{"id":1824,"date":"2025-08-10T10:13:54","date_gmt":"2025-08-10T10:13:54","guid":{"rendered":"https:\/\/exam.real4prep.com\/?p=1824"},"modified":"2025-08-10T10:13:54","modified_gmt":"2025-08-10T10:13:54","slug":"100-real-accurate-iso-iec-27001-lead-implementer-questions-and-answers-with-free-and-fast-updates-q58-q76","status":"publish","type":"post","link":"https:\/\/exam.real4prep.com\/ko\/2025\/08\/10\/100-real-accurate-iso-iec-27001-lead-implementer-questions-and-answers-with-free-and-fast-updates-q58-q76\/","title":{"rendered":"100% Real &amp; Accurate ISO-IEC-27001-Lead-Implementer Questions and Answers with Free and Fast Updates [Q58-Q76]"},"content":{"rendered":"\n\n<div class=\"kk-star-ratings kksr-auto kksr-align-left kksr-valign-top\"\n    data-payload='{&quot;align&quot;:&quot;left&quot;,&quot;id&quot;:&quot;1824&quot;,&quot;slug&quot;:&quot;default&quot;,&quot;valign&quot;:&quot;top&quot;,&quot;ignore&quot;:&quot;&quot;,&quot;reference&quot;:&quot;auto&quot;,&quot;class&quot;:&quot;&quot;,&quot;count&quot;:&quot;1&quot;,&quot;legendonly&quot;:&quot;&quot;,&quot;readonly&quot;:&quot;&quot;,&quot;score&quot;:&quot;4&quot;,&quot;starsonly&quot;:&quot;&quot;,&quot;best&quot;:&quot;5&quot;,&quot;gap&quot;:&quot;5&quot;,&quot;greet&quot;:&quot;Rate this post&quot;,&quot;legend&quot;:&quot;4\\\/5 - (1 vote)&quot;,&quot;size&quot;:&quot;24&quot;,&quot;title&quot;:&quot;100% Real \\u0026amp; Accurate ISO-IEC-27001-Lead-Implementer Questions and Answers with Free and Fast Updates [Q58-Q76]&quot;,&quot;width&quot;:&quot;113.5&quot;,&quot;_legend&quot;:&quot;{score}\\\/{best} - ({count} {votes})&quot;,&quot;font_factor&quot;:&quot;1.25&quot;}'>\n            \n<div class=\"kksr-stars\">\n    \n<div class=\"kksr-stars-inactive\">\n            <div class=\"kksr-star\" data-star=\"1\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"2\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"3\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"4\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" data-star=\"5\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n    <\/div>\n    \n<div class=\"kksr-stars-active\" style=\"width: 113.5px;\">\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n            <div class=\"kksr-star\" style=\"padding-right: 5px\">\n            \n\n<div class=\"kksr-icon\" style=\"width: 24px; height: 24px;\"><\/div>\n        <\/div>\n    <\/div>\n<\/div>\n                \n\n<div class=\"kksr-legend\" style=\"font-size: 19.2px;\">\n            4\/5 - (1 vote)    <\/div>\n    <\/div>\n<p><span style=\"font-size: 18px\"><strong><span style=\"color: red\">100% Real &amp; Accurate ISO-IEC-27001-Lead-Implementer Questions and Answers with Free and Fast Updates<\/span><\/strong><\/span><\/p>\n<p><strong><span style=\"color: red\">Get Unlimited Access to ISO-IEC-27001-Lead-Implementer Certification Exam Cert Guide<\/span><\/strong><\/p>\n<p><\/p>\n<p>PECB ISO-IEC-27001-Lead-Implementer certification exam is a globally recognized certification program that validates an individual&#8217;s knowledge and skills in implementing and managing an Information Security Management System (ISMS) based on the ISO\/IEC 27001 standard. PECB Certified ISO\/IEC 27001 Lead Implementer Exam certification exam is designed to assess the candidate&#8217;s ability to implement the requirements of the standard and develop an effective ISMS that meets the organization&#8217;s information security objectives.<\/p>\n<p>&nbsp;<\/p>\n<div id=\"watu_quiz\" class=\"quiz-area single-page-quiz\">\n<form action=\"\" method=\"post\" class=\"quiz-form \" id=\"quiz-746\" >\n<div class='watu-question' id='question-1'><div class='question-content'><p><strong>QUESTION 58<\/strong><br \/>Based on scenario 1. what is a potential impact of the loss of integrity of information in HealthGenic?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14656' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56807' \/><div class='watu-question-choice'><input type='radio' name='answer-14656[]' id='answer-id-56807' class='answer answer-1 js-answer-label answerof-14656' value='56807' \/>&nbsp;<label for='answer-id-56807' id='answer-label-56807' class='js-answer-label answer label-1'><span class='answer'>Disruption of operations and performance degradation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56808' \/><div class='watu-question-choice'><input type='radio' name='answer-14656[]' id='answer-id-56808' class='answer answer-1 php-answer-label answerof-14656' value='56808' \/>&nbsp;<label for='answer-id-56808' id='answer-label-56808' class='php-answer-label answer label-1'><span class='answer'>Incomplete and incorrect medical reports<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56809' \/><div class='watu-question-choice'><input type='radio' name='answer-14656[]' id='answer-id-56809' class='answer answer-1 js-answer-label answerof-14656' value='56809' \/>&nbsp;<label for='answer-id-56809' id='answer-label-56809' class='js-answer-label answer label-1'><span class='answer'>Service interruptions and complicated user interface<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(1,this)' id='btn-1' value='See Answer'  \/><input type='hidden' id='questionType1' value='radio' class=''><\/div><div class='watu-question' id='question-2'><div class='question-content'><p><strong>QUESTION 59<\/strong><br \/>Scenario 2:<br \/>Beauty is a well-established cosmetics company in the beauty industry. The company was founded several decades ago with a passion for creating high-quality skincare, makeup, and personal care products that enhance natural beauty. Over the years, Beauty has built a strong reputation for its innovative product offerings, commitment to customer satisfaction, and dedication to ethical and sustainable business practices.<br \/>In response to the rapidly evolving landscape of consumer shopping habits, Beauty transitioned from traditional retail to an e-commerce model. To initiate this strategy, Beauty conducted a comprehensiveinformation security risk assessment, analyzing potential threats and vulnerabilities associated with its new e-commerce venture, aligned with its business strategy and objectives.<br \/>Concerning the identified risks, the company implemented several information security controls. All employees were required to sign confidentiality agreements to emphasize the importance of protecting sensitive customer data. The company thoroughly reviewed user access rights, ensuring only authorized personnel could access sensitive information. In addition, since the company stores valuable products and unique formulas in the warehouse, it installed alarm systems and surveillance cameras with real-time alerts to prevent any potential act of vandalism.<br \/>After a while, the information security team analyzed the audit logs to monitor and track activities across the newly implemented security controls. Upon investigating and analyzing the audit logs, it was discovered that an attacker had accessed the system due to out-of-date anti-malware software, exposing customers&#8217; sensitive information, including names and home addresses. Following this, the IT team replaced the anti-malware software with a new one capable of automatically removing malicious code in case of similar incidents. The new software was installed on all workstations and regularly updated with the latest malware definitions, with an automatic update feature enabled. An authentication process requiring user identification and a password was also implemented to access sensitive information.<br \/>During the investigation, Maya, the information security manager of Beauty, found that information security responsibilities in job descriptions were not clearly defined, for which the company took immediate action.<br \/>Recognizing that their e-commerce operations would have a global reach, Beauty diligently researched and complied with the industry&#8217;s legal, statutory, regulatory, and contractual requirements. It considered international and local regulations, including data privacy laws, consumer protection acts, and global trade agreements.