CDT Security & Privacy in Document Management 2 — Questions and Answers
Question 1: Which document security control ensures that only authorized personnel can view sensitive records within an EDMS?
- Full-text indexing
- Role-based access control (RBAC) (Correct answer)
- Optical character recognition
- Batch scanning
Correct answer: Role-based access control (RBAC)
Role-based access control restricts document viewing and editing privileges based on a user's assigned organizational role.
Question 2: Under HIPAA, a covered entity that experiences a breach affecting 500 or more individuals must notify the Secretary of HHS within how many days?
- 30 days
- 45 days
- 60 days (Correct answer)
- 90 days
Correct answer: 60 days
HIPAA's Breach Notification Rule requires covered entities to notify HHS within 60 days of discovering a breach affecting 500 or more individuals.
Question 3: What is the primary purpose of applying a digital watermark to a controlled document?
- Improve print quality
- Detect unauthorized copies and trace document origin (Correct answer)
- Reduce file size
- Enable full-text search
Correct answer: Detect unauthorized copies and trace document origin
Digital watermarks embed identifying information into documents to deter unauthorized copying and help trace the source of leaks.
Question 4: A document management policy requires 'least privilege' access. What does this mean?
- Users receive the maximum access needed for any future role
- Users receive only the minimum access required for their current duties (Correct answer)
- Administrators alone can access all documents
- Documents are public by default unless flagged
Correct answer: Users receive only the minimum access required for their current duties
Least privilege limits each user to only the permissions necessary for their specific job responsibilities, reducing insider threat risk.
Question 5: Which encryption standard is currently recommended by NIST for protecting sensitive government documents at rest?
- DES (56-bit)
- 3DES (112-bit)
- AES-256 (Correct answer)
- RC4
Correct answer: AES-256
NIST recommends AES-256 as the gold standard for encrypting data at rest due to its computational strength against modern attacks.
Question 6: What does a document classification scheme (e.g., Public, Internal, Confidential, Restricted) primarily help an organization accomplish?
- Automate document printing
- Apply appropriate security controls based on information sensitivity (Correct answer)
- Reduce storage costs
- Speed up retrieval times
Correct answer: Apply appropriate security controls based on information sensitivity
Classification schemes allow organizations to match security measures to the risk level of each document category.
Question 7: An organization wants to prevent documents from being emailed outside the company. Which technology best enforces this policy?
- Anti-virus software
- Data Loss Prevention (DLP) (Correct answer)
- Firewall rules only
- Digital signatures
Correct answer: Data Loss Prevention (DLP)
Data Loss Prevention tools inspect outbound communications and block or alert when sensitive content is detected leaving the organization.
Which document security control ensures that only authorized personnel can view sensitive records within an EDMS?