Valid ISO-IEC-27001-Lead-Implementer Dumps shared by EduDump.com for Helping Passing ISO-IEC-27001-Lead-Implementer Exam! EduDump.com now offer the newest ISO-IEC-27001-Lead-Implementer exam dumps, the EduDump.com ISO-IEC-27001-Lead-Implementer exam questions have been updated and answers have been corrected get the newest EduDump.com ISO-IEC-27001-Lead-Implementer dumps with Test Engine here:
Nimbus Route, a cloud-native logistics optimization company based in the Netherlands, offers Al-driven route planning fleet management tools, and real time shipment tracking solutions to clients across Europe and North America. To safeguard sensitive logistics data and ensure resilience across its cloud services. Nimbus Route has implemented an information security management system (ISMS) based on ISO/lEC 27001. The company is also integrating intelligent transport systems and predictive analytics to increase operational efficiency and sustainability. As part of the ISMS implementation process, the company is determining the competence levels required to manage its ISMS. It has considered various factors when defining these competence requirements, including technological advancements, regulatory requirements, the company's mission. strategic objectives, available resources. as well as the needs and expectations of its customers. Furthermore, the company has established clear guidelines for internal and external communication related to the ISMS, defining what information to share, when to share it. with whom, and through which channels. However, not all communications have been formally documented: instead, the company classified and managed communication based on its needs. ensuring that documentation is maintained only to the extent necessary for the ISMS's effectiveness To support its expanding digital services and ensure operational scalability. Nimbus Route utilizes virtualized computing resources provided by an external cloud service provider. This setup allows the company to configure and manage its operating systems, deploy applications. and control storage environments as needed while relying on the provider to maintain the underlying cloud environment. To further enhance is predictive capabilities. Nimbus Route is adopting machine learning techniques across several of its core services Specifically, it uses machine learning for route optimization and delivery time estimation, leveraging algorithms such as logistic regression and support vector machines to identify patterns in historical transportation data. As Nimbus Route's ISMS matures, the company has chosen a chased approach to its transition into full operational mode Rather than waiting for a formal launch, individual elements of the ISMS, such as risk treatment procedures, access controls, and audit logging, are being activated progressively as soon as they are developed and approved Based on the scenario above answer the following question. As indicated in scenario 6. what does Nimbus Route s approach to managing its computing environment suggest about the type of cloud service model it uses?
Correct Answer: A
Nimbus Route's cloud usage clearly indicates Infrastructure as a Service (IaaS), making Option A the correct and verified answer. The scenario states that Nimbus Route: * Uses virtualized computing resources from an external cloud provider * Configures and manages its own operating systems * Deploys applications * Controls storage environments * Relies on the provider only to maintain the underlying cloud infrastructure These characteristics align precisely with the IaaS service model, where the cloud provider supplies compute, storage, networking, and virtualization, while the customer retains responsibility for operating systems, middleware, applications, and data. In contrast: * Software as a Service (SaaS) would not allow Nimbus Route to manage operating systems or storage directly. * Platform as a Service (PaaS) would abstract away OS management and infrastructure control, which the scenario explicitly says Nimbus Route performs. From an ISO/IEC 27001:2022 perspective, this distinction is critical for defining shared responsibility under Annex A controls, especially: * A.5.19 - Information security in supplier relationships * A.5.23 - Information security for use of cloud services These controls require organizations to understand which security responsibilities remain with the organization versus the cloud service provider.