Official Bank 0/80

Information Security Foundation based on ISO/IEC 27002 Exam (ISFS) - Exin Actual Exam Questions

Last updated on April 25, 2026

97% Exam Compliance
80 Total Questions
1
Question

You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?

Options
A

Natural threat

B

Organizational threat

C

Social Engineering

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question

Which measure assures that valuable information is not left out available for the taking?

Options
A

Clear desk policy

B

Infra-red detection

C

Access passes

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question

My user profile specifies which network drives I can read and write to. What is the name of the type of logical access management wherein my access and rights are determined centrally?

Options
A

Discretionary Access Control (DAC)

B

Mandatory Access Control (MAC)

C

Public Key Infrastructure (PKI)

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question

You are the owner of the courier company SpeeDelivery. You employ a few people who, while waiting to make a delivery, can carry out other tasks. You notice, however, that they use this time to send and read their private mail and surf the Internet. In legal terms, in which way can the use of the Internet and e-mail facilities be best regulated?

Options
A

Installing an application that makes certain websites no longer accessible and that filters attachments in e-mails

B

Drafting a code of conduct for the use of the Internet and e-mail in which the rights and obligations of both the employer and staff are set down

C

Implementing privacy regulations

D

Installing a virus scanner

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question

Why do organizations have an information security policy?

Options
A

In order to demonstrate the operation of the Plan-Do-Check-Act cycle within an organization.

B

In order to ensure that staff do not break any laws.

C

In order to give direction to how information security is set up within an organization.

D

In order to ensure that everyone knows who is responsible for carrying out the backup procedures.

Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.