Skip to content

ISFS Practice Questions

Prepare for ISFS with more than an answer.

315 questions in the full set20 sample questionsUpdated Sep 16, 2021
Exam fee
$175 USD
Level
Foundation
Valid for
Lifetime certification
Domains covered on the exam 4
  1. Information and Security27.5%
  2. Threats and Risks12.5%
  3. Security Controls52.5%
  4. Legislation, Regulations, and Standards7.5%
  1. 1

    You work in the IT department of a medium-sized company. Confidential information has got into the wrong hands several times. This has hurt the image of the company. You have been asked to propose organizational security measures for laptops at your company. What is the first step that you should take?

    Show answer details

    Correct answer: A

    A

  2. 2

    Your company has to ensure that it meets the requirements set down in personal data protection legislation. What is the first thing you should do?

    Show answer details

    Correct answer: B

    B

  3. 3

    In most organizations, access to the computer or the network is granted only after the user has entered a correct username and password. This process consists of 3 steps: identification, authentication and authorization. What is the purpose of the second step, authentication?

    Show answer details

    Correct answer: C

    C

  4. 4

    You work for a large organization. You notice that you have access to confidential information that you should not be able to access in your position. You report this security incident to the helpdesk. The incident cycle isinitiated. What are the stages of the security incident cycle?

    Show answer details

    Correct answer: C

    C

  5. 5

    Midwest Insurance grades the monthly report of all claimed losses per insured as confidential.
    What is accomplished if all other reports from this insurance office are also assigned the appropriate grading?

    Show answer details

    Correct answer: C

    C

  6. 6

    What is an example of a physical security measure?

    Show answer details

    Correct answer: D

    D

  7. 7

    A data center uses a 'protection rings' model for physical security. An engineer needs to access a specific server rack located in the most secure zone. What is the typical sequence of security layers the engineer must pass through?

    graph TD subgraph Outer Ring [Perimeter] A[Fence & Gate] end subgraph Middle Ring [Building] B[Reception & Access Card Entry] end subgraph Inner Ring [Data Center Floor] C[Biometric Scan & Mantrap] end subgraph Core [Secure Zone] D[Cage Lock & Server Rack Lock] end A --> B --> C --> D
    Show answer details

    Correct answer: B

    The protection rings model, also known as defense-in-depth, requires passing through sequential layers of security, from the least secure (perimeter) to the most secure (core). The correct sequence is to first pass the outer perimeter (fence), then the building entrance, then the data center floor access (biometric scan), and finally the specific secure zone (cage and rack lock).

  8. 8

    Which is a legislative or regulatory act related to information security that can be imposed upon all organizations?

    Show answer details

    Correct answer: D

    D

  9. 9

    What is the best description of a risk analysis?

    Show answer details

    Correct answer: B

    B

  10. 10

    What is the greatest risk for an organization if no information security policy has been defined?

    Show answer details

    Correct answer: D

    D

Create an account to continue.