โ† All CRM Flashcard Decks

Information Security & Privacy Flashcards

7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Information Security & Privacy flashcards as text
  1. Under the GDPR, a data subject's 'right to erasure' is also known as the:

    Answer: Right to be forgotten

    The GDPR's right to erasure (Article 17) is commonly called the 'right to be forgotten,' allowing individuals to request deletion of their personal data.

  2. Which records management practice BEST supports compliance with breach notification laws?

    Answer: Maintaining an accurate inventory of where personal data is stored

    Knowing where personal data resides enables organizations to quickly identify affected records and comply with breach notification timelines.

  3. An organization uses 'tokenization' for protecting credit card numbers in records. What does tokenization do?

    Answer: Replaces sensitive data with a non-sensitive surrogate value

    Tokenization substitutes sensitive data with a placeholder token, so the original value is never stored in operational systems.

  4. Which federal law primarily governs privacy of student education records in the United States?

    Answer: FERPA

    FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records at institutions receiving federal funding.

  5. A records manager is developing a security policy for email records containing PII. The FIRST step should be to:

    Answer: Identify and classify the PII contained in email records

    Before applying controls, the manager must identify and classify what PII exists in email records to determine the appropriate protection level.

  6. Which security control is specifically designed to detect unauthorized changes to records?

    Answer: Audit trails and hash verification

    Audit trails log all access and modifications, while cryptographic hashing can detect if a record's content has been altered.

  7. When records are transferred to a third-party vendor for storage or processing, which document BEST protects the organization's privacy obligations?

    Answer: A data processing agreement (DPA) specifying security and privacy requirements

    A DPA contractually obligates third-party vendors to uphold the organization's data protection standards when handling personal information.