Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 2 Question 23 Discussion

How is the purpose of information security policy best described?
B) An information security policy provides direction and support to the management regarding information security.
A) An information security policy documents the analysis of risks and the search for countermeasures.
C) An information security policy makes the security plan concrete by providing it with the necessary details.
D) An information security policy provides insight into threats and the possible consequences.

PECB ISO-IEC-27001-Lead-Auditor Exam - Topic 2 Question 23 Discussion

Actual exam question for PECB's ISO-IEC-27001-Lead-Auditor exam
Question #: 23
Topic #: 2
[All ISO-IEC-27001-Lead-Auditor Questions]

How is the purpose of information security policy best described?

Show Suggested Answer Hide Answer
Suggested Answer: B

Contribute your Thoughts:

0/2000 characters
Art
8 months ago
Wait, I thought it was just about compliance, not all this detail!
upvoted 0 times
...
Nickolas
8 months ago
D sounds good, but is it really the main focus?
upvoted 0 times
...
Eliz
9 months ago
C really nails it; it gives the plan structure.
upvoted 0 times
...
Catarina
9 months ago
A is more about risk analysis, not the overall purpose.
upvoted 0 times
...
Tish
9 months ago
I think option B is spot on!
upvoted 0 times
...
Kristofer
9 months ago
I recall that information security policies should also give insight into threats, so option D might be relevant too, but I'm not confident about that one.
upvoted 0 times
...
India
9 months ago
I feel like I've seen a question similar to this before, and I think the focus was on making the security plan concrete, which would be option C.
upvoted 0 times
...
Lorrie
9 months ago
I'm not entirely sure, but I remember something about how these policies also document risks and countermeasures, which sounds like option A.
upvoted 0 times
...
Angella
9 months ago
I think the purpose of an information security policy is mainly to provide direction and support to management, so I might lean towards option B.
upvoted 0 times
...
Laticia
9 months ago
Hmm, I'm not totally sure about this one. I know non-relational databases are different from SQL databases, but I can't quite remember the specific characteristics. I'll have to think this through carefully.
upvoted 0 times
...
Paris
9 months ago
Transactions are a key part of JMS, so I should be able to handle this. I'll review the code and the options to determine the correct approach to transaction management.
upvoted 0 times
...
Gilma
10 months ago
The GCP Console option seems the most user-friendly, but I wonder if it provides the same level of automation and scripting capabilities as the API and CLI. I'll need to weigh the tradeoffs.
upvoted 0 times
...
Pearlie
10 months ago
Hmm, I'm not totally sure about this one. I'll have to think it through carefully before selecting an answer.
upvoted 0 times
...

Save Cancel