ISFS Exam Questions
90 real ISFS exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1
What is a risk analysis used for?
- Question #2
A well executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives. What is not one of the four main objectives of a risk analysis?
- Question #3
What is an example of a security incident?
- Question #4
Which of the following measures is a corrective measure?
- Question #5
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
- Question #6
What is an example of a non-human threat to the physical environment?
- Question #7
In most organizations, access to the computer or the network is granted only after the user has entered a correct username and password. This process consists of 3 steps: identific...
- Question #8
Which of these is not malicious software?
- Question #9
Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?
- Question #10
What is the definition of the Annual Loss Expectancy?
- Question #11
What is the most important reason for applying segregation of duties?
- Question #12
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
- Question #13
Why is compliance important for the reliability of the information?
- Question #14
You are the owner of the courier company SpeeDelivery. On the basis of your risk analysis you have decided to take a number of measures. You have daily backups made of the server,...
- Question #16
Which type of malware builds a network of contaminated computers?
- Question #17
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?
- Question #18
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business...
- Question #19
Your company is in the news as a result of an unfortunate action by one of your employees. The phones are ringing off the hook with customers wanting to cancel their contracts. Wha...
- Question #20
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
- Question #21
Under which condition is an employer permitted to check if Internet and email services in the workplace are being used for private purposes?
- Question #22
You have a small office in an industrial areA. You would like to analyze the risks your company faces. The office is in a pretty remote location; therefore, the possibility of arso...
- Question #23
You work for a flexible employer who doesnt mind if you work from home or on the road. You regularly take copies of documents with you on a USB memory stick that is not secure. Wha...
- Question #24
What is the best way to comply with legislation and regulations for personal data protection?
- Question #25
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the e...
- Question #26
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequ...
- Question #28
What is a human threat to the reliability of the information on your company website?
- Question #29
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigne...
- Question #30
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this...
- Question #31
In the organization where you work, information of a very sensitive nature is processed. Management is legally obliged to implement the highest-level security measures. What is thi...
- Question #32
The act of taking organizational security measures is inextricably linked with all other measures that have to be taken. What is the name of the system that guarantees the coherenc...
- Question #33
You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy....
- Question #34
What is a repressive measure in the case of a fire?
- Question #35
The consultants at Smith Consultants Inc. work on laptops that are protected by asymmetrical cryptography. To keep the management of the keys cheap, all consultants use the same ke...
- Question #36
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This inclu...
- Question #37
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
- Question #38
My user profile specifies which network drives I can read and write to. What is the name of the type of logical access management wherein my access and rights are determined centra...
- Question #39
Some security measures are optional. Other security measures must always be implemented. Which measure(s) must always be implemented?
- Question #40
Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure. What are some other measures?
- Question #41
You are the owner of the SpeeDelivery courier service. Last year you had a firewall installed. You now discover that no maintenance has been performed since the installation. What...
- Question #42
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your companys information is worth more and more and gone are the days when you could kee...
- Question #43
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
- Question #44
Which measure assures that valuable information is not left out available for the taking?
- Question #45
What is an example of a good physical security measure?
- Question #46
You read in the newspapers that the ex-employee of a large company systematically deleted files out of revenge on his manager. Recovering these files caused great losses in time an...
- Question #47
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
- Question #48
You are the first to arrive at work in the morning and notice that the CD ROM on which you saved contracts yesterday has disappeared. You were the last to leave yesterday. When sho...
- Question #49
A Dutch company requests to be listed on the American Stock Exchange. Which legislation within the scope of information security is relevant in this case?
- Question #50
You own a small company in a remote industrial areA. Lately, the alarm regularly goes off in the middle of the night. It takes quite a bit of time to respond to it and it seems to...
- Question #51
At Midwest Insurance, all information is classified. What is the goal of this classification of information?
- Question #52
Which one of the threats listed below can occur as a result of the absence of a physical measure?