CRM Information Security & Privacy 2 — Questions and Answers
Question 1: Which principle of information security ensures that data is not disclosed to unauthorized individuals?
- Integrity
- Confidentiality (Correct answer)
- Availability
- Authenticity
Correct answer: Confidentiality
Confidentiality is the CIA triad principle that restricts information access to authorized parties only.
Question 2: A records manager discovers that an employee copied sensitive client records to a personal USB drive. This is BEST classified as a:
- Natural disaster risk
- Data breach through insider threat (Correct answer)
- System availability failure
- Metadata exposure incident
Correct answer: Data breach through insider threat
Unauthorized copying of sensitive records by an employee constitutes an insider threat data breach.
Question 3: Under HIPAA, which of the following is considered Protected Health Information (PHI)?
- Anonymized patient statistics
- A patient's name combined with their diagnosis (Correct answer)
- General public health research data
- Aggregated hospital admission counts
Correct answer: A patient's name combined with their diagnosis
PHI includes any individually identifiable health information, such as a patient's name linked to their medical condition.
Question 4: What is the primary purpose of a data classification policy in records management?
- To assign retention schedules to all records
- To categorize information by sensitivity and apply appropriate controls (Correct answer)
- To index records for faster retrieval
- To determine the physical storage location of records
Correct answer: To categorize information by sensitivity and apply appropriate controls
Data classification policies categorize records by sensitivity level so that appropriate security controls can be applied to each category.
Question 5: Which encryption standard is currently recommended by NIST for protecting sensitive federal records at rest?
- DES (Data Encryption Standard)
- RC4
- AES-256 (Advanced Encryption Standard) (Correct answer)
- MD5
Correct answer: AES-256 (Advanced Encryption Standard)
NIST recommends AES-256 as the current standard for strong encryption of sensitive data at rest.
Question 6: A 'privacy impact assessment' (PIA) is conducted to:
- Evaluate the financial cost of a data breach
- Identify privacy risks before implementing a new system or process involving personal data (Correct answer)
- Train employees on data handling procedures
- Archive records that contain personal information
Correct answer: Identify privacy risks before implementing a new system or process involving personal data
A PIA is a proactive analysis performed before deploying new systems or processes to identify and mitigate privacy risks.
Question 7: Which of the following BEST describes the concept of 'least privilege' in records security?
- Users receive access only to the information they need to perform their job functions (Correct answer)
- All employees share equal access to organizational records
- Senior managers have unrestricted access to all records
- Access rights are granted based on seniority alone
Correct answer: Users receive access only to the information they need to perform their job functions
Least privilege limits user access rights to only what is necessary for their specific role, minimizing unauthorized exposure.
Which principle of information security ensures that data is not disclosed to unauthorized individuals?