Security & Privacy in Document Management Flashcards
7 cards from real CDT practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Security & Privacy in Document Management flashcards as text
Which security concept ensures that a document cannot be altered without detection after it has been finalized?
Answer: Integrity
Integrity controls, such as hash values and digital signatures, ensure any unauthorized modification to a document is detectable.
A company wants to allow remote employees to securely access the document management system. What is the most appropriate solution?
Answer: Provide VPN access with multi-factor authentication
A VPN combined with MFA encrypts the connection and requires multiple verification factors, preventing unauthorized remote access to sensitive documents.
Under the California Consumer Privacy Act (CCPA), consumers have the right to request that a business do which of the following regarding their personal information?
Answer: Delete it upon request
CCPA grants California consumers the right to request deletion of their personal information held by covered businesses, subject to certain exceptions.
What is 'document sanitization' in the context of information security?
Answer: Removing hidden metadata and sensitive embedded content before releasing a document
Sanitization strips documents of hidden metadata, tracked changes, comments, and embedded data that could inadvertently reveal sensitive information to recipients.
When must an organization conducting business under PCI DSS restrict access to cardholder data documents?
Answer: On a need-to-know basis at all times
PCI DSS Requirement 7 mandates that access to cardholder data be restricted to only those individuals whose job requires it, on a continuous need-to-know basis.
A ransomware attack encrypts all documents on the company's network shares. Which preparedness measure would most quickly restore operations?
Answer: Tested offline or air-gapped backups
Offline or air-gapped backups that are regularly tested allow organizations to restore encrypted or deleted documents without paying a ransom.
Which document destruction method is recommended by NIST SP 800-88 for media containing highly sensitive (Secret-level) information?
Answer: Physical destruction (disintegration, incineration, or degaussing)
NIST SP 800-88 recommends physical destruction methods such as disintegration, incineration, or degaussing for the highest sensitivity levels to ensure data is irrecoverable.