EMT Practice Test

1. Question Content...


Question List

Question1: What is the ISO / IEC 27002 standard?

Question2: What sort of security does a Public Key Infrastructure (PKI) offer?

Question3: Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?

Question4: What do employees need to know to report a security incident?

Question5: Which of the following measures is a correctivemeasure?

Question6: You are the owner of the courier company SpeeDelivery. You have carried out a risk analysis and now want to determine your risk strategy. You decide to take measures for the large risks but not for the small risks. What is this risk strategy called?

Question7: What is the most important reason for applying the segregation of duties?

Question8: Which of the following measures is a preventive measure?

Question9: The company Midwest Insurance has taken many measures to protect its information. It uses an Information Security Management System, the input and output of data in applications is validated, confidential documents are sent in encrypted form and staff use tokens to access information systems. Which of these is not a technical measure?

Question10: You are a consultant and areregularly hired by the Ministry of Defense to perform analysis. Since the assignments are irregular, you outsource the administration of your business to temporary workers. You don't want the temporary workers to have access to your reports.
Which reliability aspect of the information in your reports must you protect?

Question11: What is the best way to comply with legislation and regulations for personal data protection?

Question12: Companies use 27002 for compliance for which of the following reasons:

Question13: The identified owner of an asset is always an individual

Question14: Logging in to a computer system is an access-granting process consisting of three steps: identification, authentication and authorization. What occurs during the first step of this process: identification?

Question15: What is the greatest risk for an organization ifno information security policy has been defined?

Question16: Who is authorized to change the classification of a document?

Question17: What does the Information Security Policy describe?