Free EXIN ISFS Exam Questions (page: 2)

You are the owner of the courier company SpeeDelivery. You employ a few people who, while waiting to make a delivery, can carry out other tasks. You notice, however, that they use this time to send and read their private mail and surf the Internet. In legal terms, in which way can the use of the Internet and e-mail facilities be best regulated?

  1. Installing an application that makes certain websites no longer accessible and that filters attachments in e-mails
  2. Drafting a code of conduct for the use of the Internet and e-mail in which the rights and obligations of both the employer and staff are set down
  3. Implementing privacy regulations
  4. Installing a virus scanner

Answer(s): B



My user profile specifies which network drives I can read and write to. What is the name of the type of logical access management wherein my access and rights are determined centrally?

  1. Discretionary Access Control (DAC)
  2. Mandatory Access Control (MAC)
  3. Public Key Infrastructure (PKI)

Answer(s): B



You apply for a position in another company and get the job. Along with your contract, you are asked to sign a code of conduct. What is a code of conduct?

  1. A code of conduct specifies how employees are expected to conduct themselves and is the same for all companies.
  2. A code of conduct is a standard part of a labor contract.
  3. A code of conduct differs from company to company and specifies, among other things, the rules of behavior with regard to the usage of information systems.

Answer(s): C



You are the owner of a growing company, SpeeDelivery, which provides courier services. You decide that it is time to draw up a risk analysis for your information system. This includes an
inventory of the threats and risks. What is the relation between a threat, risk and risk analysis?

  1. A risk analysis identifies threats from the known risks.
  2. A risk analysis is used to clarify which threats are relevant and what risks they involve.
  3. A risk analysis is used to remove the risk of a threat.
  4. Risk analyses help to find a balance between threats and risks.

Answer(s): B



The consultants at Smith Consultants Inc. work on laptops that are protected by asymmetrical cryptography. To keep the management of the keys cheap, all consultants use the same key pair. What is the companys risk if they operate in this manner?

  1. If the private key becomes known all laptops must be supplied with new keys.
  2. If the Public Key Infrastructure (PKI) becomes known all laptops must be supplied with new keys.
  3. If the public key becomes known all laptops must be supplied with new keys.

Answer(s): A



What is a repressive measure in the case of a fire?

  1. Taking out fire insurance
  2. Putting out a fire after it has been detected by a fire detector
  3. Repairing damage caused by the fire

Answer(s): B



You are the owner of SpeeDelivery courier service. Because of your companys growth you have to think about information security. You know that you have to start creating a policy. Why is it so important to have an information security policy as a starting point?

  1. The information security policy gives direction to the information security efforts.
  2. The information security policy supplies instructions for the daily practice of information security.
  3. The information security policy establishes which devices will be protected.
  4. The information security policy establishes who is responsible for which area of information security.

Answer(s): A



The act of taking organizational security measures is inextricably linked with all other measures that have to be taken. What is the name of the system that guarantees the coherence of information security in the organization?

  1. Information Security Management System (ISMS)
  2. Rootkit
  3. Security regulations for special information for the government

Answer(s): A






Post your Comments and Discuss EXIN ISFS exam prep with other Community members:

ISFS Exam Discussions & Posts