Information Security & Privacy Flashcards
7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security & Privacy flashcards as text
Which principle of information security ensures that data is not disclosed to unauthorized individuals?
Answer: Confidentiality
Confidentiality is the CIA triad principle that restricts information access to authorized parties only.
A records manager discovers that an employee copied sensitive client records to a personal USB drive. This is BEST classified as a:
Answer: Data breach through insider threat
Unauthorized copying of sensitive records by an employee constitutes an insider threat data breach.
Under HIPAA, which of the following is considered Protected Health Information (PHI)?
Answer: A patient's name combined with their diagnosis
PHI includes any individually identifiable health information, such as a patient's name linked to their medical condition.
What is the primary purpose of a data classification policy in records management?
Answer: To categorize information by sensitivity and apply appropriate controls
Data classification policies categorize records by sensitivity level so that appropriate security controls can be applied to each category.
Which encryption standard is currently recommended by NIST for protecting sensitive federal records at rest?
Answer: AES-256 (Advanced Encryption Standard)
NIST recommends AES-256 as the current standard for strong encryption of sensitive data at rest.
A 'privacy impact assessment' (PIA) is conducted to:
Answer: Identify privacy risks before implementing a new system or process involving personal data
A PIA is a proactive analysis performed before deploying new systems or processes to identify and mitigate privacy risks.
Which of the following BEST describes the concept of 'least privilege' in records security?
Answer: Users receive access only to the information they need to perform their job functions
Least privilege limits user access rights to only what is necessary for their specific role, minimizing unauthorized exposure.