<br \/>To meet these requirements, Beauty invested in legal counsel and compliance experts who continuously monitored and ensured the company&#8217;s compliance with legal standards in every market they operated in.<br \/>Additionally, Beauty conducted multiple information security awareness sessions for the IT team and other employees with access to confidential information, emphasizing the importance of system and network security.<br \/>Under which category does the vulnerability identified by Maya during the incident fall into?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14657' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56810' \/><div class='watu-question-choice'><input type='radio' name='answer-14657[]' id='answer-id-56810' class='answer answer-2 js-answer-label answerof-14657' value='56810' \/>&nbsp;<label for='answer-id-56810' id='answer-label-56810' class='js-answer-label answer label-2'><span class='answer'>Network<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56811' \/><div class='watu-question-choice'><input type='radio' name='answer-14657[]' id='answer-id-56811' class='answer answer-2 js-answer-label answerof-14657' value='56811' \/>&nbsp;<label for='answer-id-56811' id='answer-label-56811' class='js-answer-label answer label-2'><span class='answer'>Site<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56812' \/><div class='watu-question-choice'><input type='radio' name='answer-14657[]' id='answer-id-56812' class='answer answer-2 php-answer-label answerof-14657' value='56812' \/>&nbsp;<label for='answer-id-56812' id='answer-label-56812' class='php-answer-label answer label-2'><span class='answer'>Organization<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(2,this)' id='btn-2' value='See Answer'  \/><input type='hidden' id='questionType2' value='radio' class=''><\/div><div class='watu-question' id='question-3'><div class='question-content'><p><strong>QUESTION 60<\/strong><br \/>Has Bytes determined all the relevant factors that impact its ability to achieve the intended outcomes of its ISMS, in accordance with clause 4.1 &#8220;Understanding the organization and its context&#8221; of ISO\/IEC 27001?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14658' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56813' \/><div class='watu-question-choice'><input type='radio' name='answer-14658[]' id='answer-id-56813' class='answer answer-3 js-answer-label answerof-14658' value='56813' \/>&nbsp;<label for='answer-id-56813' id='answer-label-56813' class='js-answer-label answer label-3'><span class='answer'>No, the company did not determine which requirements of interested parties will be addressed through the ISMS<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56814' \/><div class='watu-question-choice'><input type='radio' name='answer-14658[]' id='answer-id-56814' class='answer answer-3 php-answer-label answerof-14658' value='56814' \/>&nbsp;<label for='answer-id-56814' id='answer-label-56814' class='php-answer-label answer label-3'><span class='answer'>Yes, the company determined all the relevant issues to its purpose that affect its ability to achieve the intended outcomes<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56815' \/><div class='watu-question-choice'><input type='radio' name='answer-14658[]' id='answer-id-56815' class='answer answer-3 js-answer-label answerof-14658' value='56815' \/>&nbsp;<label for='answer-id-56815' id='answer-label-56815' class='js-answer-label answer label-3'><span class='answer'>No, the company did not determine whether climate change is a relevant issue<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(3,this)' id='btn-3' value='See Answer'  \/><input type='hidden' id='questionType3' value='radio' class=''><\/div><div class='watu-question' id='question-4'><div class='question-content'><p><strong>QUESTION 61<\/strong><br \/>What should an organization allocate to ensure the maintenance and improvement of the information security management system?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14659' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56816' \/><div class='watu-question-choice'><input type='radio' name='answer-14659[]' id='answer-id-56816' class='answer answer-4 js-answer-label answerof-14659' value='56816' \/>&nbsp;<label for='answer-id-56816' id='answer-label-56816' class='js-answer-label answer label-4'><span class='answer'>The appropriate transfer to operations<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56817' \/><div class='watu-question-choice'><input type='radio' name='answer-14659[]' id='answer-id-56817' class='answer answer-4 php-answer-label answerof-14659' value='56817' \/>&nbsp;<label for='answer-id-56817' id='answer-label-56817' class='php-answer-label answer label-4'><span class='answer'>Sufficient resources, such as the budget, qualified personnel, and required tools<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56818' \/><div class='watu-question-choice'><input type='radio' name='answer-14659[]' id='answer-id-56818' class='answer answer-4 js-answer-label answerof-14659' value='56818' \/>&nbsp;<label for='answer-id-56818' id='answer-label-56818' class='js-answer-label answer label-4'><span class='answer'>The documented information required by ISO\/IEC 27001<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>According to ISO\/IEC 27001:2022, clause 10.2.2, the organization shall define and apply an information security incident management process that includes the following activities:<br\/>* reporting information security events and weaknesses;<br\/>* assessing information security events and classifying them as information security incidents;<br\/>* responding to information security incidents according to their classification;<br\/>* learning from information security incidents, including identifying causes, taking corrective actions and preventive actions, and communicating the results and actions taken;<br\/>* collecting evidence, where applicable.<br\/>The standard does not specify who should perform these activities, as long as they are done in a consistent and effective manner. Therefore, the organization may choose to conduct forensic investigation internally or by using external consultants, depending on its needs, resources, and capabilities. However, the organization should ensure that the external consultants are competent, trustworthy, and comply with the organization&#8217;s policies and procedures.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(4,this)' id='btn-4' value='See Answer'  \/><input type='hidden' id='questionType4' value='radio' class=''><\/div><div class='watu-question' id='question-5'><div class='question-content'><p><strong>QUESTION 62<\/strong><br \/>Based on scenario 9. the top management decided to accept the risk related to a nonconformity to control 5.17 Authentication informal ion. is this acceptable?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14660' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56819' \/><div class='watu-question-choice'><input type='radio' name='answer-14660[]' id='answer-id-56819' class='answer answer-5 js-answer-label answerof-14660' value='56819' \/>&nbsp;<label for='answer-id-56819' id='answer-label-56819' class='js-answer-label answer label-5'><span class='answer'>Acceptable, the company analyzed the implementation costs and accepted the risk<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56820' \/><div class='watu-question-choice'><input type='radio' name='answer-14660[]' id='answer-id-56820' class='answer answer-5 js-answer-label answerof-14660' value='56820' \/>&nbsp;<label for='answer-id-56820' id='answer-label-56820' class='js-answer-label answer label-5'><span class='answer'>Acceptable, as the company properly informed the internal audit that they decided to accept the risk<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56821' \/><div class='watu-question-choice'><input type='radio' name='answer-14660[]' id='answer-id-56821' class='answer answer-5 php-answer-label answerof-14660' value='56821' \/>&nbsp;<label for='answer-id-56821' id='answer-label-56821' class='php-answer-label answer label-5'><span class='answer'>Unacceptable, the company should have provided justification for accepting the risks and documented it<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(5,this)' id='btn-5' value='See Answer'  \/><input type='hidden' id='questionType5' value='radio' class=''><\/div><div class='watu-question' id='question-6'><div class='question-content'><p><strong>QUESTION 63<\/strong><br \/>What is the main purpose of Annex A 7.1 Physical security perimeters of ISO\/IEC 27001?