Security & Access Management Flashcards
7 cards from real CDT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Access Management flashcards as text
Which technology embeds invisible identifying information into a printed document to trace its source if leaked?
Answer: Document steganography or printer tracking dots
Printer tracking dots (yellow dots) and steganographic techniques embed covert identifiers in printed output, allowing investigators to trace the printer and print time.
In a role-based access control system, when an organization restructures and creates new job roles, the administrator should:
Answer: Define new roles with permissions aligned to the principle of least privilege
New roles should be built from a baseline of minimum required permissions to avoid introducing excessive access rights during organizational changes.
What is 'document tokenization' in the context of sensitive data protection?
Answer: Replacing sensitive data values with non-sensitive placeholders while preserving document usability
Tokenization substitutes sensitive fields (e.g., Social Security Numbers) with random tokens, allowing documents to be processed without exposing the original data.
Which scenario best illustrates an 'insider threat' risk in document security?
Answer: An authorized employee copying confidential documents for unauthorized personal use
Insider threats involve individuals with legitimate access misusing their privileges, making them harder to detect than external attacks.
What is the difference between document authentication and document authorization?
Answer: Authentication verifies identity; authorization determines what that identity is allowed to do
Authentication establishes who the user is, while authorization defines what documents or actions that verified user is permitted to access.
A secure document portal requires multi-factor authentication (MFA) because:
Answer: A compromised password alone is insufficient to grant access, adding a second verification layer
MFA requires a second factor (e.g., OTP, biometric) in addition to a password, ensuring that stolen credentials alone cannot grant unauthorized document access.
Which standard specifically addresses information security management, including document control and access management practices?
Answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems and includes requirements for document control, access management, and risk treatment.