PECB Lead Implementer - PECB Certified ISO/IEC 27001 Lead Implementer Exam
Page: 3 / 57
Total 285 questions
Question #11 (Topic: Exam A)
FinanceX, a well-known financial institution, uses an online banking platform that enables clients to easily and securely access their bank accounts. To log in, clients are required to enter the one-time authorization code sent to their smartphone. What can be concluded from this scenario?
A. FinanceX has implemented a security control that ensures the confidentiality of information
B. FinanceX has implemented an integrity control that avoids the involuntary corruption of data
C. FinanceX has incorrectly implemented a security control that could become a vulnerability
Answer: A
Question #12 (Topic: Exam A)
An employee of the organization accidentally deleted customers’ data stored in the database. What is the impact of this action?
A. Information is not accessible when required
B. Information is modified in transit
C. Information is not available to only authorized users
Answer: A
Question #13 (Topic: Exam A)
Which of the following statements regarding information security risk is NOT correct?
A. Information security risk is associated with the potential that the vulnerabilities of an information asset may be exploited by threats
B. Information security risk cannot be accepted without being treated or during the process of risk treatment
C. Information security risk can be expressed as the effect of uncertainty on information security objectives
Answer: B
Question #14 (Topic: Exam A)
The IT Department of a financial institution decided to implement preventive controls to avoid potential security breaches. Therefore, they separated the development, testing, and operating equipment, secured their offices, and used cryptographic keys. However, they are seeking further measures to enhance their security and minimize the risk of security breaches. Which of the following controls would help the IT Department achieve this objective?
A. Alarms to detect risks related to heat, smoke, fire, or water
B. Change all passwords of all systems
C. An access control software to restrict access to sensitive files
Answer: C
Question #15 (Topic: Exam A)
Diana works as a customer service representative for a large e-commerce company. One day, she accidently modified the order details of a customer without their permission. Due to this error, the customer received an incorrect product. Which information security principle was breached in this case?
A. Availability
B. Confidentiality
C. Integrity
Answer: C