Why is compliance important for the reliability of the information?
A. When an organization employs a standard such as the ISO/IEC 27002 and uses it everywhere, it is compliant and therefore it guarantees the reliability of its information.
B. By meeting the legislative requirements and the regulations of both the government and internal management, an organization shows that it manages its information in a sound manner.
C. Compliance is another word for reliability. So, if a company indicates that it is compliant, it means that the information is managed properly.
D. When an organization is compliant, it meets the requirements of privacy legislation and, in doing so, protects the reliability of its information.
正解:B
質問 2:
Midwest Insurance grades the monthly report of all claimed losses per insured as confidential. What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?
A. Everyone can easiliy see how sensitive the reports' contents are by consulting the grading label.
B. Reports can be developed more easily and with fewer errors.
C. A determination can be made as to which report should be printed first and which one can wait a little longer.
D. The costs for automating are easier to charge to the responsible departments.
正解:A
質問 3:
You have just started working at a large organization. You have been asked to sign a code of conduct as well as a contract. What does the organization wish to achieve with this?
A. A code of conduct gives staff guidance on how to report suspected misuses of IT facilities.
B. A code of conduct helps to prevent the misuse of IT facilities.
C. A code of conduct is a legal obligation that organizations have to meet.
D. A code of conduct prevents a virus outbreak.
正解:B
質問 4:
What is the most important reason for applying segregation of duties?
A. Segregation of duties makes it easier for a person who is ready with his or her part of the work to take time off or to take over the work of another person.
B. Segregation of duties makes it clear who is responsible for what.
C. Tasks and responsibilities must be separated in order to minimize the opportunities for business assets to be misused or changed, whether the change be unauthorized or unintentional.
D. Segregation of duties ensures that, when a person is absent, it can be investigated whether he or she has been committing fraud.
正解:C
質問 5:
What is an example of a physical security measure?
A. A code of conduct that requires staff to adhere to the clear desk policy, ensuring that confidential information is not left visibly on the desk at the end of the work day
B. Special fire extinguishers with inert gas, such as Argon
C. The encryption of confidential information
D. An access control policy with passes that have to be worn visibly
正解:B
佐々** -
すべての問題を暗記して言ったら絶対合格すると思うよ。Pass4Testの問題集を購入させてISFSの試験に受かりました。