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14661' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56822' \/><div class='watu-question-choice'><input type='radio' name='answer-14661[]' id='answer-id-56822' class='answer answer-6 php-answer-label answerof-14661' value='56822' \/>&nbsp;<label for='answer-id-56822' id='answer-label-56822' class='php-answer-label answer label-6'><span class='answer'>To prevent unauthorized physical access, damage, and interference to the organization&#8217;s information and other associated assets<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56823' \/><div class='watu-question-choice'><input type='radio' name='answer-14661[]' id='answer-id-56823' class='answer answer-6 js-answer-label answerof-14661' value='56823' \/>&nbsp;<label for='answer-id-56823' id='answer-label-56823' class='js-answer-label answer label-6'><span class='answer'>To maintain the confidentiality of information that is accessible by personnel or external parties<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56824' \/><div class='watu-question-choice'><input type='radio' name='answer-14661[]' id='answer-id-56824' class='answer answer-6 js-answer-label answerof-14661' value='56824' \/>&nbsp;<label for='answer-id-56824' id='answer-label-56824' class='js-answer-label answer label-6'><span class='answer'>To ensure access to information and other associated assets is defined and authorized<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Annex A 7.1 of ISO\/IEC 27001 : 2022 is a control that requires an organization to define and implement security perimeters and use them to protect areas that contain information and other associated assets.<br\/>Information and information security assets can include data, infrastructure, software, hardware, and personnel. The main purpose of this control is to prevent unauthorized physical access, damage, and interference to these assets, which could compromise the confidentiality, integrity, and availability of the information. Physical security perimeters can include fences, walls, gates, locks, alarms, cameras, and other barriers or devices that restrict or monitor access to the facility or area. The organization should also consider the environmental and fire protection of the assets, as well as the disposal of any waste or media that could contain sensitive information.<br\/>References:<br\/>* ISO\/IEC 27001 : 2022 Lead Implementer Study Guide, Section 5.3.1.7, page 101<br\/>* ISO\/IEC 27001 : 2022 Lead Implementer Info Kit, page 17<br\/>* ISO\/IEC 27002 : 2022, Control 7.1 &#8211; Physical Security Perimeters123<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(6,this)' id='btn-6' value='See Answer'  \/><input type='hidden' id='questionType6' value='radio' class=''><\/div><div class='watu-question' id='question-7'><div class='question-content'><p><strong>QUESTION 64<\/strong><br \/>Scenario 1: HealthGenic is a pediatric clinic that monitors the health and growth of individuals from infancy to early adulthood using a web-based medical software. The software is also used to schedule appointments, create customized medical reports, store patients&#8217; data and medical history, and communicate with all the<br \/>[^involved parties, including parents, other physicians, and the medical laboratory staff.<br \/>Last month, HealthGenic experienced a number of service interruptions due to the increased number of users accessing the software Another issue the company faced while using the software was the complicated user interface, which the untrained personnel found challenging to use.<br \/>The top management of HealthGenic immediately informed the company that had developed the software about the issue. The software company fixed the issue; however, in the process of doing so, it modified some files that comprised sensitive information related to HealthGenic&#8217;s patients. The modifications that were made resulted in incomplete and incorrect medical reports and, more importantly, invaded the patients&#8217; privacy.<br \/>Based on the scenario above, answer the following question:<br \/>Which of the following indicates that the confidentiality of information was compromised?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14662' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56825' \/><div class='watu-question-choice'><input type='radio' name='answer-14662[]' id='answer-id-56825' class='answer answer-7 js-answer-label answerof-14662' value='56825' \/>&nbsp;<label for='answer-id-56825' id='answer-label-56825' class='js-answer-label answer label-7'><span class='answer'>Service interruptions due to the increased number of users<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56826' \/><div class='watu-question-choice'><input type='radio' name='answer-14662[]' id='answer-id-56826' class='answer answer-7 php-answer-label answerof-14662' value='56826' \/>&nbsp;<label for='answer-id-56826' id='answer-label-56826' class='php-answer-label answer label-7'><span class='answer'>Invasion of patients&#8217; privacy<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56827' \/><div class='watu-question-choice'><input type='radio' name='answer-14662[]' id='answer-id-56827' class='answer answer-7 js-answer-label answerof-14662' value='56827' \/>&nbsp;<label for='answer-id-56827' id='answer-label-56827' class='js-answer-label answer label-7'><span class='answer'>Modification of patients&#8217; medical reports<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>Confidentiality of information is the property that information is not made available or disclosed to unauthorized individuals, entities, or processes. In other words, confidentiality ensures that only those who are authorized to access the information can do so. In the scenario, the confidentiality of information was compromised when the software company modified some files that contained sensitive information related to HealthGenic&#8217;s patients. This modification resulted in the invasion of patients&#8217; privacy, which means that their personal and medical information was exposed to unauthorized parties. Therefore, the correct answer is B.<br\/>References: : ISO\/IEC 27001:2013, Information technology &#8211; Security techniques &#8211; Information security management systems &#8211; Requirements, clause 3.14.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(7,this)' id='btn-7' value='See Answer'  \/><input type='hidden' id='questionType7' value='radio' class=''><\/div><div class='watu-question' id='question-8'><div class='question-content'><p><strong>QUESTION 65<\/strong><br \/>Scenario 4: TradeB is a newly established commercial bank located in Europe, with a diverse clientele. It provides services that encompass retail banking, corporate banking, wealth management, and digital banking, all tailored to meet the evolving financial needs of individuals and businesses in the region. Recognizing the critical importance of information security in the modern banking landscape, TradeB has initiated the implementation of an information security management system (ISMS) based on ISO\/IEC 27001. To ensure the successful implementation of the ISMS, the top management decided to contract two experts to lead and oversee the ISMS implementation project.