CRM Risk Management & Security 3 — Questions and Answers
Question 1: Which concept describes the practice of keeping two separate individuals required to complete a sensitive records transaction, preventing any one person from acting alone?
- Least privilege
- Dual control (Correct answer)
- Chain of custody
- Segregation of storage
Correct answer: Dual control
Dual control (two-person integrity) requires two authorized individuals to jointly perform a sensitive action, reducing insider threat and fraud risk.
Question 2: An organization retains paper records in a storage facility. Which environmental control is most critical to prevent physical deterioration of paper documents?
- Fire suppression system only
- Controlled temperature and humidity (Correct answer)
- Biometric entry locks
- CCTV surveillance cameras
Correct answer: Controlled temperature and humidity
Paper records degrade rapidly when exposed to high humidity, high temperatures, or fluctuating conditions, making climate control the top preservation priority.
Question 3: When conducting a records risk assessment, 'threat' is best defined as:
- The potential harm that could result from a security incident
- Any circumstance or event with the potential to exploit a vulnerability (Correct answer)
- A weakness in a control that could be exploited
- The probability that a harmful event will occur
Correct answer: Any circumstance or event with the potential to exploit a vulnerability
A threat is a potential source of harm (natural, human, or environmental) that could exploit a vulnerability in the records system.
Question 4: Under the Privacy Act of 1974, federal agencies must do which of the following regarding records about individuals?
- Encrypt all records using AES-256 regardless of content
- Allow individuals to access and request corrections to their own records (Correct answer)
- Destroy records within five years of creation
- Classify personal records as Confidential by default
Correct answer: Allow individuals to access and request corrections to their own records
The Privacy Act grants individuals the right to access federal records about themselves and request amendments to inaccurate information.
Question 5: A chain of custody document for evidentiary records must include which essential element?
- The market value of the records
- A chronological log of every person who handled the records (Correct answer)
- The file format used for digital versions
- The retention schedule assigned to the records
Correct answer: A chronological log of every person who handled the records
Chain of custody requires a detailed log of everyone who accessed, transferred, or handled evidence to maintain its integrity and admissibility.
Question 6: Which risk treatment option involves shifting potential financial losses from a records incident to a third party?
- Risk avoidance
- Risk acceptance
- Risk transfer (Correct answer)
- Risk mitigation
Correct answer: Risk transfer
Risk transfer moves the financial consequence of a risk to another party, typically through insurance or contractual agreements with service providers.
Question 7: A records manager is implementing role-based access control (RBAC). What is the primary advantage of RBAC over assigning permissions individually to each user?
- It eliminates the need for any auditing of record access
- It simplifies administration by grouping users with similar job functions (Correct answer)
- It allows users to grant their own permissions as needed
- It automatically encrypts records assigned to each role
Correct answer: It simplifies administration by grouping users with similar job functions
RBAC groups users by job role and assigns permissions to roles, reducing the administrative burden of managing individual user permissions at scale.
Which concept describes the practice of keeping two separate individuals required to complete a sensitive records transaction, preventing any one person from acting alone?