โ† All BBC Flashcard Decks

Safety and Compliance Flashcards

7 cards from real BBC practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Safety and Compliance flashcards as text
  1. Under the California Public Records Act (CPRA), which type of document is generally exempt from public disclosure?

    Answer: Personnel records containing private employee information

    Personnel records are among the specific exemptions in the CPRA because they contain private employee information protected by statute.

  2. An employee accidentally sends an email containing confidential client data to the wrong recipient. The correct immediate action is to:

    Answer: Notify a supervisor and the IT/security team immediately

    Accidental data disclosure is a security incident requiring immediate notification to supervisors and IT so breach-response procedures can begin.

  3. What does the term 'need-to-know' mean in the context of information access controls?

    Answer: Access to sensitive information should be limited to those whose job duties require it

    The need-to-know principle restricts access to sensitive information to only those employees whose specific job duties require it.

  4. When completing a required compliance training, an employee discovers a policy that directly conflicts with how their office currently operates. They should:

    Answer: Report the discrepancy to their supervisor so it can be resolved

    Discrepancies between policy and practice must be escalated to management so they can be investigated and corrected at the appropriate level.

  5. In an office emergency evacuation, what is the role of the designated floor warden?

    Answer: To guide employees to exits, account for all personnel, and relay information to emergency responders

    Floor wardens guide evacuations, take headcounts, and communicate with emergency services to ensure everyone's safety.

  6. Which of the following is an example of a 'social engineering' attack that clerical staff should be trained to recognize?

    Answer: A caller impersonating IT support to obtain an employee's login credentials

    Social engineering exploits human trust; impersonating IT support to extract credentials is a classic example clerical staff must recognize.

  7. Under LA County's drug-free workplace policy, an employee who is prescribed a medication that may impair their ability to perform job duties safely should:

    Answer: Notify their supervisor or HR so appropriate accommodations or restrictions can be applied

    Disclosing impairing medications allows the employer to implement safety measures while protecting both the employee and others.