<br \/>As a primary strategy for implementing the ISMS, the experts chose an approach that emphasizes a swift implementation of the ISMS by initially meeting the minimum requirements of ISO\/IEC 27001, followed by continual improvement over time. Additionally, under the guidance of the experts, TradeB opted for a methodological framework, which serves as a structured framework and a guideline that outlines the high-level stages of the ISMS implementation, the associated activities, and the deliverables without incorporating any specific tools.<br \/>The experts analyzed the ISO\/IEC 27001 controls and listed only the security controls deemed applicable to the company and its objectives. Based on this analysis, they drafted the Statement of Applicability. Afterward, they conducted a risk assessment, during which they identified assets, such as hardware, software, and networks, as well as threats and vulnerabilities, assessed potential consequences and likelihood, and determined the level of risks based on a methodical approach that involved defining and characterizing the terms and criteria used in the assessment process, categorizing them into non-numerical levels (e.g., very low, low, moderate, high, very high). Explanatory notes were thoughtfully crafted to justify assessed values, with the primary goal of enhancing repeatability and reproducibility.<br \/>Then, they evaluated the risks based on the risk evaluation criteria, where they decided to treat only the risks of the high-risk category. Additionally, they focused primarily on the unauthorized use of administrator rights and system interruptions due to several hardware failures. To address these issues, they established a new version of the access control policy, implemented controls to manage and control user access, and introduced a control for ICT readiness to ensure business continuity.<br \/>Their risk assessment report indicated that if the implemented security controls reduce the risk levels to an acceptable threshold, those risks will be accepted.<br \/>Based on the scenario above, answer the following question:<br \/>According to scenario 4, what type of assets were identified during the risk assessment?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14663' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56828' \/><div class='watu-question-choice'><input type='radio' name='answer-14663[]' id='answer-id-56828' class='answer answer-8 php-answer-label answerof-14663' value='56828' \/>&nbsp;<label for='answer-id-56828' id='answer-label-56828' class='php-answer-label answer label-8'><span class='answer'>Supporting assets<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56829' \/><div class='watu-question-choice'><input type='radio' name='answer-14663[]' id='answer-id-56829' class='answer answer-8 js-answer-label answerof-14663' value='56829' \/>&nbsp;<label for='answer-id-56829' id='answer-label-56829' class='js-answer-label answer label-8'><span class='answer'>Financial assets<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56830' \/><div class='watu-question-choice'><input type='radio' name='answer-14663[]' id='answer-id-56830' class='answer answer-8 js-answer-label answerof-14663' value='56830' \/>&nbsp;<label for='answer-id-56830' id='answer-label-56830' class='js-answer-label answer label-8'><span class='answer'>Business assets<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(8,this)' id='btn-8' value='See Answer'  \/><input type='hidden' id='questionType8' value='radio' class=''><\/div><div class='watu-question' id='question-9'><div class='question-content'><p><strong>QUESTION 66<\/strong><br \/>Select risk control activities for domain &#8220;10. Encryption&#8221; of ISO \/ 27002: 2013 (Choose two)<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14664' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56831' \/><div class='watu-question-choice'><input type='checkbox' name='answer-14664[]' id='answer-id-56831' class='answer answer-9 js-answer-label answerof-14664' value='56831' \/>&nbsp;<label for='answer-id-56831' id='answer-label-56831' class='js-answer-label answer label-9'><span class='answer'>Work in safe areas<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56832' \/><div class='watu-question-choice'><input type='checkbox' name='answer-14664[]' id='answer-id-56832' class='answer answer-9 php-answer-label answerof-14664' value='56832' \/>&nbsp;<label for='answer-id-56832' id='answer-label-56832' class='php-answer-label answer label-9'><span class='answer'>Cryptographic Controls Use Policy<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56833' \/><div class='watu-question-choice'><input type='checkbox' name='answer-14664[]' id='answer-id-56833' class='answer answer-9 js-answer-label answerof-14664' value='56833' \/>&nbsp;<label for='answer-id-56833' id='answer-label-56833' class='js-answer-label answer label-9'><span class='answer'>Physical security perimeter<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56834' \/><div class='watu-question-choice'><input type='checkbox' name='answer-14664[]' id='answer-id-56834' class='answer answer-9 php-answer-label answerof-14664' value='56834' \/>&nbsp;<label for='answer-id-56834' id='answer-label-56834' class='php-answer-label answer label-9'><span class='answer'>Key management<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(9,this)' id='btn-9' value='See Answer'  \/><input type='hidden' id='questionType9' value='checkbox' class=''><\/div><div class='watu-question' id='question-10'><div class='question-content'><p><strong>QUESTION 67<\/strong><br \/>What is the first phase in the information security policy development life cycle?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14665' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56835' \/><div class='watu-question-choice'><input type='radio' name='answer-14665[]' id='answer-id-56835' class='answer answer-10 js-answer-label answerof-14665' value='56835' \/>&nbsp;<label for='answer-id-56835' id='answer-label-56835' class='js-answer-label answer label-10'><span class='answer'>Policy construction<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56836' \/><div class='watu-question-choice'><input type='radio' name='answer-14665[]' id='answer-id-56836' class='answer answer-10 js-answer-label answerof-14665' value='56836' \/>&nbsp;<label for='answer-id-56836' id='answer-label-56836' class='js-answer-label answer label-10'><span class='answer'>Policy implementation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56837' \/><div class='watu-question-choice'><input type='radio' name='answer-14665[]' id='answer-id-56837' class='answer answer-10 js-answer-label answerof-14665' value='56837' \/>&nbsp;<label for='answer-id-56837' id='answer-label-56837' class='js-answer-label answer label-10'><span class='answer'>Risk assessment<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56838' \/><div class='watu-question-choice'><input type='radio' name='answer-14665[]' id='answer-id-56838' class='answer answer-10 php-answer-label answerof-14665' value='56838' \/>&nbsp;<label for='answer-id-56838' id='answer-label-56838' class='php-answer-label answer label-10'><span class='answer'>Policy planning \/ Needs assessment<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(10,this)' id='btn-10' value='See Answer'  \/><input type='hidden' id='questionType10' value='radio' class=''><\/div><div class='watu-question' id='question-11'><div class='question-content'><p><strong>QUESTION 68<\/strong><br \/>Scenario 7: CyTekShield<br \/>CyTekShield based in Dublin. Ireland, is a cybersecurity consulting provider specializing in digital risk management and enterprise security solutions. After facing multiple security incidents. CyberTekShield formed expanded its information security team by bringing in Sadie and Niamh as part of the team. This team is structured into three key divisions: incident response, security architecture and forensics Sadie will separate the demilitarized zone from CyTekShield&#8217;s private network and publicly accessible resources, as part of implementing a screened subnet network architecture. In addition, Sadie will carry out comprehensive evaluations of any unexpected incidents, analyzing their causes and assessing their potential impact. She also developed security strategies and policies. Whereas Niamh. a specialized expert in forensic investigations, will be responsible for creating records of different data for evidence purposes To do this effectively, she first reviewed the company&#8217;s information security incident management policy, which outlines the types of records to be created, their storage location, and the required format and content for specific record types.