ISFS Exam Questions
90 real ISFS exam questions with expert-verified answers and explanations. Page 2 of 2.
- Question #53
What is the best description of a risk analysis?
- Question #54
What is the goal of an organization's security policy?
- Question #55
The Information Security Manager (ISM) at Smith Consultants Inc. introduces the following measures to assure information security: - The security requirements for the network are s...
- Question #56
A company moves into a new building. A few weeks after the move, a visitor appears unannounced in the office of the director. An investigation shows that visitors passes grant the...
- Question #57
You have an office that designs corporate logos. You have been working on a draft for a large client. Just as you are going to press the <save> button, the screen goes blank. The h...
- Question #58
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large...
- Question #59
Three characteristics determine the reliability of information. Which characteristics are these?
- Question #60
What action is an unintentional human threat?
- Question #61
You are the owner of the courier company SpeeDelivery. You employ a few people who, while waiting to make a delivery, can carry out other tasks. You notice, however, that they use...
- Question #62
Why is air-conditioning placed in the server room?
- Question #63
Who is authorized to change the classification of a document?
- Question #64
The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is...
- Question #65
What is an example of a physical security measure?
- Question #66
What physical security measure is necessary to control access to company information?
- Question #67
Why do organizations have an information security policy?
- Question #68
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been...
- Question #69
You work for a large organization. You notice that you have access to confidential information that you should not be able to access in your position. You report this security inci...
- Question #70
Your organization has an office with space for 25 workstations. These workstations are all fully equipped and in use. Due to a reorganization 10 extra workstations are added, 5 of...
- Question #71
Which of the following measures is a preventive measure?
- Question #72
Your company has to ensure that it meets the requirements set down in personal data protection legislation. What is the first thing you should do?
- Question #73
What sort of security does a Public Key Infrastructure (PKI) offer?
- Question #74
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry date of a contract with one of the clients is earlier than the start date. What ty...
- Question #75
What is the greatest risk for an organization if no information security policy has been defined?
- Question #76
What is the objective of classifying information?
- Question #77
What do employees need to know to report a security incident?
- Question #78
You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
- Question #79
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and conditions for a life insurance policy to Rachel, a client. Who determines the valu...
- Question #80
When we are at our desk, we want the information system and the necessary information to be available. We want to be able to work with the computer and access the network and our f...
- Question #81
Access management is closely related to which other process?
- Question #82
In which core ITIL publication can you find detailed descriptions of service catalogue management, information security management, and supplier management?
- Question #83
Which process is responsible for the availability, confidentiality and integrity of data?
- Question #84
Which one of the following activities would be performed by access management?
- Question #85
Which of the following BEST describes the purpose of access management?
- Question #86
Which of the following statements describes the objectives of service asset and configuration management? 1. To identify, control, report and verify service assets and configuratio...
- Question #87
Which of the following is a best practice concerning Information Security Risk assessment?
- Question #88
Security controls shall be documented. What will the controls be related to?
- Question #89
Personnel should be competent on the basis of appropriate education and experience. Which of the following is a best practice relating to competence?
- Question #90
What is the purpose of a Problem review?
- Question #91
Which of the following is true of process descriptions?
- Question #92
Which audit is conducted by, or on behalf of, the organization itself for internal purposes and can form the basis for an organization's self-declaration of conformity?