ISFS Exam Questions
90 real ISFS exam questions with expert-verified answers and explanations. Page 1 of 2.
- Question #1Risk and security management
What is a risk analysis used for?
risk analysissecurity measurescost-effectivenessrisk management - Question #2Risk and security management
A well executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives. What is not one of the four main objectives of a risk analysis?
risk analysis objectivesasset identificationvulnerability assessmentthreat determination - Question #3Information security incident management
What is an example of a security incident?
security incidentlost laptopincident identificationinformation security - Question #4Outlining security controls
Which of the following measures is a corrective measure?
corrective controlsbackup recoverycontrol typesincident response - Question #5Reliability aspects
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
CIA triadavailabilityintegrityconfidentiality - Question #6Threats and risks
What is an example of a non-human threat to the physical environment?
non-human threatsnatural threatsphysical threatsthreat classification - Question #7Access control
In most organizations, access to the computer or the network is granted only after the user has entered a correct username and password. This process consists of 3 steps: identific...
authenticationidentificationauthorizationaccess control process - Question #8Threats and risks
Which of these is not malicious software?
malwarephishingspywaremalicious software - Question #9Threats and risks
Some threats are caused directly by people, others have a natural cause. What is an example of an intentional human threat?
intentional human threatarsonthreat classificationdeliberate threats - Question #10Risk and security management
What is the definition of the Annual Loss Expectancy?
Annual Loss ExpectancyALErisk quantificationincident damage - Question #11Organizational controls
What is the most important reason for applying segregation of duties?
segregation of dutiesfraud preventionaccess controlorganizational control - Question #12Physical and environmental security
A non-human threat for computer systems is a flood. In which situation is a flood always a relevant threat?
physical threatflood riskenvironmental controlsdata center location - Question #13Compliance
Why is compliance important for the reliability of the information?
compliancelegislative requirementsreliabilityregulations - Question #14Outlining security controls
You are the owner of the courier company SpeeDelivery. On the basis of your risk analysis you have decided to take a number of measures. You have daily backups made of the server,...
detective controlsintrusion alarmcontrol typessecurity measures - Question #16Threats and risks
Which type of malware builds a network of contaminated computers?
botnetStorm Wormmalware typesnetwork infection - Question #17Threats and risks
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?
social engineeringpassword thefthuman threathelpdesk impersonation - Question #18Reliability aspects
You are a consultant and are regularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business...
confidentialityCIA triaddata protectionaccess restriction - Question #19Risk and security management
Your company is in the news as a result of an unfortunate action by one of your employees. The phones are ringing off the hook with customers wanting to cancel their contracts. Wha...
indirect damagereputational damageincident impactdamage types - Question #20Information security incident management
An airline company employee notices that she has access to one of the company's applications that she has not used before. Is this an information security incident?
security incidentunauthorized accessincident definitionaccess management - Question #21Legislation and regulations
Under which condition is an employer permitted to check if Internet and email services in the workplace are being used for private purposes?
employee monitoringprivacy legislationacceptable use policyemployer rights - Question #22Threats and risks
You have a small office in an industrial areA. You would like to analyze the risks your company faces. The office is in a pretty remote location; therefore, the possibility of arso...
threatriskrisk calculationfire threat - Question #23Reliability aspects
You work for a flexible employer who doesnt mind if you work from home or on the road. You regularly take copies of documents with you on a USB memory stick that is not secure. Wha...
confidentialityremovable mediadata lossinformation reliability - Question #24Legislation and regulations
What is the best way to comply with legislation and regulations for personal data protection?
personal data protectionlegislation complianceaccountabilityresponsibility assignment - Question #25Threats and risks
There was a fire in a branch of the company Midwest Insurance. The fire department quickly arrived at the scene and could extinguish the fire before it spread and burned down the e...
direct damageindirect damagefire incidentbusiness impact - Question #26Reliability aspects
There is a network printer in the hallway of the company where you work. Many employees dont pick up their printouts immediately and leave them in the printer. What are the consequ...
confidentialityphysical securityprint securityinformation reliability - Question #28Threats and risks
What is a human threat to the reliability of the information on your company website?