<br \/>To support the process of handling of evidence related to information security events. CyTekShield has established internal procedures. These procedures ensure that evidence is properly identified, collected, and preserved within the company CyTekShield&#8217;s procedures specify how to handle records in various storage mediums, ensuring that all evidence is safeguarded in its original state, whether the devices are powered on or off.<br \/>As part of CyTekShield&#8217;s initiative to strengthen information security measures, Niamh will conduct information security risk assessments only when significant changes are proposed and will document the results of these risk assessments Upon completion of the risk assessment process, Niamh is responsible to develop and implement a plan for treating information security risks and document the risk treatment results.<br \/>Furthermore, while implementing the communication plan for information security, the CyTekShield&#8217;s top management was responsible for creating a roadmap for new product development. This approach helps the company to align its security measures with the product development efforts, demonstrating a commitment to integrating security into every aspect of its business operations.CyTekShield uses a cloud service model that includes cloud-based apps accessed through the web or an application programming interface (API). All cloud services are provided by the cloud service provider, while data is managed by CyTekShield This introduces unique security considerations and becomes a primary focus for the information security team to ensure data and systems are protected in this environment.CyTekShield uses a cloud service model that includes cloud- based apps accessed through the web or an application programming interface (API). All cloud services are provided by the cloud service provider, while data is managed by CyTekShield This introduces unique security considerations and becomes a primary focus for the information security team to ensure data and systems are protected in this environment.<br \/>Niamh, the forensics expert, conducted information security risk assessments upon significant changes and developed arisk treatment plan. The results of both weredocumented.<br \/>Question:<br \/>Does CyTekShield comply with ISO\/IEC 27001 requirements regarding the information security risk treatment plan?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14666' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56839' \/><div class='watu-question-choice'><input type='radio' name='answer-14666[]' id='answer-id-56839' class='answer answer-11 php-answer-label answerof-14666' value='56839' \/>&nbsp;<label for='answer-id-56839' id='answer-label-56839' class='php-answer-label answer label-11'><span class='answer'>Yes &#8211; by implementing a risk treatment plan and documenting risk treatment results<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56840' \/><div class='watu-question-choice'><input type='radio' name='answer-14666[]' id='answer-id-56840' class='answer answer-11 js-answer-label answerof-14666' value='56840' \/>&nbsp;<label for='answer-id-56840' id='answer-label-56840' class='js-answer-label answer label-11'><span class='answer'>No &#8211; it should only retain documented information for risk assessment results<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56841' \/><div class='watu-question-choice'><input type='radio' name='answer-14666[]' id='answer-id-56841' class='answer answer-11 js-answer-label answerof-14666' value='56841' \/>&nbsp;<label for='answer-id-56841' id='answer-label-56841' class='js-answer-label answer label-11'><span class='answer'>No &#8211; the information security risk treatment plan should be developed only by the top management<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>ISO\/IEC 27001:2022 Clause 6.1.3 (e) requires organizations to:<br\/>&#8220;Formulate an information security risk treatment plan and obtain risk owners&#8217; approval&#8230;<br\/>The organization shall retain documented information about the information security risk treatment process.&#8221; Niamh&#8217;s role aligns with ISO expectations. There isno restrictionthat only top management must develop this plan, as long as risk owners approve it (6.1.3(f)). Documentation ofboth assessment and treatmentis required.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(11,this)' id='btn-11' value='See Answer'  \/><input type='hidden' id='questionType11' value='radio' class=''><\/div><div class='watu-question' id='question-12'><div class='question-content'><p><strong>QUESTION 69<\/strong><br \/>An organization has compared its actual performance against predetermined performance targets. What is the primary purpose of this action?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14667' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56842' \/><div class='watu-question-choice'><input type='radio' name='answer-14667[]' id='answer-id-56842' class='answer answer-12 js-answer-label answerof-14667' value='56842' \/>&nbsp;<label for='answer-id-56842' id='answer-label-56842' class='js-answer-label answer label-12'><span class='answer'>To verify that all security incidents are resolved<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56843' \/><div class='watu-question-choice'><input type='radio' name='answer-14667[]' id='answer-id-56843' class='answer answer-12 php-answer-label answerof-14667' value='56843' \/>&nbsp;<label for='answer-id-56843' id='answer-label-56843' class='php-answer-label answer label-12'><span class='answer'>To assess whether the organization&#8217;s security objectives are being met<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56844' \/><div class='watu-question-choice'><input type='radio' name='answer-14667[]' id='answer-id-56844' class='answer answer-12 js-answer-label answerof-14667' value='56844' \/>&nbsp;<label for='answer-id-56844' id='answer-label-56844' class='js-answer-label answer label-12'><span class='answer'>To eliminate the need for manual tracking and reporting<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(12,this)' id='btn-12' value='See Answer'  \/><input type='hidden' id='questionType12' value='radio' class=''><\/div><div class='watu-question' id='question-13'><div class='question-content'><p><strong>QUESTION 70<\/strong><br \/>Scenario 4: TradeB. a commercial bank that has just entered the market, accepts deposits from its clients and offers basic financial services and loans for investments. TradeB has decided to implement an information security management system (ISMS) based on ISO\/IEC 27001 Having no experience of a management<br \/>[^system implementation, TradeB&#8217;s top management contracted two experts to direct and manage the ISMS implementation project.