Increase your chances of passing the PECB ISO-IEC-27001-Lead-Implementer exam questions on your first try. Practice with our free online ISO-IEC-27001-Lead-Implementer exam mock test designed to help you prepare effectively and confidently.
Scenario 7: Incident Response at Texas H&H Inc.
Once they made sure that the attackers do not have access in their system, the security administrators decided
to proceed with the forensic analysis. They concluded that their access security system was not designed tor
threat detection, including the detection of malicious files which could be the cause of possible future attacks.
Based on these findings. Texas H$H inc, decided to modify its access security system to avoid future
incidents and integrate an incident management policy in their Information security policy that could serve as
guidance for employees on how to respond to similar incidents.
Based on the scenario above, answer the following question: Texas H&H Inc. decided to assign an internal expert for their forensic analysis. Is this acceptable? Refer lo scenario 7.
Which statement regarding organizational roles, responsibilities, and authorities isNOTcorrect?
Scenario 5: Operaze is a small software development company that develops applications for various
companies around the world. Recently, the company conducted a risk assessment to assess the information
security risks that could arise from operating in a digital landscape. Using different testing methods, including
penetration Resting and code review, the company identified some issues in its ICT systems, including
improper user permissions, misconfigured security settings, and insecure network configurations. To resolve
these issues and enhance information security, Operaze decided to implement an information security
management system (ISMS) based on ISO/IEC 27001.
Considering that Operaze is a small company, the entire IT team was involved in the ISMS implementation
project. Initially, the company analyzed the business requirements and the internal and external environment,
identified its key processes and activities, and identified and analyzed the interested parties In addition, the top
management of Operaze decided to Include most of the company's departments within the ISMS scope. The
defined scope included the organizational and physical boundaries. The IT team drafted an information
security policy and communicated it to all relevant interested parties In addition, other specific policies were
developed to elaborate on security issues and the roles and responsibilities were assigned to all interested
parties.
Following that, the HR manager claimed that the paperwork created by ISMS does not justify its value and the
implementation of the ISMS should be canceled However, the top management determined that this claim was
invalid and organized an awareness session to explain the benefits of the ISMS to all interested parties.
Operaze decided to migrate Its physical servers to their virtual servers on third-party infrastructure. The new
cloud computing solution brought additional changes to the company Operaze's top management, on the other
hand, aimed to not only implement an effective ISMS but also ensure the smooth running of the ISMS
operations. In this situation, Operaze's top management concluded that the services of external experts were
required to implement their information security strategies. The IT team, on the other hand, decided to initiate
a change in the ISMS scope and implemented the required modifications to the processes of the company.
Based on scenario 5. in which category of the interested parties does the MR manager of Operaze belong?
Scenario 2:
Beauty is a well-established cosmetics company in the beauty industry. The company was founded several
decades ago with a passion for creating high-quality skincare, makeup, and personal care products that
enhance natural beauty. Over the years, Beauty has built a strong reputation for its innovative product
offerings, commitment to customer satisfaction, and dedication to ethical and sustainable business practices.
In response to the rapidly evolving landscape of consumer shopping habits, Beauty transitioned from
traditional retail to an e-commerce model. To initiate this strategy, Beauty conducted a comprehensive
information security risk assessment, analyzing potential threats and vulnerabilities associated with its new ecommerce venture, aligned with its business strategy and objectives.
Concerning the identified risks, the company implemented several information security controls. All
employees were required to sign confidentiality agreements to emphasize the importance of protecting
sensitive customer data. The company thoroughly rev iewed user access rights, ensuring only authorized personnel could access sensitive information. In addition, since the company stores valuable products and
unique formulas in the warehouse, it installed alarm systems and surveillance cameras with real-time alerts to
prevent any potential act of vandalism.
After a while, the information security team analyzed the audit logs to monitor and track activities across the
newly implemented security controls. Upon investigating and analyzing the audit logs, it was discovered that
an attacker had accessed the system due to out-of-date anti-malware software, exposing customers' sensitive
information, including names and home addresses. Following this, the IT team replaced the anti-malware
software with a new one capable of automatically removing malicious code in case of similar incidents. The
new software was installed on all workstations and regularly updated with the latest malware definitions, with
an automatic update feature enabled. An authentication process requiring user identification and a password
was also implemented to access sensitive information.
During the investigation, Maya, the information security manager of Beauty, found that information security
responsibilities in job descriptions were not clearly defined, for which the company took immediate action.
Recognizing that their e-commerce operations would have a global reach, Beauty diligently researched and
complied with the industry's legal, statutory, regulatory, and contractual requirements. It considered
international and local regulations, including data privacy laws, consumer protection acts, and global trade
agreements.
To meet these requirements, Beauty invested in legal counsel and compliance experts who continuously
monitored and ensured the company's compliance with legal standards in every market they operated in.
Additionally, Beauty conducted multiple information security awareness sessions for the IT team and other
employees with access to confidential information, emphasizing the importance of system and network
security.
Based on scenario 2, which information security requirement was NOT assessed by Beauty?
'The ISMS covers all departments within Company XYZ that have access to customers' data. The purpose of
the ISMS is to ensure the confidentiality, integrity, and availability of customers' data, and ensure compliancewith the applicable regulatory requirements regarding information security." What does this statement
^"describe?
© Copyrights FreeMockExams 2026. All Rights Reserved
We use cookies to ensure that we give you the best experience on our website (FreeMockExams). If you continue without changing your settings, we'll assume that you are happy to receive all cookies on the FreeMockExams.