Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free GAQM ISO 27001 : 2013 - Certified Lead Auditor ISO27-13-001 Exam Questions

Page: 1 / 10 Total 100 questions

Want more questions? Get Premium Access.

Question 1

Which threat could occur if no physical measures are taken?

Correct Answer: C. A server shutting down because of overheating

Question 2

The following are definitions of Information, except:

Correct Answer: C. mature and measurable data

Question 3

There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the entire premises. The server, however, was destroyed in the fire. The backup tapes kept in another room had melted and many other documents were lost for good.

What is an example of the indirect damage caused by this fire?

Correct Answer: D. Water damage due to the fire extinguishers

Question 4

Which of the following is a preventive security measure?

Correct Answer: C. Storing sensitive information in a data save

Question 5

-------------------------is an asset like other important business assets has value to an organization and consequently needs to be protected.

Correct Answer: C. Information

Question 6

A couple of years ago you started your company which has now grown from 1 to 20 employees. Your company's information is worth more and more and gone are the days when you could keep control yourself. You are aware that you have to take measures, but what should they be? You hire a consultant who advises you to start with a qualitative risk analysis.

What is a qualitative risk analysis?

Correct Answer: B. This analysis is based on scenarios and situations and produces a subjective view of the possible threats.

Question 7

Who are allowed to access highly confidential files?

Correct Answer: C. Employees with signed NDA have a business need-to-know

Question 8

What is the name of the system that guarantees the coherence of information security in the organization?

Correct Answer: A. Information Security Management System (ISMS)

Question 9

In the event of an Information security incident, system users' roles and responsibilities are to be observed, except:

Correct Answer: D. Make the information security incident details known to all employees

Question 10

Four types of Data Classification (Choose two)

Correct Answer: A. Restricted Data, Confidential Data; D. Unrestricted Data, Highly Confidential Data