<br \/>First, the project team analyzed the 93 controls of ISO\/IEC 27001 Annex A and listed only the security controls deemed applicable to the company and their objectives Based on this analysis, they drafted the Statement of Applicability. Afterward, they conducted a risk assessment, during which they identified assets, such as hardware, software, and networks, as well as threats and vulnerabilities, assessed potential consequences and likelihood, and determined the level of risks based on three nonnumerical categories (low, medium, and high). They evaluated the risks based on the risk evaluation criteria and decided to treat only the high risk category They also decided to focus primarily on the unauthorized use of administrator rights and system interruptions due to several hardware failures by establishing a new version of the access control policy, implementing controls to manage and control user access, and implementing a control for ICT readiness for business continuity Lastly, they drafted a risk assessment report, in which they wrote that if after the implementation of these security controls the level of risk is below the acceptable level, the risks will be accepted Which of the actions presented in scenario 4 is NOT compliant with the requirements of ISO\/IEC 27001?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14668' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56845' \/><div class='watu-question-choice'><input type='radio' name='answer-14668[]' id='answer-id-56845' class='answer answer-13 js-answer-label answerof-14668' value='56845' \/>&nbsp;<label for='answer-id-56845' id='answer-label-56845' class='js-answer-label answer label-13'><span class='answer'>TradeB selected only ISO\/IEC 27001 controls deemed applicable to the company<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56846' \/><div class='watu-question-choice'><input type='radio' name='answer-14668[]' id='answer-id-56846' class='answer answer-13 php-answer-label answerof-14668' value='56846' \/>&nbsp;<label for='answer-id-56846' id='answer-label-56846' class='php-answer-label answer label-13'><span class='answer'>The Statement of Applicability was drafted before conducting the risk assessment<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56847' \/><div class='watu-question-choice'><input type='radio' name='answer-14668[]' id='answer-id-56847' class='answer answer-13 js-answer-label answerof-14668' value='56847' \/>&nbsp;<label for='answer-id-56847' id='answer-label-56847' class='js-answer-label answer label-13'><span class='answer'>The external experts selected security controls and drafted the Statement of Applicability<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>According to ISO\/IEC 27001:2022, clause 6.1.3, the Statement of Applicability (SoA) is a document that identifies the controls that are applicable to the organization&#8217;s ISMS and explains why they are selected or not. The SoA is based on the results of the risk assessment and risk treatment, which are the previous steps in the risk management process. Therefore, the SoA should be drafted after conducting the risk assessment, not before. Drafting the SoA before the risk assessment may lead to inappropriate or incomplete selection of controls, as the organization may not have a clear understanding of its information security risks and their impact.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(13,this)' id='btn-13' value='See Answer'  \/><input type='hidden' id='questionType13' value='radio' class=''><\/div><div class='watu-question' id='question-14'><div class='question-content'><p><strong>QUESTION 71<\/strong><br \/>Question:<br \/>Which statement regarding management reviews is correct?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14669' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56848' \/><div class='watu-question-choice'><input type='radio' name='answer-14669[]' id='answer-id-56848' class='answer answer-14 php-answer-label answerof-14669' value='56848' \/>&nbsp;<label for='answer-id-56848' id='answer-label-56848' class='php-answer-label answer label-14'><span class='answer'>Management reviews are carried out at various levels in the organization<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56849' \/><div class='watu-question-choice'><input type='radio' name='answer-14669[]' id='answer-id-56849' class='answer answer-14 js-answer-label answerof-14669' value='56849' \/>&nbsp;<label for='answer-id-56849' id='answer-label-56849' class='js-answer-label answer label-14'><span class='answer'>Management reviews must be carried out monthly<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56850' \/><div class='watu-question-choice'><input type='radio' name='answer-14669[]' id='answer-id-56850' class='answer answer-14 js-answer-label answerof-14669' value='56850' \/>&nbsp;<label for='answer-id-56850' id='answer-label-56850' class='js-answer-label answer label-14'><span class='answer'>Top management can delegate the ultimate responsibility of the management review process to individuals working for the organization<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>ISO\/IEC 27001:2022 Clause 9.3 -Management Review:<br\/>&#8220;Top management shall review the organization&#8217;s ISMS, at planned intervals, to ensure its continuing suitability, adequacy and effectiveness.&#8221; While theultimate responsibility rests with top management, reviews may be conducted atmultiple organizational levelsfor broader visibility and alignment. ISO\/IEC 27004 also supports reviews at tactical and operational levels.<br\/>There isno requirementfor monthly reviews. Option C is incorrect, astop management cannot fully delegate the ultimate responsibility, only supporting roles.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(14,this)' id='btn-14' value='See Answer'  \/><input type='hidden' id='questionType14' value='radio' class=''><\/div><div class='watu-question' id='question-15'><div class='question-content'><p><strong>QUESTION 72<\/strong><br \/>Who should verily the effectiveness of the corrective actions taken by the auditee after an internal audit?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14670' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56851' \/><div class='watu-question-choice'><input type='radio' name='answer-14670[]' id='answer-id-56851' class='answer answer-15 js-answer-label answerof-14670' value='56851' \/>&nbsp;<label for='answer-id-56851' id='answer-label-56851' class='js-answer-label answer label-15'><span class='answer'>An Independent auditor should be contracted to perform this evaluation<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56852' \/><div class='watu-question-choice'><input type='radio' name='answer-14670[]' id='answer-id-56852' class='answer answer-15 php-answer-label answerof-14670' value='56852' \/>&nbsp;<label for='answer-id-56852' id='answer-label-56852' class='php-answer-label answer label-15'><span class='answer'>The internal auditor<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56853' \/><div class='watu-question-choice'><input type='radio' name='answer-14670[]' id='answer-id-56853' class='answer answer-15 js-answer-label answerof-14670' value='56853' \/>&nbsp;<label for='answer-id-56853' id='answer-label-56853' class='js-answer-label answer label-15'><span class='answer'>The information security manager<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(15,this)' id='btn-15' value='See Answer'  \/><input type='hidden' id='questionType15' value='radio' class=''><\/div><div class='watu-question' id='question-16'><div class='question-content'><p><strong>QUESTION 73<\/strong><br \/>Scenario 3: Socket Inc is a telecommunications company offering mainly wireless products and services. It uses MongoDB. a document model database that offers high availability, scalability, and flexibility.<br \/>Last month, Socket Inc. reported an information security incident. A group of hackers compromised its MongoDB database, because the database administrators did not change its default settings, leaving it without a password and publicly accessible.<br \/>Fortunately. Socket Inc. performed regular information backups in their MongoDB database, so no information was lost during the incident. In addition, a syslog server allowed Socket Inc. to centralize all logs in one server. The company found out that no persistent backdoor was placed and that the attack was not initiated from an employee inside the company by reviewing the event logs that record user faults and exceptions.