Official Bank 0/80

Information Security Foundation based on ISO/IEC 27002 Exam (ISFS) - Exin Exam Questions

Last updated on June 20, 2026

97% Exam Compliance
80 Total Questions
1
Question
We can acquire and supply information in various ways. The value of the information depends on whether it is reliable. What are the reliability aspects of information?
Options
A Availability, Integrity and Completeness
B Timeliness, Accuracy and Completeness
C Availability, Integrity and Confidentiality
D Availability, Information Value and Confidentiality
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

2
Question
What is the definition of the Annual Loss Expectancy?
Options
A The Annual Loss Expectancy is the average damage calculated by insurance companies for businesses in a country.
B The Annual Loss Expectancy is the minimum amount for which an organization must insure itself.
C The Annual Loss Expectancy is the size of the damage claims resulting from not having carried out risk analyses effectively.
D The Annual Loss Expectancy is the amount of damage that can occur as a result of an incident during the year.
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

3
Question
You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?
Options
A Encrypt the hard drives of laptops and USB sticks
B Set up an access control policy
C Appoint security personnel
D Formulate a policy regarding mobile media (PDAs, laptops, smartphones, USB sticks)
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

4
Question
The Information Security Manager (ISM) at Smith Consultants Inc. introduces the following measures to assure information security:

- The security requirements for the network are specified.

- A test environment is set up for the purpose of testing reports coming from the database.

- The various employee functions are assigned corresponding access rights.

- RFID access passes are introduced for the building.

Which one of these measures is not a technical measure?
Options
A Introducing a logical access policy
B Introducing RFID access passes
C Setting up a test environment
D The specification of requirements for the network
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

5
Question
You work in the office of a large company. You receive a call from a person claiming to be from the Helpdesk. He asks you for your password. What kind of threat is this?
Options
A Social Engineering
B Organizational threat
C Natural threat
Discussion (0 comments)

to join the discussion

Community Discussion

No discussions yet. Be the first to ask!

Finish Practice?

Are you sure you want to finish? This will end your practice session.