It is not possible for an organization to implement information security in a consistent manner.
Questions for the ISO IEC 27001 LEAD IMPLEMENTER were updated on : Mar 24 ,2026
What is the objective of classifying information?
C
What is the greatest risk for an organization if no information security policy has been defined?
D
It is not possible for an organization to implement information security in a consistent manner.
An employee in the administrative department of Smiths Consultants Inc. finds out that the expiry
date of a contract with one of the clients is earlier than the start date. What type of measure could
prevent this error?
D
Integrity measure
We can acquire and supply information in various ways. The value of the information depends on
whether it is reliable. What are the reliability aspects of information?
B
Confidentiality, Integrity, and Availability - the CIA Tirad.
What is an example of a security incident?
B
A member of staff loses a laptop.
Which of the following measures is a preventive measure?
C
Putting sensitive information in a safe
Who is authorized to change the classification of a document?
C
The owner of the document
Peter works at the company Midwest Insurance. His manager, Linda, asks him to send the terms and
conditions for a life insurance policy to Rachel, a client. Who determines the value of the information
in the insurance terms and conditions document?
A
The recipient, Rachel
You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide
that it is time to draw up a risk analysis for your information system. This includes an inventory of
threats and risks. What is the relation between a threat, risk and risk analysis?
B
A risk analysis is used to clarify which threats are relevant and what risks they involve.
A risk analysis is used to clarify which threats are relevant and what risks they involve.
You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now
want to determine your risk strategy. You decide to take measures for the large risks but not for the
small risks. What is this risk strategy called?
C
Risk bearing
You have just started working at a large organization. You have been asked to sign a code of conduct
as well as a contract. What does the organization wish to achieve with this?
A
A code of conduct helps to prevent the misuse of IT facilities.
What do employees need to know to report a security incident?
A
How to report an incident and to whom.
Which of the following measures is a corrective measure?
D
Restoring a backup of the correct database after a corrupt copy of the database was written over the original
What is an example of a non-human threat to the physical environment?
C
Storm affecting the data center.
What is the best description of a risk analysis?
B
A risk analysis helps to estimate the risks and develop the appropriate security measures.
A risk analysis helps to estimate the risks and develop the appropriate security measures.
B. Creating a label that indicates how confidential the information is
Creating a label that indicates how confidential the information is
Defining different levels of sensitivity into which information may be arranged
Defining different levels of sensitivity into which information may be arranged