<br \/>To prevent similar incidents in the future, Socket Inc. decided to use an access control system that grants access to authorized personnel only. The company also implemented a control in order to defineand implement rules for the effective use of cryptography, including cryptographic key management, to protect the database from unauthorized access The implementation was based on all relevant agreements, legislation, and regulations, and the information classification scheme. To improve security and reduce the administrative efforts, network segregation using VPNs was proposed.<br \/>Lastly, Socket Inc. implemented a new system to maintain, collect, and analyze information related to information security threats, and integrate information security into project management.<br \/>Based on scenario 3, what would help Socket Inc. address similar information security incidents in the future?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14671' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56854' \/><div class='watu-question-choice'><input type='radio' name='answer-14671[]' id='answer-id-56854' class='answer answer-16 js-answer-label answerof-14671' value='56854' \/>&nbsp;<label for='answer-id-56854' id='answer-label-56854' class='js-answer-label answer label-16'><span class='answer'>Using the MongoDB database with the default settings<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56855' \/><div class='watu-question-choice'><input type='radio' name='answer-14671[]' id='answer-id-56855' class='answer answer-16 php-answer-label answerof-14671' value='56855' \/>&nbsp;<label for='answer-id-56855' id='answer-label-56855' class='php-answer-label answer label-16'><span class='answer'>Using cryptographic keys to protect the database from unauthorized access<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56856' \/><div class='watu-question-choice'><input type='radio' name='answer-14671[]' id='answer-id-56856' class='answer answer-16 js-answer-label answerof-14671' value='56856' \/>&nbsp;<label for='answer-id-56856' id='answer-label-56856' class='js-answer-label answer label-16'><span class='answer'>Using the access control system to ensure that only authorized personnel is granted access<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>In Scenario 3, the measure that would help Socket Inc. address similar information security incidents in the future is &#8220;B. Using cryptographic keys to protect the database from unauthorized access.&#8221; Implementing cryptographic controls, including cryptographic key management, is a proactive measure to secure the data in the MongoDB database against unauthorized access. It ensures that even if attackers gain access to the database, they cannot read or misuse the data without the appropriate cryptographic keys. This approach aligns with best practices for securing sensitive data and is part of a comprehensive security strategy.<br\/>References:<br\/>* ISO 27001 &#8211; Annex A.10 &#8211; Cryptography<br\/>* ISO 27001 Annex A.10 &#8211; Cryptography | ISMS.online<br\/>* ISO 27001 cryptographic controls policy | What needs to be included?<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(16,this)' id='btn-16' value='See Answer'  \/><input type='hidden' id='questionType16' value='radio' class=''><\/div><div class='watu-question' id='question-17'><div class='question-content'><p><strong>QUESTION 74<\/strong><br \/>Which of the following standards provides the requirements and guidelines for establishing a privacy information management system (PIMS)?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14672' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56857' \/><div class='watu-question-choice'><input type='radio' name='answer-14672[]' id='answer-id-56857' class='answer answer-17 php-answer-label answerof-14672' value='56857' \/>&nbsp;<label for='answer-id-56857' id='answer-label-56857' class='php-answer-label answer label-17'><span class='answer'>ISO\/IEC 27701<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56858' \/><div class='watu-question-choice'><input type='radio' name='answer-14672[]' id='answer-id-56858' class='answer answer-17 js-answer-label answerof-14672' value='56858' \/>&nbsp;<label for='answer-id-56858' id='answer-label-56858' class='js-answer-label answer label-17'><span class='answer'>ISO\/IEC 27011<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56859' \/><div class='watu-question-choice'><input type='radio' name='answer-14672[]' id='answer-id-56859' class='answer answer-17 js-answer-label answerof-14672' value='56859' \/>&nbsp;<label for='answer-id-56859' id='answer-label-56859' class='js-answer-label answer label-17'><span class='answer'>ISO\/IEC 27009<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'><\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(17,this)' id='btn-17' value='See Answer'  \/><input type='hidden' id='questionType17' value='radio' class=''><\/div><div class='watu-question' id='question-18'><div class='question-content'><p><strong>QUESTION 75<\/strong><br \/>An organization has justified the exclusion of control 5.18 Access rights of ISO\/IEC 27001 in the Statement of Applicability (SoA) as follows: &#8220;An access control reader is already installed at the main entrance of the building.&#8221; Which statement is correct&#8217;<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14673' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56860' \/><div class='watu-question-choice'><input type='radio' name='answer-14673[]' id='answer-id-56860' class='answer answer-18 js-answer-label answerof-14673' value='56860' \/>&nbsp;<label for='answer-id-56860' id='answer-label-56860' class='js-answer-label answer label-18'><span class='answer'>The justification for the exclusion of a control is not required to be included in the SoA<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56861' \/><div class='watu-question-choice'><input type='radio' name='answer-14673[]' id='answer-id-56861' class='answer answer-18 php-answer-label answerof-14673' value='56861' \/>&nbsp;<label for='answer-id-56861' id='answer-label-56861' class='php-answer-label answer label-18'><span class='answer'>The justification is not acceptable, because it does not reflect the purpose of control 5.18<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56862' \/><div class='watu-question-choice'><input type='radio' name='answer-14673[]' id='answer-id-56862' class='answer answer-18 js-answer-label answerof-14673' value='56862' \/>&nbsp;<label for='answer-id-56862' id='answer-label-56862' class='js-answer-label answer label-18'><span class='answer'>The justification is not acceptable because it does not indicate that it has been selected based on the risk assessment results<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>According to ISO\/IEC 27001:2022, clause 6.1.3, the Statement of Applicability (SoA) is a document that identifies the controls that are applicable to the organization&#8217;s ISMS and explains why they are selected or not. The SoA is based on the results of the risk assessment and risk treatment, which are the previous steps in the risk management process. Therefore, the justification for the exclusion of a control should be based on the risk assessment results and the risk treatment plan, and should reflect the purpose and objective of the control.<br\/>Control 5.18 of ISO\/IEC 27001:2022 is about access rights to information and other associated assets, which should be provisioned, reviewed, modified and removed in accordance with the organization&#8217;s topic-specific policy on and rules for access control. The purpose of this control is to prevent unauthorized access to, modification of, and destruction of information assets. Therefore, the justification for the exclusion of this control should explain why the organization does not need to implement this control to protect its information assets from unauthorized access.