CET Confidentiality & Data Security 3 — Questions and Answers
Question 1: A technician is asked to repair a device that may contain evidence in a criminal investigation. The technician should FIRST:
- Begin repair immediately to minimize downtime
- Consult with law enforcement or legal counsel before proceeding (Correct answer)
- Make a full backup of the device
- Replace the storage media to avoid contamination
Correct answer: Consult with law enforcement or legal counsel before proceeding
Devices involved in legal investigations must be handled according to legal protocols; proceeding without guidance could compromise evidence or expose the technician to liability.
Question 2: What does the principle of 'least privilege' mean in data security?
- Users should have the minimum access rights needed to perform their job (Correct answer)
- Only the least experienced technician handles sensitive data
- Passwords should be as short as possible
- Security measures should use the fewest system resources
Correct answer: Users should have the minimum access rights needed to perform their job
Least privilege limits each user's access rights to only what is necessary for their role, reducing the potential damage from breaches or errors.
Question 3: Which of the following is an example of social engineering in a cybersecurity context?
- Exploiting an unpatched software vulnerability
- Tricking an employee into revealing login credentials via a fake phone call (Correct answer)
- Using brute force to crack a password
- Intercepting data with a packet sniffer
Correct answer: Tricking an employee into revealing login credentials via a fake phone call
Social engineering manipulates people—rather than technology—into divulging confidential information, as in phishing calls or impersonation.
Question 4: A Non-Disclosure Agreement (NDA) in an electronics service context is primarily designed to:
- Protect the technician from warranty claims
- Prevent the technician from sharing confidential customer or company information (Correct answer)
- Allow the technician to retain customer data for marketing
- Authorize remote access to customer devices
Correct answer: Prevent the technician from sharing confidential customer or company information
An NDA legally obligates parties to keep specified information confidential, protecting both customer data and proprietary business information.
Question 5: Which type of malware encrypts a user's files and demands payment for the decryption key?
- Spyware
- Adware
- Ransomware (Correct answer)
- Rootkit
Correct answer: Ransomware
Ransomware encrypts victim files and extorts payment (often in cryptocurrency) in exchange for the decryption key.
Question 6: When a technician remotely accesses a customer's device for support, which practice is most important for data security?
- Using the customer's own login credentials for convenience
- Conducting the session over an encrypted, authenticated connection with customer consent (Correct answer)
- Disabling the firewall temporarily for faster access
- Saving the session recording to the technician's personal drive
Correct answer: Conducting the session over an encrypted, authenticated connection with customer consent
Remote support must be conducted over encrypted, authenticated connections with explicit customer consent to protect data and comply with privacy obligations.
Question 7: What is 'data at rest' in the context of electronics security?
- Data being transmitted over a network
- Data stored on a device or media not currently being transferred (Correct answer)
- Data that has been permanently deleted
- Temporary data held in RAM during processing
Correct answer: Data stored on a device or media not currently being transferred
Data at rest refers to inactive data stored physically on drives, SSDs, USB sticks, or other media, as opposed to data in transit or in use.
A technician is asked to repair a device that may contain evidence in a criminal investigation.
The technician should FIRST: