CDT Security & Access Management 3 — Questions and Answers
Question 1: What is the function of digital rights management (DRM) in document security?
- Encrypts documents stored on physical media only
- Controls how documents can be used, copied, or distributed after delivery (Correct answer)
- Generates unique document serial numbers for tracking
- Scans documents for malware before printing
Correct answer: Controls how documents can be used, copied, or distributed after delivery
DRM enforces usage policies on digital documents, preventing unauthorized copying, printing, forwarding, or editing even after the document reaches the recipient.
Question 2: In the context of document security, 'data at rest' refers to:
- Documents currently being viewed on screen
- Stored documents not actively being transmitted or processed (Correct answer)
- Documents queued for printing
- Files in transit over a network
Correct answer: Stored documents not actively being transmitted or processed
Data at rest includes documents stored on servers, hard drives, or archives, which require encryption and access controls to prevent unauthorized access.
Question 3: Which secure document destruction method is most appropriate for classified paper records?
- Recycling bin disposal
- Cross-cut shredding to DIN 66399 P-4 or higher (Correct answer)
- Burning in an open container
- Tearing and discarding in standard waste
Correct answer: Cross-cut shredding to DIN 66399 P-4 or higher
Cross-cut shredding at security level P-4 or higher reduces documents to small particles, making reconstruction virtually impossible for classified material.
Question 4: What does 'chain of custody' mean for sensitive documents?
- A document's alphabetical filing order
- A chronological record documenting who handled a document and when (Correct answer)
- The approval hierarchy required before a document is published
- The sequence of edits made to a document
Correct answer: A chronological record documenting who handled a document and when
Chain of custody documents every transfer of possession of a sensitive document, ensuring accountability and supporting legal or audit requirements.
Question 5: A 'two-person integrity' rule in document handling requires:
- Two copies of every sensitive document to be maintained
- Two authorized individuals to be present when accessing or handling certain documents (Correct answer)
- Two-factor authentication before any document is printed
- Dual encryption keys for all archived files
Correct answer: Two authorized individuals to be present when accessing or handling certain documents
Two-person integrity prevents a single individual from unilaterally accessing or manipulating highly sensitive documents, reducing insider threat risk.
Question 6: Which document marking practice helps ensure that sensitive content is handled appropriately throughout its lifecycle?
- Watermarking every page with the author's name
- Applying classification labels such as CONFIDENTIAL or RESTRICTED (Correct answer)
- Numbering each document sequentially
- Adding a date stamp to the document footer
Correct answer: Applying classification labels such as CONFIDENTIAL or RESTRICTED
Classification labels communicate the sensitivity level of a document to all handlers, guiding appropriate storage, transmission, and destruction procedures.
Question 7: What is a primary risk of using unencrypted email to transmit sensitive documents?
- The email may be delayed in delivery
- Unauthorized parties can intercept and read the document in transit (Correct answer)
- The document formatting may be lost
- The file attachment size may exceed server limits
Correct answer: Unauthorized parties can intercept and read the document in transit
Unencrypted email transmits data in plaintext, making it vulnerable to interception through man-in-the-middle attacks or unauthorized server access.
What is the function of digital rights management (DRM) in document security?