CMM Technology & Digital Government 5 — Questions and Answers
Question 1: Which type of attack involves flooding a city's public-facing website with traffic to make it inaccessible to residents?
- Phishing
- SQL injection
- Distributed Denial of Service (DDoS) (Correct answer)
- Man-in-the-middle attack
Correct answer: Distributed Denial of Service (DDoS)
A DDoS attack overwhelms a server with massive volumes of traffic from multiple sources, rendering the targeted website or service unavailable to legitimate users.
Question 2: A municipality wants to use predictive analytics to allocate code enforcement resources more efficiently. What type of data would be MOST useful as input?
- Employee vacation schedules
- Historical violation records, property age, and complaint density by location (Correct answer)
- Vendor invoices for inspection equipment
- City council meeting minutes
Correct answer: Historical violation records, property age, and complaint density by location
Historical violation data combined with property characteristics and complaint patterns enables predictive models to identify high-risk areas for proactive enforcement.
Question 3: Under the Government Records Access and Management Act (GRAMA) and similar state public records laws, how should local governments treat electronic records?
- Electronic records are exempt from public records requirements
- Electronic records are subject to the same retention and disclosure rules as paper records (Correct answer)
- Only printed copies of electronic records must be retained
- Electronic records may be deleted after 30 days without a retention schedule
Correct answer: Electronic records are subject to the same retention and disclosure rules as paper records
Public records laws treat electronic records equivalently to paper records, requiring the same retention schedules, disclosure rules, and preservation standards.
Question 4: Which strategy helps municipalities reduce the risk of vendor lock-in when procuring technology systems?
- Signing long-term exclusive contracts with a single vendor
- Requiring open standards, interoperability, and data portability in contracts (Correct answer)
- Avoiding cloud-based solutions entirely
- Allowing vendors to own all custom code developed for the city
Correct answer: Requiring open standards, interoperability, and data portability in contracts
Requiring open standards and data portability ensures the municipality can switch vendors or integrate other systems without being trapped by proprietary formats.
Question 5: A city is piloting an artificial intelligence chatbot for resident services. Which governance step is MOST important before public launch?
- Ensuring the chatbot has a friendly name and avatar
- Conducting a bias audit and establishing human escalation pathways (Correct answer)
- Training the AI exclusively on data from the wealthiest zip codes
- Eliminating all human customer service staff to reduce costs
Correct answer: Conducting a bias audit and establishing human escalation pathways
Before deploying AI in public-facing services, municipalities must audit for bias and ensure residents can escalate to a human agent when the AI fails or provides inaccurate information.
Question 6: Which federal law governs how local governments must handle the personally identifiable information (PII) of children under 13 collected through municipal websites?
- FERPA
- HIPAA
- COPPA (Correct answer)
- GDPR
Correct answer: COPPA
The Children's Online Privacy Protection Act (COPPA) requires verifiable parental consent before collecting PII from children under 13 on websites and online services.
Question 7: A municipality's IT governance committee is establishing a data classification policy. Which data category would typically receive the HIGHEST level of protection?
- Publicly available press releases
- Internal staff meeting agendas
- Sensitive personally identifiable information (SPII) such as Social Security numbers (Correct answer)
- Approved budget summaries
Correct answer: Sensitive personally identifiable information (SPII) such as Social Security numbers
Sensitive PII such as Social Security numbers, financial account data, and medical records require the strongest access controls, encryption, and handling procedures.
Which type of attack involves flooding a city's public-facing website with traffic to make it inaccessible to residents?