Information Security Management Examination (SG) | Section A Security Management and Law 04
Problem 1 ・ Question 1 / 10
What should be done first in operating an ISMS?
View explanation
Taking the organisation's circumstances into account, make the scope and the basic policy of the ISMS clear.
Problem 1 ・ Question 2 / 10
Which team is responsible for the organisation's response to information security incidents?
View explanation
A CSIRT gathers and analyses incident information, responds and coordinates communication.
Problem 1 ・ Question 3 / 10
Which is an appropriate way to check the effectiveness of security education?
View explanation
Measure comprehension and changes in behaviour, and improve the content of the education according to the results.
Problem 1 ・ Question 4 / 10
In managing the security of a subcontractor, what should be done before the contract?
View explanation
According to the importance of the information entrusted, confirm the subcontractor's management capability at the selection stage.
Problem 1 ・ Question 5 / 10
What should an organisation that has outsourced work involving personal data do?
View explanation
The outsourcing organisation is required to supervise properly how the subcontractor handles personal data.
Problem 1 ・ Question 6 / 10
Which law relates to the act of using someone else's ID and password without permission to break into an access-controlled system?
View explanation
Unauthorised access using another person's identification code falls under that Act.
Problem 1 ・ Question 7 / 10
Which is among the requirements for protection as a trade secret?
View explanation
A trade secret must be managed as secret, be useful and not be publicly known.
Problem 1 ・ Question 8 / 10
Which is appropriate access management when an employee leaves the company?
View explanation
Remove unnecessary rights promptly when people leave or change roles.
Problem 1 ・ Question 9 / 10
Which is the most appropriate evidence for an information security audit?
View explanation
Audit conclusions rest on sufficient and appropriate evidence that can be confirmed objectively.
Problem 1 ・ Question 10 / 10
What is the main purpose of setting out contacts and the division of roles in an incident response plan?
View explanation
Deciding the chain of command and the lines of communication in advance keeps down confusion in the first response.
Result
More sets in this exam
- Information Security Management Examination (SG) | Section A Security Fundamentals 01
- Information Security Management Examination (SG) | Section A Threats and Attack Techniques 02
- Information Security Management Examination (SG) | Section A Cryptography, Authentication and Controls 03
- Information Security Management Examination (SG) | Section A Attack Mitigation and Business Continuity 06
- Information Security Management Examination (SG) | Section A Security Properties and Design Principles Questions 07
- Information Security Management Examination (SG) | Section A Risk Treatment, Supplier, and Incident Management Questions 08