Data Security & Privacy Flashcards
7 cards from real APRP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Data Security & Privacy flashcards as text
Under the GDPR, what is the maximum timeframe within which a data controller must notify the supervisory authority of a personal data breach?
Answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
A payment processor stores cardholder data in a database. Under PCI DSS, which of the following elements is NEVER permitted to be stored after authorization?
Answer: Full magnetic stripe data
PCI DSS prohibits storage of sensitive authentication data including full magnetic stripe (track) data even if encrypted, after transaction authorization.
Which encryption mode is considered most appropriate for encrypting large volumes of payment data at rest because it allows parallel processing and does not propagate errors?
Answer: Counter Mode (CTR)
Counter (CTR) mode converts a block cipher into a stream cipher, supports parallel encryption/decryption, and errors do not propagate across blocks.
A merchant's point-of-sale terminal is compromised via a RAM-scraping malware attack. Which data is MOST at risk during this type of attack?
Answer: Cardholder data in clear text during transaction processing
RAM-scraping malware captures card data from system memory at the moment it is decrypted for processing, before it can be re-encrypted or tokenized.
Under the California Consumer Privacy Act (CCPA), which of the following rights does NOT apply to business-to-business (B2B) commercial data?
Answer: Right to know what personal information is collected
CCPA originally provided a B2B exemption, meaning information collected in a B2B context is not subject to the same consumer rights as B2C data, though exemptions have evolved.
A company uses a third-party payment processor. Under the principle of data minimization, what is the BEST approach to handling customer data shared with the processor?
Answer: Share only the data fields strictly necessary to complete the transaction
Data minimization requires sharing only the minimum necessary data to fulfill the specific processing purpose, reducing exposure in the event of a breach.
Which of the following BEST describes the purpose of a Data Processing Agreement (DPA) in a payment ecosystem?
Answer: It defines how a data processor must handle personal data on behalf of the controller
A DPA is a legally binding contract that specifies the data processor's obligations when processing personal data on behalf of the data controller, as required by GDPR Article 28.