Valid ISO-IEC-27001-Lead-Implementer Dumps shared by ExamDiscuss.com for Helping Passing ISO-IEC-27001-Lead-Implementer Exam! ExamDiscuss.com now offer the newest ISO-IEC-27001-Lead-Implementer exam dumps, the ExamDiscuss.com ISO-IEC-27001-Lead-Implementer exam questions have been updated and answers have been corrected get the newest ExamDiscuss.com ISO-IEC-27001-Lead-Implementer dumps with Test Engine here:

Access ISO-IEC-27001-Lead-Implementer Dumps Premium Version
(294 Q&As Dumps, 35%OFF Special Discount Code: freecram)

<< Prev Question Next Question >>

Question 34/35

Scenario 3: Socket Inc is a telecommunications company offering mainly wireless products and services. It uses MongoDB. a document model database that offers high availability, scalability, and flexibility.
Last month, Socket Inc. reported an information security incident. A group of hackers compromised its MongoDB database, because the database administrators did not change its default settings, leaving it without a password and publicly accessible.
Fortunately. Socket Inc. performed regular information backups in their MongoDB database, so no information was lost during the incident. In addition, a syslog server allowed Socket Inc. to centralize alllogs in one server. The company found out that no persistent backdoor was placed and that the attack was not initiated from an employee inside the company by reviewing the event logs that record user faults and exceptions.
To prevent similar incidents in the future, Socket Inc. decided to use an access control system that grants access to authorized personnel only. The company also implemented a control in order to define and implement rules for the effective use of cryptography, including cryptographic key management, to protect the database from unauthorized access The implementation was based on all relevant agreements, legislation, and regulations, and the information classification scheme. To improve security and reduce the administrative efforts, network segregation using VPNs was proposed.
Lastly, Socket Inc. implemented a new system to maintain, collect, and analyze information related to information security threats, and integrate information security into project management.
Based on scenario 3. which information security control of Annex A of ISO/IEC 27001 did Socket Inc.
implement by establishing a new system to maintain, collect, and analyze information related to information security threats?

LEAVE A REPLY

Your email address will not be published. Required fields are marked *

Question List (35q)
Question 1: An organization that has an ISMS in place conducts managemen...
Question 2: Scenario 6: Skyver offers worldwide shipping of electronic p...
Question 3: Scenario 4: TradeB. a commercial bank that has just entered ...
Question 4: Scenario 8: SunDee is an American biopharmaceutical company,...
Question 5: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 6: Scenario 5: Operaze is a small software development company ...
Question 7: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 8: Scenario 10: NetworkFuse develops, manufactures, and sells n...
Question 9: Scenario 7: InfoSec is a multinational corporation headquart...
Question 10: An organization wants to enable the correlation and analysis...
Question 11: Who should be involved, among others, in the draft, review, ...
Question 12: Scenario 5: Operaze is a small software development company ...
Question 13: Scenario 7: InfoSec is a multinational corporation headquart...
Question 14: An organization documented each security control that it Imp...
Question 15: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 16: What is the main purpose of Annex A 7.1 Physical security pe...
Question 17: An organization has justified the exclusion of control 5.18 ...
Question 18: Scenario 10: NetworkFuse develops, manufactures, and sells n...
Question 19: Scenario 3: Socket Inc is a telecommunications company offer...
Question 20: Scenario 3: Socket Inc is a telecommunications company offer...
Question 21: A small organization that is implementing an ISMS based on I...
Question 22: Which of the situations below can negatively affect the inte...
Question 23: Which of the following is NOT part of the steps required by ...
Question 24: An organization uses Platform as a Services (PaaS) to host i...
Question 25: Scenario 10: NetworkFuse develops, manufactures, and sells n...
Question 26: Scenario 4: TradeB. a commercial bank that has just entered ...
Question 27: The IT Department of a financial institution decided to impl...
Question 28: Which approach should organizations use to implement an ISMS...
Question 29: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 30: An organization has implemented a control that enables the c...
Question 31: Scenario 3: Socket Inc is a telecommunications company offer...
Question 32: Scenario 2: Beauty is a cosmetics company that has recently ...
Question 33: Scenario 1: HealthGenic is a pediatric clinic that monitors ...
Question 34: Scenario 3: Socket Inc is a telecommunications company offer...
Question 35: Scenario 7: InfoSec is a multinational corporation headquart...