CRT Cybersecurity & Risk Management 2 — Questions and Answers
Question 1: A retail tobacconist store experiences a ransomware attack that encrypts all customer purchase records. What is the FIRST step the owner should take?
- Pay the ransom immediately to recover files
- Disconnect affected systems from the network (Correct answer)
- Contact customers to warn them
- Reinstall the operating system
Correct answer: Disconnect affected systems from the network
Isolating infected systems from the network prevents ransomware from spreading to other devices or backups.
Question 2: Which type of authentication provides the strongest protection for a tobacco retail POS system login?
- Single password only
- PIN number only
- Multi-factor authentication (MFA) (Correct answer)
- Fingerprint alone
Correct answer: Multi-factor authentication (MFA)
MFA requires multiple verification factors, making unauthorized access significantly harder even if one credential is compromised.
Question 3: A tobacco retailer collects customer birthdate data for age verification. Under risk management best practices, this data should be:
- Stored indefinitely for future marketing
- Retained only as long as legally required, then securely deleted (Correct answer)
- Shared freely with tobacco suppliers
- Kept in plain text for easy access
Correct answer: Retained only as long as legally required, then securely deleted
Data minimization and retention limits reduce liability and comply with privacy regulations by not holding data longer than necessary.
Question 4: An employee receives an email claiming to be from a tobacco supplier asking for urgent wire payment. This is most likely a:
- Legitimate vendor request
- Business email compromise (BEC) scam (Correct answer)
- Software update notification
- Regulatory compliance notice
Correct answer: Business email compromise (BEC) scam
Business email compromise scams impersonate trusted contacts to trick businesses into fraudulent wire transfers.
Question 5: What does the term 'least privilege' mean in a retail cybersecurity context?
- Employees share one login for simplicity
- Each employee only has system access needed for their specific job role (Correct answer)
- The owner has no system access restrictions
- Customers can access employee portals
Correct answer: Each employee only has system access needed for their specific job role
Least privilege limits each user's access to only what they need, reducing the damage potential of compromised accounts.
Question 6: A tobacco shop's Wi-Fi network is used for both the POS system and customer internet access. The BEST security practice is to:
- Use the same password for both
- Segment them into separate networks (Correct answer)
- Disable the customer Wi-Fi entirely
- Share all network files between both networks
Correct answer: Segment them into separate networks
Network segmentation ensures that a compromised guest network cannot expose the POS or sensitive business systems.
Question 7: Which regulation most directly governs how a U.S. tobacco retailer must protect customers' payment card data?
- FDA Tobacco Control Act
- PCI DSS (Payment Card Industry Data Security Standard) (Correct answer)
- OSHA workplace safety standards
- FTC advertising regulations
Correct answer: PCI DSS (Payment Card Industry Data Security Standard)
PCI DSS sets the security standards for any business that accepts, processes, or stores credit/debit card payments.
A retail tobacconist store experiences a ransomware attack that encrypts all customer purchase records.
What is the FIRST step the owner should take?