Security & Privacy in Document Management Flashcards
7 cards from real CDT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Privacy in Document Management flashcards as text
What is the purpose of a document management system's 'audit log'?
Answer: Record all user actions such as views, edits, and deletions for accountability
Audit logs provide a tamper-evident record of all actions taken on documents, supporting investigations, compliance audits, and forensic analysis.
Which type of attack involves an unauthorized party intercepting document transmissions between two parties without their knowledge?
Answer: Man-in-the-middle (MITM) attack
A man-in-the-middle attack intercepts communications in transit, potentially allowing an attacker to read or alter documents before they reach the intended recipient.
FERPA protects the educational records of students. Which of the following is NOT considered a protected educational record under FERPA?
Answer: Directory information if the institution has issued a FERPA opt-out notice
Institutions may disclose directory information (name, address, enrollment status) unless a student has filed a FERPA opt-out, removing it from FERPA's default protection.
An organization implements 'two-person integrity' for accessing highly classified document vaults. What does this control require?
Answer: Two authorized individuals must be present simultaneously to access the vault
Two-person integrity requires at least two authorized individuals to be present for access to sensitive areas or materials, preventing unilateral insider actions.
Which document security practice involves removing or obscuring personally identifiable information (PII) before sharing a document externally?
Answer: Redaction
Redaction permanently removes or blacks out sensitive PII or privileged information so documents can be shared without exposing protected data.
What is a 'privacy impact assessment' (PIA) used for in document management?
Answer: Evaluating risks to individual privacy before implementing a new document system or process
A PIA systematically identifies privacy risks associated with a new system or process and recommends mitigations before deployment.
Which physical security control best protects paper documents containing PII stored in an office environment?
Answer: Locked filing cabinets with key or combination access restricted to authorized staff
Locked cabinets with controlled key or combination access ensure only authorized personnel can retrieve physical documents containing sensitive information.