ISFS Exam Questions
90 real ISFS exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #53Risk and security management
What is the best description of a risk analysis?
risk analysisrisk estimationsecurity measuresrisk mapping - Question #54Information security policy
What is the goal of an organization's security policy?
security policymanagement directioninformation security support - Question #55Outlining security controls
The Information Security Manager (ISM) at Smith Consultants Inc. introduces the following measures to assure information security: - The security requirements for the network are s...
technical controlsphysical controlsRFIDmeasure classification - Question #56Physical and environmental security
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the...
visitor accessphysical access controlaccess passesphysical security - Question #57Outlining security controls
You have an office that designs corporate logos. You have been working on a draft for a large client. Just as you are going to press the <save> button, the screen goes blank. The h...
corrective measuredata recoverybackupcontrol types - Question #58Risk and security management
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large...
risk strategyrisk neutralrisk bearingrisk treatment - Question #59Basic concepts of information security
Three characteristics determine the reliability of information. Which characteristics are these?
CIA triadavailabilityintegrityconfidentiality - Question #60Threats and risks
What action is an unintentional human threat?
unintentional threatshuman threatsthreat classificationaccidental actions - Question #61Organizational controls
You are the owner of the courier company SpeeDelivery. You employ a few people who, while waiting to make a delivery, can carry out other tasks. You notice, however, that they use...
acceptable use policycode of conductinternet useemail policy - Question #62Physical and environmental security
Why is air-conditioning placed in the server room?
server roomair conditioningenvironmental controlsheat extraction - Question #63Asset management
Who is authorized to change the classification of a document?
document classificationinformation ownershipasset owner - Question #64Outlining security controls
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is...
technical measuresISMSorganizational measuressecurity controls - Question #65Physical controls
What is an example of a physical security measure?
physical securityfire suppressionenvironmental controls - Question #66Physical controls
What physical security measure is necessary to control access to company information?
physical access controlperimeter securityphysical barriers - Question #67Information security policy
Why do organizations have an information security policy?
security policyorganizational directioninformation security management - Question #68Organizational controls
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been...
mobile device policyorganizational measurespolicy developmentlaptops - Question #69Information security incident management
You work for a large organization. You notice that you have access to confidential information that you should not be able to access in your position. You report this security inci...
incident cycleincident managementthreatrecovery - Question #70Physical controls
Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of...
UPSavailabilitypower supplyphysical security - Question #71Outlining security controls
Which of the following measures is a preventive measure?
preventive measurescontrol typesphysical security - Question #72Legislation and regulations
Your company has to ensure that it meets the requirements set down in personal data protection legislation. What is the first thing you should do?
data protection legislationprivacy policypersonal datacompliance - Question #73Technical controls
What sort of security does a Public Key Infrastructure (PKI) offer?
PKIdigital certificatespublic key infrastructuretrust - Question #74Technical controls
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What ty...
data validationintegrityinput validationtechnical controls - Question #75Information security policy
What is the greatest risk for an organization if no information security policy has been defined?
security policyconsistencyinformation security management - Question #76Asset management
What is the objective of classifying information?
information classificationsensitivity levelsdata classification - Question #77Information security incident management
What do employees need to know to report a security incident?
incident reportingsecurity awarenessincident procedure - Question #78People controls
You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
code of conductacceptable useIT facilitiesHR security - Question #79Concepts relating to information
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the valu...
information valuerecipient valuedata ownership - Question #80Basic concepts of information security
When we are at our desk, we want the information system and the necessary information to be available. We want to be able to work with the computer and access the network and our f...
availabilityCIA triadsystem availabilityinformation security - Question #81Access control
Access management is closely related to which other process?
access managementinformation security managementprocess integration - Question #82Standards
In which core ITIL publication can you find detailed descriptions of service catalogue management, information security management, and supplier management?
ITILservice designservice managementIT standards - Question #83Basic concepts of information security
Which process is responsible for the availability, confidentiality and integrity of data?
CIA triadinformation security managementavailabilityconfidentiality - Question #84Access control
Which one of the following activities would be performed by access management?
access managementuser rightsservice access - Question #85Access control
Which of the following BEST describes the purpose of access management?
access managementuser rightsservice accesspurpose - Question #86Asset management
Which of the following statements describes the objectives of service asset and configuration management? 1. To identify, control, report and verify service assets and configuratio...
configuration managementservice assetsconfiguration itemsasset control - Question #87Risk and security management
Which of the following is a best practice concerning Information Security Risk assessment?
risk assessmentbest practiceagreed intervalsISO 27001 - Question #88Outlining security controls
Security controls shall be documented. What will the controls be related to?
security controlsdocumentationrisk relationship - Question #89Human resources security
Personnel should be competent on the basis of appropriate education and experience. Which of the following is a best practice relating to competence?
personnel competencetrainingeducationISO 27002 - Question #90Information security incident management
What is the purpose of a Problem review?
problem managementincident preventionprocess improvement - Question #91Organizing information security
Which of the following is true of process descriptions?
process descriptionsorganizational rolesresponsibilities - Question #92Compliance
Which audit is conducted by, or on behalf of, the organization itself for internal purposes and can form the basis for an organization's self-declaration of conformity?
audit typesfirst party auditinternal auditconformity