CIPA Data Security & Privacy Compliance 2 — Questions and Answers
Question 1: Under HIPAA's Security Rule, which of the following is classified as an 'administrative safeguard'?
- Encryption of data at rest
- Workforce training and security awareness programs (Correct answer)
- Physical access controls to server rooms
- Automatic logoff from workstations
Correct answer: Workforce training and security awareness programs
HIPAA's Security Rule categorizes workforce training and security awareness programs as administrative safeguards, distinct from physical or technical safeguards.
Question 2: A company collects consumer data in California. Under CCPA, what right allows consumers to prevent a business from selling their personal information?
- Right to erasure
- Right to opt-out (Correct answer)
- Right to portability
- Right to correction
Correct answer: Right to opt-out
The CCPA grants California consumers the right to opt-out of the sale of their personal information to third parties.
Question 3: Which data classification level typically requires the strictest access controls and encryption standards?
- Public
- Internal
- Confidential
- Top Secret / Restricted (Correct answer)
Correct answer: Top Secret / Restricted
Top Secret or Restricted data requires the strictest controls because unauthorized disclosure could cause severe harm to the organization or individuals.
Question 4: A penetration tester discovers that an organization stores Social Security Numbers in plaintext in a database. Which control would most directly remediate this risk?
- Implementing a firewall rule to block external access
- Applying data-at-rest encryption to the database (Correct answer)
- Enabling multi-factor authentication for database admins
- Conducting quarterly vulnerability scans
Correct answer: Applying data-at-rest encryption to the database
Encrypting data at rest ensures that SSNs are unreadable even if an attacker gains direct access to the database files.
Question 5: Under GDPR, the 'right to be forgotten' is formally known as which right?
- Right to restriction of processing
- Right to data portability
- Right to erasure (Correct answer)
- Right to object
Correct answer: Right to erasure
GDPR Article 17 codifies the 'right to be forgotten' as the right to erasure, allowing individuals to request deletion of their personal data.
Question 6: Which federal law mandates that financial institutions implement safeguards to protect customer financial information and deliver privacy notices?
- FCRA
- FERPA
- GLBA (Correct answer)
- COPPA
Correct answer: GLBA
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their data-sharing practices and protect sensitive customer data.
Question 7: An organization must destroy paper records containing PII. Which method best meets NIST SP 800-88 media sanitization guidelines for paper?
- Recycling bins in secure areas
- Cross-cut shredding to DIN 66399 P-4 or higher (Correct answer)
- Tearing documents in half before disposal
- Storing in a locked archive indefinitely
Correct answer: Cross-cut shredding to DIN 66399 P-4 or higher
NIST SP 800-88 recommends cross-cut shredding at a sufficient security level (such as DIN P-4 or higher) to ensure paper records cannot be reconstructed.
Under HIPAA's Security Rule, which of the following is classified as an 'administrative safeguard'?