<br\/>The justification given by the organization in the question is not acceptable, because it does not reflect the purpose of control 5.18. An access control reader at the main entrance of the building is a physical security measure, which is related to control 5.15 of ISO\/IEC 27001:2022, not control 5.18. Control 5.18 is about logical access rights to information systems and services, which are not addressed by the access control reader. Therefore, the organization should either provide a valid justification for the exclusion of control 5.18, or include it in the SoA and implement it according to the risk assessment and risk treatment results.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(18,this)' id='btn-18' value='See Answer'  \/><input type='hidden' id='questionType18' value='radio' class=''><\/div><div class='watu-question' id='question-19'><div class='question-content'><p><strong>QUESTION 76<\/strong><br \/>Question:<br \/>Who is responsible for ensuring that the ISMS achieves its intended outcomes?<\/p>\n<\/div><input type='hidden' name='question_id[]' value='14674' \/><div class='watu-questions-wrap '><input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56863' \/><div class='watu-question-choice'><input type='radio' name='answer-14674[]' id='answer-id-56863' class='answer answer-19 js-answer-label answerof-14674' value='56863' \/>&nbsp;<label for='answer-id-56863' id='answer-label-56863' class='js-answer-label answer label-19'><span class='answer'>IT Department<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56864' \/><div class='watu-question-choice'><input type='radio' name='answer-14674[]' id='answer-id-56864' class='answer answer-19 php-answer-label answerof-14674' value='56864' \/>&nbsp;<label for='answer-id-56864' id='answer-label-56864' class='php-answer-label answer label-19'><span class='answer'>Top management<\/span><\/label><\/div>\n<input type='hidden' name='answer_ids[]' class='watu-answer-ids' value='56865' \/><div class='watu-question-choice'><input type='radio' name='answer-14674[]' id='answer-id-56865' class='answer answer-19 js-answer-label answerof-14674' value='56865' \/>&nbsp;<label for='answer-id-56865' id='answer-label-56865' class='js-answer-label answer label-19'><span class='answer'>ISMS project manager<\/span><\/label><\/div>\n<\/div><div class='show-question-feedback' style='display:none;'>According to ISO\/IEC 27001:2022 Clause 5.1 -Leadership and Commitment:<br\/>&#8220;Top management shall demonstrate leadership and commitment with respect to the information security management system by:<br\/>e) ensuring that the ISMS achieves its intended outcomes.&#8221;<br\/>Top management must not only provide resources but alsointegrate ISMS into organizational processes, promote awareness, and support roles like the ISMS manager. While theISMS project managersupports implementation,top management bears ultimate accountability.<\/div><input type='button' class='showchecked' style='margin: 10px 0;' onclick='showanswer1(19,this)' id='btn-19' value='See Answer'  \/><input type='hidden' id='questionType19' value='radio' class=''><\/div><div style='display:none' id='question-20'><br \/><div class='question-content'><img decoding=\"async\" src=\"https:\/\/exam.real4prep.com\/wp-content\/plugins\/watu\/loading.gif\" width=\"16\" height=\"16\" alt=\"Loading ...\" title=\"Loading ...\" \/>&nbsp;Loading &#8230;<\/div><\/div><br \/>\n<input type=\"button\" name=\"action\" onclick=\"Watu.submitResult()\" id=\"action-button\" style=\"margin:0 auto 20px auto;\" value=\"View Results\"  class=\"watu-submit-button\" \/>\n<input type=\"hidden\" name=\"no_ajax\" value=\"0\"><input type=\"hidden\" name=\"quiz_id\" value=\"746\" \/>\n<input type=\"hidden\" id=\"watuStartTime\" name=\"start_time\" value=\"2026-09-23 18:06:58\" \/>\n<\/form>\n<\/div>\n<div id=\"watu-loading-result\" style=\"display:none;\">\n\t<p align=\"center\"><img decoding=\"async\" src=\"https:\/\/exam.real4prep.com\/wp-content\/plugins\/watu\/loading.gif\" width=\"16\" height=\"16\" alt=\"Loading\" title=\"Loading\" \/><\/p>\n<\/div>\t\n<script type=\"text\/javascript\">\nvar exam_id=0;\nvar question_ids='';\nvar watuURL='';\njQuery(function($){\nquestion_ids = \"14656,14657,14658,14659,14660,14661,14662,14663,14664,14665,14666,14667,14668,14669,14670,14671,14672,14673,14674\";\nexam_id = 746;\nWatu.exam_id = exam_id;\nWatu.qArr = question_ids.split(',');\nWatu.post_id = 1824;\nWatu.singlePage = '1';\nWatu.hAppID = \"0.03883500 1790186818\";\nwatuURL = \"https:\/\/exam.real4prep.com\/wp-admin\/admin-ajax.php\";\nWatu.noAlertUnanswered = 0;\n});\n\nfunction showanswer1(e,q) {\n\tvar check = new Array();\n\tjQuery('.answer-' + e).each(function (i) {\n\t\tcheck.push(this.checked)\n\t})\n\tlet textval = jQuery('.watu-textarea-' + e).val()\n\tif (jQuery.inArray(true, check) >= 0 || textval !== '' && textval !== undefined) {\n\t\tjQuery(q).stop().fadeOut(300)\n\t\tjQuery('.php-answer-label.label-' + e).addClass(\n\t\t\t'correct-answer'\n\t\t)\n\t\tjQuery('.answer-' + e).each(function (i) {\n\t\t\tif (this.checked && this.className.match(\/js\\-answer\/)) {\n\t\t\t\tvar number = this.id.toString().replace(\/\\D\/g, '')\n\t\t\t\tif (number) {\n\t\t\t\t\tjQuery('#answer-label-' + number).addClass('user-answer')\n\t\t\t\t}\n\t\t\t}\n\t\t})\n\t\tjQuery(q).siblings('.show-question-feedback').stop().fadeIn(300)\n\t\ttextval = ''\n\t} else if (textval == '' || textval == undefined){\n\t\t\/\/jQuery(\".hint\").stop().fadeIn(300)\n\t\talert('Please first answer the question');\n\t}\n}\nvar btnisshow = jQuery(\".php-answer-label\").length\nif (btnisshow > 0) {\n\tjQuery('.showchecked').show()\n} else {\n\tjQuery('.showchecked').hide()\n}\n<\/script>\n<p>PECB ISO-IEC-27001-Lead-Implementer certification exam is a valuable credential for professionals who are responsible for managing and protecting their organization&#8217;s information assets. ISO-IEC-27001-Lead-Implementer exam validates an individual&#8217;s knowledge and skills in implementing and managing an ISMS based on the ISO\/IEC 27001 standard and demonstrates their commitment to ensuring the security and integrity of their organization&#8217;s information assets.<\/p>\n<p>&nbsp;<\/p>\n<p><strong>Reliable Study Materials for ISO-IEC-27001-Lead-Implementer Exam Success For Sure: <a href=\"https:\/\/www.real4prep.com\/ISO-IEC-27001-Lead-Implementer-exam.html\" target=\"_blank\">https:\/\/www.real4prep.com\/ISO-IEC-27001-Lead-Implementer-exam.html<\/a><\/strong><\/p>\n\n","protected":false},"excerpt":{"rendered":"<p>100% Real &amp; Accurate ISO-IEC-27001-Lead-Implementer Questions and Answers with Free and Fast Updates Get Unlimited Access to ISO-IEC-27001-Lead-Implementer Certification Exam Cert Guide PECB ISO-IEC-27001-Lead-Implementer certification exam is&#8230; <\/p>","protected":false},"author":1,"featured_media":1825,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"rank_math_lock_modified_date":false,"footnotes":""},"categories":[5241,1163],"tags":[5238,5239,5240,5237,5236],"class_list":["post-1824","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-iso-iec-27001-lead-implementer","category-pecb","tag-iso-iec-27001-lead-implementer-dumps-torrent","tag-iso-iec-27001-lead-implementer-free-exam-questions","tag-iso-iec-27001-lead-implementer-latest-test-cram-materials","tag-iso-iec-27001-lead-implementer-valid-real-test-questions","tag-new-iso-iec-27001-lead-implementer-test-duration"],"_links":{"self":[{"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/posts\/1824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/comments?post=1824"}],"version-history":[{"count":1,"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/posts\/1824\/revisions"}],"predecessor-version":[{"id":1855,"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/posts\/1824\/revisions\/1855"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/media\/1825"}],"wp:attachment":[{"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/media?parent=1824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/categories?post=1824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/exam.real4prep.com\/ko\/wp-json\/wp\/v2\/tags?post=1824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}