nerdexam
PECB

LEAD-AUDITOR · Question #38

You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team. Your colleague…

The correct answer is E. A contractor who has not been paid deletes top management ICT accounts F. An unhappy employee changes payroll records without permission H. The organisation's marketing data is copied by hackers and sold to a competitor. You've hit your limit · resets 4am (America/New_York)

Information Security Incident Management

Question

You are carrying out your first third-party ISMS surveillance audit as an Audit Team Leader. You are presently in the auditee's data centre with another member of your audit team. Your colleague seems unsure as to the difference between an information security event and an information security incident. You attempt to explain the difference by providing examples. Which three of the following scenarios can be defined as information security incidents?

Options

  • AThe organisation's malware protection software prevents a virus
  • BA hard drive is used after its recommended replacement date
  • CThe organisation receives a phishing email
  • DAn employee fails to clear their desk at the end of their shift
  • EA contractor who has not been paid deletes top management ICT accounts
  • FAn unhappy employee changes payroll records without permission
  • GThe organisation fails a third-party penetration test
  • HThe organisation's marketing data is copied by hackers and sold to a competitor

How the community answered

(29 responses)
  • A
    7% (2)
  • D
    3% (1)
  • E
    79% (23)
  • G
    10% (3)

Explanation

You've hit your limit · resets 4am (America/New_York)

Topics

#information security incidents#information security events#incident classification#ISO 27035

Community Discussion

No community discussion yet for this question.

Full LEAD-AUDITOR Practice