CET Confidentiality & Data Security 2 — Questions and Answers
Question 1: Which encryption standard is most commonly recommended for securing sensitive data stored on electronic devices in the US?
- DES (56-bit)
- AES-256 (Correct answer)
- RC4
- MD5
Correct answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the current US government-approved standard for protecting sensitive data at rest.
Question 2: A technician discovers a hard drive containing customer records while repairing a computer. The best course of action is to:
- Copy the data for reference during repair
- Access the data only if needed for diagnostics
- Avoid accessing personal data and inform the customer (Correct answer)
- Delete the data to protect privacy
Correct answer: Avoid accessing personal data and inform the customer
Technicians must avoid accessing personal customer data and should inform the customer of its presence to maintain confidentiality.
Question 3: What is the primary purpose of a chain of custody document in electronics repair or forensics?
- To track shipping costs
- To document who handled evidence or devices and when (Correct answer)
- To list the parts replaced during repair
- To record customer payment history
Correct answer: To document who handled evidence or devices and when
A chain of custody document records every person who handled a device or piece of evidence to maintain integrity and accountability.
Question 4: Which of the following is considered a 'data breach' under most US privacy regulations?
- A technician backing up customer data before repair
- Unauthorized access to personally identifiable information (PII) (Correct answer)
- Encrypting customer data for secure storage
- Asking a customer to verify their identity before service
Correct answer: Unauthorized access to personally identifiable information (PII)
A data breach occurs when unauthorized parties gain access to personally identifiable information, triggering legal notification requirements.
Question 5: When disposing of a customer's old hard drive, which method ensures data is unrecoverable?
- Deleting all files and emptying the Recycle Bin
- Performing a quick format
- Physical destruction or DoD-standard overwriting (7-pass wipe) (Correct answer)
- Removing the drive from the computer
Correct answer: Physical destruction or DoD-standard overwriting (7-pass wipe)
Physical destruction or multi-pass overwriting per DoD 5220.22-M standard renders data unrecoverable, unlike simple deletion or formatting.
Question 6: Two-factor authentication (2FA) improves security because it requires:
- Two different passwords
- Something you know and something you have or are (Correct answer)
- Two technicians to approve access
- A password changed every two days
Correct answer: Something you know and something you have or are
2FA combines two different authentication factors—typically a password (something you know) with a token or biometric (something you have or are).
Question 7: Which regulation specifically governs the privacy of health-related electronic data in the United States?
- FERPA
- HIPAA (Correct answer)
- GDPR
- COPPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) sets the standard for protecting sensitive patient health information in the US.
Which encryption standard is most commonly recommended for securing sensitive data stored on electronic devices in the US?