EMT Practice Test

1. Question Content...


Question List

Question1: Which of the following does an Asset Register contain? (Choose two)

Question2: You have just completed a scheduled information security audit of your organisation when the IT Manager approaches you and asks for your assistance in the revision of the company's risk management process.
He is attempting to update the current documentation to make it easier for other managers to understand, however, it is clear from your discussion he is confusing several key terms.
You ask him to match each of the descriptions with the appropriate risk term. What should the correct answers be?

Question3: You have a hard copy of a customer design document that you want to dispose off. What would you do

Question4: As a new member of the IT department you have noticed that confidential information has been leaked several times. This may damage the reputation of the company. You have been asked to propose an organisational measure to protect laptop computers. What is the first step in a structured approach to come up with this measure?

Question5: Which of the following factors does NOT contribute to the value of data for an organisation?

Question6: Please match the roles to the following descriptions:

To complete the table click on the blank section you want to complete so that it is highlighted in red, and then click on the applicable test from the options below. Alternatively, you may drag and drop each option to the appropriate blank section.

Question7: Availability means

Question8: Cabling Security is associated with Power, telecommunication and network cabling carrying information are protected from interception and damage.

Question9: The following are the guidelines to protect your password, except:

Question10: Which one of the following statements best describes the purpose of conducting a document review?

Question11: Which is not a requirement of HR prior to hiring?

Question12: How are data and information related?

Question13: The following are definitions of Information, except:

Question14: Information or data that are classified as ______ do not require labeling.

Question15: What is social engineering?

Question16: Which one of the following options describes the main purpose of a Stage 1 audit?

Question17: Select the words that best complete the sentence:
To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

Question18: An employee caught with offense of abusing the internet, such as P2P file sharing or video/audio streaming, will not receive a warning for committing such act but will directly receive an IR.

Question19: After a devastating office fire, all staff are moved to other branches of the company. At what moment in the incident management process is this measure effectuated?

Question20: All are prohibited in acceptable use of information assets, except:

Question21: Why do we need to test a disaster recovery plan regularly, and keep it up to date?

Question22: Which of the following is a technical security measure?

Question23: A well-executed risk analysis provides a great deal of useful information. A risk analysis has four main objectives.
What is not one of the four main objectives of a risk analysis?

Question24: What is the worst possible action that an employee may receive for sharing his or her password or access with others?

Question25: Four types of Data Classification (Choose two)

Question26: You are performing an ISMS audit at a residential nursing home railed ABC that provides healthcare services.
The next step in your audit plan is to verify the effectiveness of the continual improvement process. During the audit, you learned most of the residents' family members (90%) receive WeCare medical device promotional advertisements through email and SMS once a week via ABC's healthcare mobile app. All of them do not agree on the use of the collected personal data (or marketing or any other purposes than nursing and medical care on the signed service agreement with ABC. They have very strong reason to believe that ABC is leaking residents' and family members' personal information to a non-relevant third party and they have filed complaints.
The Service Manager says that all these complaints have been treated as nonconformities, and the corrective actions have been planned and implemented according to the Nonconformity and Corrective management procedure. The corrective action involved stopping working with WeCare the medical device manufacturer immediately and asking them to delete all personal data received as well as sending an apology email to all residents and their family members.
You are preparing the audit findings. Select one option of the correct finding.

Question27: What is a reason for the classification of information?

Question28:

Question29: What would be the reference for you to know who should have access to data/document?

Question30: What type of compliancy standard, regulation or legislation provides a code of practice for information security?

Question31: After completing Stage 1 and in preparation for a Stage 2 initial certification audit, the auditee informs the audit team leader that they wish to extend the audit scope to include two additional sites that have recently been acquired by the organisation.
Considering this information, what action would you expect the audit team leader to take?

Question32: Changes on project-managed applications or database should undergo the change control process as documented.

Question33: Select a word from the following options that best completes the sentence:
To complete the sentence with the word(s) click on the blank section you want to complete so that it is highlighted in red, and then click on the application text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

Question34: Stages of Information

Question35: What is the relationship between data and information?

Question36: What controls can you do to protect sensitive data in your computer when you go out for lunch?

Question37: CMM stands for?

Question38: You see a blue color sticker on certain physical assets. What does this signify?

Question39: Which of the following is a preventive security measure?

Question40: We can leave laptops during weekdays or weekends in locked bins.

Question41: Who is responsible for Initial asset allocation to the user/custodian of the assets?

Question42: What is the name of the system that guarantees the coherence of information security in the organization?

Question43: Which of the following is a possible event that can have a disruptive effect on the reliability of information?

Question44: Implement plan on a test basis - this comes under which section of PDCA

Question45: Which two of the following statements are true?

Question46: In which order is an Information Security Management System set up?

Question47: In regard to generating an audit finding, select the words that best complete the following sentence.
To complete the sentence with the best word(s), click on the blank section you want to complete so that it Is highlighted in red, and then click on the applicable text from the options below. Alternatively, you may drag and drop the option to the appropriate blank section.

Question48: __________ is a software used or created by hackers to disrupt computer operation, gather sensitive information, or gain access to private computer systems.

Question49: What type of measure involves the stopping of possible consequences of security incidents?

Question50: Which department maintain's contacts with law enforcement authorities, regulatory bodies, information service providers and telecommunications service providers depending on the service required.

Question51: Often, people do not pick up their prints from a shared printer. How can this affect the confidentiality of information?

Question52: Which two of the following statements are true?

Question53: Changes to the information processing facilities shall be done in controlled manner.

Question54: A decent visitor is roaming around without visitor's ID. As an employee you should do the following, except:

Question55: You are an experienced ISMS audit team leader. An auditor in training has approached you to ask you to clarify the different types of audits she may be required to undertake.
Match the following audit types to the descriptions.
To complete the table click on the blank section you want to complete so that It is highlighted In fed, and then click on the applicable text from the options below. Alternatively, you may drag and drop each option to the appropriate blank section.

Question56: In acceptable use of Information Assets, which is the best practice?