Summer Special 60% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: bestdeal

Free PECB ISO-IEC-27035-Lead-Incident-Manager Practice Exam with Questions & Answers

Questions 1

What does the Incident Cause Analysis Method (ICAM) promote?

Options:
A.

A disciplined approach to incident analysis by emphasizing five key areas: people, environment, equipment, procedures, and the organization

B.

An emphasis on evaluating and reporting the financial impact of incidents on the organization

C.

The analysis of incidents through the creation of a detailed timeline of events leading up to the incident

PECB ISO-IEC-27035-Lead-Incident-Manager Premium Access
Questions 2

During the 'detect and report' phase of incident management at TechFlow, the incident response team began collecting detailed threat intelligence and conducting vulnerability assessments related to these login attempts. Additionally, the incident response team classified a series of unusual login attempts as a potential security incident and distributed initial reports to the incident coordinator. Is this approach correct?

Options:
A.

Yes, because classifying events as information security incidents is essential during this phase

B.

No, because collecting detailed information about threats and vulnerabilities should occur in later phases

C.

No, because information security incidents cannot yet be classified as information security incidents in this phase

Questions 3

Who is responsible for providing threat intelligence and supporting the lead investigator within an incident response team?

Options:
A.

IT support staff

B.

Analysts and researchers

C.

Team leader

Questions 4

Which factor of change should be monitored when maintaining incident management documentation?

Options:
A.

Market trends

B.

Employee attendance records

C.

Test results

Questions 5

Which of the following statements regarding the principles for digital evidence gathering is correct?

Options:
A.

Sufficiency means that only a minimal amount of material should be gathered to avoid unnecessary auditing and justification efforts

B.

Reliability implies that all processes used in handling digital evidence should be unique and not necessarily reproducible

C.

Relevance means that the DEFR should be able to describe the procedures followed and justify the decision to acquire each item based on its value to the investigation

Questions 6

Who should have access to training materials on information security incident management?

Options:
A.

Only personnel involved in technical roles

B.

Only internal interested parties

C.

All personnel, including new employees, third-party users, and contractors

Questions 7

Scenario 2: NoSpace, a forward-thinking e-commerce store based in London, is renowned for its diverse products and advanced technology. To enhance its information security, NoSpace implemented an ISMS according to ISO/IEC 27001 to better protect customer data and ensure business continuity. Additionally, the company adopted ISO/IEC 27035-1 and ISO/IEC 27035-2 guidelines. Mark, the incident manager at NoSpace, strategically led the entire implementation. He played a crucial role in aligning the company's ISMS with the requirements specified in ISO/IEC 27001, using ISO/IEC 27035-1 guidelines as the foundation.

During a routine internal audit a minor anomaly was detected in the data traffic that could potentially indicate a security threat. Mark was immediately notified to assess the situation. Then, Mark and his team immediately escalated the incident to crisis management to handle the potential threat without further assessment. The decision was made to ensure a swift response.

After resolving the situation, Mark decided to update the incident management process. During the initial phase of incident management, Mark recognized the necessity of updating NoSpace's information security policies. This included revising policies related to risk management at the organizational level as well as for specific systems, services, or networks. The second phase of the updated incident management process included the assessment of the information associated with occurrences of information security events and the importance of classifying events and vulnerabilities as information security incidents. During this phase, he also introduced a 'count down' process to expedite the evaluation and classification of occurrences, determining whether they should be recognized as information security incidents.

Mark developed a new incident management policy to enhance the organization's resilience and adaptability in handling information security incidents. Starting with a strategic review session with key stakeholders, the team prioritized critical focus areas over less impactful threats, choosing not to include all potential threats in the policy document. This decision was made to keep the policy streamlined and actionable, focusing on the most significant risks identified through a risk assessment. The policy was shaped by integrating feedback from various department heads to ensure it was realistic and enforceable. Training and awareness initiatives were tailored to focus only on critical response roles, optimizing resource allocation and focusing on essential capabilities.

Based on scenario 2, NoSpace used the ISO/IEC 27035-1 guidelines to meet the ISMS requirements specified in ISO/IEC 27001. Is this acceptable?

Options:
A.

Yes, another objective associated with ISO/IEC 27035-1 is to provide guidance on meeting the ISMS requirements specified in ISO/IEC 27001

B.

No, guidelines provided in ISO/IEC 27035-1 do not apply to ISMS requirements specified in ISO/IEC 27001

C.

No, ISO/IEC 27035-1 is designed for incident management and response and does not address the broader scope of ISMS requirements specified in ISO/IEC 27001

Questions 8

Who is responsible for approving an organization’s information security incident management policy?

Options:
A.

Top management

B.

Incident manager

C.

Incident coordinator

Questions 9

Scenario 6: EastCyber has established itself as a premier cyber security company that offers threat detection, vulnerability assessment, and penetration testing tailored to protect organizations from emerging cyber threats. The company effectively utilizes ISO/IEC 27035*1 and 27035-2 standards, enhancing its capability to manage information security incidents.

EastCyber appointed an information security management team led by Mike Despite limited resources, Mike and the team implemented advanced monitoring protocols to ensure that every device within the company’s purview is under constant surveillance This monitoring approach is crucial for covering everything thoroughly, enabling the information security and cyber management team to proactively detect and respond to any sign of unauthorized access, modifications, or malicious activity within its systems and networks.

In addition, they focused on establishing an advanced network traffic monitoring system This system carefully monitors network activity, quickly spotting and alerting the security team to unauthorized actions This vigilance is pivotal in maintaining the integrity of EastCyber’s digital infrastructure and ensuring the confidentiality, availability, and integrity of the data it protects.

Furthermore, the team focused on documentation management. They meticulously crafted a procedure to ensure thorough documentation of information security events. Based on this procedure, the company would document only the events that escalate into high-severity incidents and the subsequent actions. This documentation strategy streamlines the incident management process, enabling the team to allocate resources more effectively and focus on incidents that pose the greatest threat.

A recent incident involving unauthorized access to company phones highlighted the critical nature of incident management. Nate, the incident coordinator, quickly prepared an exhaustive incident report. His report detailed an analysis of the situation, identifying the problem and its cause. However, it became evident that assessing the seriousness and the urgency of a response was inadvertently overlooked.

In response to the incident, EastCyber addressed the exploited vulnerabilities. This action started the eradication phase, aimed at systematically eliminating the elements of the incident. This approach addresses the immediate concerns and strengthens EastCyber’s defenses against similar threats in the future.

According to scenario 6, what mechanisms for detecting security incidents did EastCyber implement?

Options:
A.

Security information and event management systems

B.

Intrusion detection systems

C.

Intrusion prevention systems

Questions 10

What roles do business managers play in relation to the Incident Management Team (IMT) and Incident Response Teams (IRTs)?

Options:
A.

Developing policies and procedures for managing internal employees found engaging in unauthorized or illegal computer activities

B.

Guiding on liability and compliance issues to the IMT and IRT and advise on which incidents constitute mandatory data breach notifications

C.

Understanding how the IMT and IRTs support business processes and define authority over business systems

Certification Provider: PECB
Exam Name: PECB Certified ISO/IEC 27035 Lead Incident Manager
Last Update: Sep 12, 2025
Questions: 80