
[Jan 23, 2023] 100% Latest Most updated ISFS Questions and Answers
Try with 100% Real Exam Questions and Answers
NEW QUESTION 24
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization.
What occurs during the first step of this process: identification?
- A. The first step consists of comparing the password with the registered password.
- B. The first step consists of checking if the user appears on the list of authorized users.
- C. The first step consists of granting access to the information to which the user is authorized.
- D. The first step consists of checking if the user is using the correct certificate.
Answer: B
NEW QUESTION 25
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports. Which reliability aspect of the information in your reports must you protect?
- A. Confidentiality
- B. Availability
- C. Integrity
Answer: A
NEW QUESTION 26
What is an example of a non-human threat to the physical environment?
- A. Storm
- B. Corrupted file
- C. Fraudulent transaction
- D. Virus
Answer: A
NEW QUESTION 27
What action is an unintentional human threat?
- A. Theft of a laptop
- B. Incorrect use of fire extinguishing equipment
- C. Arson
- D. Social engineering
Answer: B
NEW QUESTION 28
What is the relationship between data and information?
- A. Information is the meaning and value assigned to a collection of data.
- B. Data is structured information.
Answer: A
NEW QUESTION 29
You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so important to have an information security policy as a starting point?
- A. The information security policy gives direction to the information security efforts.
- B. The information security policy establishes who is responsible for which area of information security.
- C. The information security policy supplies instructions for the daily practice of information security.
- D. The information security policy establishes which devices will be protected.
Answer: A
NEW QUESTION 30
A Dutch company requests to be listed on the American Stock Exchange. Which legislation within the scope of information security is relevant in this case?
- A. Public Records Act
- B. Dutch Tax Law
- C. Sarbanes-Oxley Act
- D. Security regulations for the Dutch government
Answer: C
NEW QUESTION 31
My user profile specifies which network drives I can read and write to. What is the name of the type of logical access management wherein my access and rights are determined centrally?
- A. Mandatory Access Control (MAC)
- B. Public Key Infrastructure (PKI)
- C. Discretionary Access Control (DAC)
Answer: A
NEW QUESTION 32
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your companys information is worth more and more and gone are the days when you could keep it all in hand yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis. What is a qualitative risk analysis?
- A. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.
- B. This analysis follows a precise statistical probability calculation in order to calculate exact loss caused by damage.
Answer: A
NEW QUESTION 33
A well executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives. What is not one of the four main objectives of a risk analysis?
- A. Determining the costs of threats
- B. Establishing a balance between the costs of an incident and the costs of a security measure
- C. Determining relevant vulnerabilities and threats
- D. Identifying assets and their value
Answer: A
NEW QUESTION 34
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequences of this to the reliability of the information?
- A. The confidentiality of the information is no longer guaranteed.
- B. The availability of the information is no longer guaranteed.
- C. The integrity of the information is no longer guaranteed.
Answer: A
Explanation:
Explanation
NEW QUESTION 35
Who is authorized to change the classification of a document?
- A. The owner of the document
- B. The administrator of the document
- C. The author of the document
- D. The manager of the owner of the document
Answer: A
NEW QUESTION 36
You are the first to arrive at work in the morning and notice that the CD ROM on which you saved contracts yesterday has disappeared. You were the last to leave yesterday. When should you report this information security incident?
- A. You should first investigate this incident yourself and try to limit the damage.
- B. This incident should be reported immediately.
- C. You should wait a few days before reporting this incident. The CD ROM can still reappear and, in that case, you will have made a fuss for nothing.
Answer: B
NEW QUESTION 37
What is the most important reason for applying segregation of duties?
- A. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
- B. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
- C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
- D. Segregation of duties makes it clear who is responsible for what.
Answer: C
Explanation:
Explanation
NEW QUESTION 38
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- A. Yes
- B. No
Answer: B
Explanation:
Explanation
NEW QUESTION 39
......
New EXIN ISFS Dumps & Questions: https://www.prep4sureexam.com/ISFS-dumps-torrent.html
Dumps to Pass your ISFS Exam with 100% Real Questions and Answers: https://drive.google.com/open?id=1TDs_Xp6Q0MRMK7L3HPz1WX39lnV9aFgk