← All CDT Flashcard Decks

Security & Access Management Flashcards

7 cards from real CDT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Access Management flashcards as text
  1. Which document security feature uses invisible patterns that appear when photocopied to deter counterfeiting?

    Answer: Void pantograph

    Void pantographs are hidden patterns embedded in document backgrounds that reveal the word 'VOID' when photocopied, making counterfeiting detectable.

  2. In document management, 'need-to-know' access control means:

    Answer: Access is granted only when operationally required for a specific role

    Need-to-know access restricts document access to individuals whose job functions require that specific information, minimizing unnecessary exposure.

  3. What is the primary purpose of a document retention schedule in a security context?

    Answer: To ensure documents are kept only as long as legally and operationally required

    Retention schedules define how long documents must be kept and when they should be securely destroyed, reducing the risk of unauthorized access to outdated sensitive records.

  4. Which term describes the process of verifying that a document has not been altered since it was created or last authorized?

    Answer: Integrity verification

    Integrity verification confirms that document content remains unchanged, often using checksums, digital signatures, or hash values.

  5. A 'clean desk policy' primarily supports document security by:

    Answer: Preventing unauthorized viewing of sensitive documents left unattended

    Clean desk policies require employees to secure or remove sensitive documents when not in use, reducing the risk of unauthorized access or shoulder surfing.

  6. When a document management system enforces 'separation of duties,' it means:

    Answer: No single user can complete a sensitive transaction without involvement of another

    Separation of duties requires that critical document actions (e.g., creation and approval) be performed by different individuals to prevent fraud or error.

  7. Which access control model assigns permissions based on predefined organizational rules rather than individual identity?

    Answer: Role-Based Access Control (RBAC)

    RBAC grants document access based on a user's role within the organization, making administration scalable and consistent across large teams.