← All CDT Flashcard Decks

Security & Privacy in Document Management Flashcards

7 cards from real CDT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Security & Privacy in Document Management flashcards as text
  1. Which document security control ensures that only authorized personnel can view sensitive records within an EDMS?

    Answer: Role-based access control (RBAC)

    Role-based access control restricts document viewing and editing privileges based on a user's assigned organizational role.

  2. Under HIPAA, a covered entity that experiences a breach affecting 500 or more individuals must notify the Secretary of HHS within how many days?

    Answer: 60 days

    HIPAA's Breach Notification Rule requires covered entities to notify HHS within 60 days of discovering a breach affecting 500 or more individuals.

  3. What is the primary purpose of applying a digital watermark to a controlled document?

    Answer: Detect unauthorized copies and trace document origin

    Digital watermarks embed identifying information into documents to deter unauthorized copying and help trace the source of leaks.

  4. A document management policy requires 'least privilege' access. What does this mean?

    Answer: Users receive only the minimum access required for their current duties

    Least privilege limits each user to only the permissions necessary for their specific job responsibilities, reducing insider threat risk.

  5. Which encryption standard is currently recommended by NIST for protecting sensitive government documents at rest?

    Answer: AES-256

    NIST recommends AES-256 as the gold standard for encrypting data at rest due to its computational strength against modern attacks.

  6. What does a document classification scheme (e.g., Public, Internal, Confidential, Restricted) primarily help an organization accomplish?

    Answer: Apply appropriate security controls based on information sensitivity

    Classification schemes allow organizations to match security measures to the risk level of each document category.

  7. An organization wants to prevent documents from being emailed outside the company. Which technology best enforces this policy?

    Answer: Data Loss Prevention (DLP)

    Data Loss Prevention tools inspect outbound communications and block or alert when sensitive content is detected leaving the organization.