether the token used is authentic.
- D. The authentication step checks the username against a list of users who have access to the system.
Answer: C
NEW QUESTION 23
You work for a flexible employer who doesnt mind if you work from home or on the road. You regularly take copies of documents with you on a USB memory stick that is not secure. What are the consequences for the reliability of the information if you leave your USB memory stick behind on the train?
- A. The integrity of the data on the USB memory stick is no longer guaranteed.
- B. The availability of the data on the USB memory stick is no longer guaranteed.
- C. The confidentiality of the data on the USB memory stick is no longer guaranteed.
Answer: C
NEW QUESTION 24
Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of which are used for a call centre 24 hours per day. Five workstations must always be available. What physical security measures must be taken in order to ensure this?
- A. Obtain an extra office and set up 10 workstations. Ensure that there are security personnel both in the evenings and at night, so that staff can work there safely and securely.
- B. Obtain an extra office and provide a UPS (Uninterruptible Power Supply) for the five most important workstations.
- C. Obtain an extra office and set up 10 workstations. You would therefore have spare equipment that can be used to replace any non-functioning equipment.
- D. Obtain an extra office and connect all 10 new workstations to an emergency power supply and UPS (Uninterruptible Power Supply). Adjust the access control system to the working hours of the new staff. Inform the building security personnel that work will also be carried out in the evenings and at night.
Answer: D
NEW QUESTION 25
You own a small company in a remote industrial areA. Lately, the alarm regularly goes off in the middle of the night. It takes quite a bit of time to respond to it and it seems to be a false alarm every time. You decide to set up a hidden camerA. What is such a measure called?
- A. Repressive measure
- B. Preventive measure
- C. Detective measure
Answer: C
Explanation:
Explanation/Reference:
NEW QUESTION 26
......
Exin Information Security Foundation (based on ISO/IEC 27002) (EX0-105) ISFS Exam
Exin Information Security Foundation (based on ISO/IEC 27002) (EX0-105) ISFS Exam which is related to Exin Information Security Foundation based on ISO/IEC 27002 and credits toward Exin Information Security Management Certification. This exam validates the Candidate knowledge and skills of the concept of Information, relationships between threats, risks and the reliability of the information, importance of measures, physical security, technical measures, measures security policy and security organization.
ISFS Dumps for success in Actual Exam: https://www.passleader.top/EXIN/ISFS-exam-braindumps.html
Realistic ISFS 100% Pass Guaranteed Download Exam Q&A: https://drive.google.com/open?id=11O0S-Z4HaCty92rCHjAyFrJxBjiAN5Gb