human threatthreat classificationwebsite integrityaccidental error - Question #29Asset management
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigne...
information classificationsensitivity labelsdata gradingasset management - Question #30Access control
Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this...
identificationauthenticationauthorizationaccess control process - Question #31Risk and security management
In the organization where you work, information of a very sensitive nature is processed. Management is legally obliged to implement the highest-level security measures. What is thi...
risk avoidancerisk strategylegal obligationrisk management - Question #32Organizing information security
The act of taking organizational security measures is inextricably linked with all other measures that have to be taken. What is the name of the system that guarantees the coherenc...
ISMSinformation security management systemorganizational coherencesecurity framework - Question #33Information security policy
You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy....
information security policypolicy directionstrategic planningsecurity governance - Question #34Outlining security controls
What is a repressive measure in the case of a fire?
repressive measurefire responsemeasure typessecurity controls - Question #35Technical controls
The consultants at Smith Consultants Inc. work on laptops that are protected by asymmetrical cryptography. To keep the management of the keys cheap, all consultants use the same ke...
asymmetric cryptographykey managementprivate key riskPKI - Question #36Risk and security management
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This inclu...
risk analysisthreat identificationrisk assessmentthreat-risk relationship - Question #37Human resources security
You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?
code of conductemployee behaviorHR policyworkplace rules - Question #38Access control
My user profile specifies which network drives I can read and write to. What is the name of the type of logical access management wherein my access and rights are determined centra...
Mandatory Access ControlDACMAClogical access management - Question #39Compliance
Some security measures are optional. Other security measures must always be implemented. Which measure(s) must always be implemented?
mandatory controlslegal requirementscompliance obligationssecurity measures - Question #40Outlining security controls
Midwest Insurance controls access to its offices with a passkey system. We call this a preventive measure. What are some other measures?
preventive measuredetective measurerepressive measurecorrective measure - Question #41Technical controls
You are the owner of the SpeeDelivery courier service. Last year you had a firewall installed. You now discover that no maintenance has been performed since the installation. What...
firewallpatch managementnetwork securityvulnerability management - Question #42Risk and security management
A couple of years ago you started your company which has now grown from 1 to 20 employees. Your companys information is worth more and more and gone are the days when you could kee...
qualitative risk analysisrisk assessmentscenario-based analysisthreat analysis - Question #43Communication Management
Susan sends an email to Paul. Who determines the meaning and the value of information in this email?
communication modelinformation valuesender-receivermessage interpretation - Question #44Risk Management
Which measure assures that valuable information is not left out available for the taking?
clear desk policyinformation securitydata protectionphysical security - Question #45Risk Management
What is an example of a good physical security measure?
physical securityaccess controlsecurity measuresaccess pass - Question #46Risk Management
You read in the newspapers that the ex-employee of a large company systematically deleted files out of revenge on his manager. Recovering these files caused great losses in time an...
human threatinsider threatinformation securitythreat classification - Question #47Organizational Aspects of Project Management
Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?
data protection legislationregulatory complianceinformation security lawISO standards - Question #48Information security incident management
You are the first to arrive at work in the morning and notice that the CD ROM on which you saved contracts yesterday has disappeared. You were the last to leave yesterday. When sho...
incident reportingdata lossCD ROMresponse procedures - Question #49Legislation and regulations
A Dutch company requests to be listed on the American Stock Exchange. Which legislation within the scope of information security is relevant in this case?
Sarbanes-Oxley Actfinancial legislationstock exchangecompliance - Question #50Outlining security controls
You own a small company in a remote industrial areA. Lately, the alarm regularly goes off in the middle of the night. It takes quite a bit of time to respond to it and it seems to...
detective measuresurveillancehidden camerasecurity control types - Question #51Asset management
At Midwest Insurance, all information is classified. What is the goal of this classification of information?
information classificationdata sensitivityasset classification - Question #52Physical and environmental security
Which one of the threats listed below can occur as a result of the absence of a physical measure?
physical threatsserver overheatingenvironmental controlsphysical measure absence