IGP Technology & Information Security 4 — Questions and Answers
Question 1: What is the main purpose of a records retention schedule in relation to information security?
- Define encryption algorithms for stored records
- Specify how long records must be kept and when they should be destroyed (Correct answer)
- Assign access permissions to records by role
- Determine backup frequency for critical records
Correct answer: Specify how long records must be kept and when they should be destroyed
A records retention schedule defines required retention periods for each record type and the authorized disposition method, supporting both legal compliance and data minimization.
Question 2: Which cloud deployment model provides dedicated infrastructure for a single organization, offering the highest level of control and security?
- Public cloud
- Community cloud
- Private cloud (Correct answer)
- Hybrid cloud
Correct answer: Private cloud
A private cloud provides cloud infrastructure exclusively for one organization, giving maximum control over security configurations and data isolation.
Question 3: An IGP professional reviewing a vendor contract should ensure which security clause is included to address data handling after contract termination?
- Service level agreement (SLA) for uptime
- Data return and destruction provisions (Correct answer)
- Liability caps for business interruptions
- Intellectual property ownership terms
Correct answer: Data return and destruction provisions
Data return and destruction provisions ensure that the vendor returns or securely destroys all organizational data once the contract ends, preventing residual data exposure.
Question 4: Which framework provides a risk-based approach to managing cybersecurity that is widely used as a voluntary standard in the US?
- ISO 27001
- NIST Cybersecurity Framework (CSF) (Correct answer)
- COBIT 2019
- PCI DSS
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework provides a voluntary, risk-based framework organized around five functions (Identify, Protect, Detect, Respond, Recover) for managing cybersecurity risk.
Question 5: What does the concept of 'data sovereignty' mean in information governance?
- The owner of a dataset has exclusive rights to monetize it
- Data is subject to the laws of the country where it is physically stored or processed (Correct answer)
- Encrypted data cannot be subpoenaed by foreign governments
- Users retain ownership of all personal data they create
Correct answer: Data is subject to the laws of the country where it is physically stored or processed
Data sovereignty means that data is governed by the legal jurisdiction of the country where it resides or is processed, affecting cross-border transfer rules.
Question 6: A company conducts a Business Impact Analysis (BIA). What does the Recovery Time Objective (RTO) define?
- The maximum amount of data loss measured in time that is acceptable
- The maximum acceptable time to restore a system after a disruption (Correct answer)
- The minimum backup frequency required for critical systems
- The total cost of recovering from a major incident
Correct answer: The maximum acceptable time to restore a system after a disruption
RTO defines the maximum tolerable duration of downtime for a business process or system before the disruption causes unacceptable harm to the organization.
Question 7: Which authentication method is considered MOST secure for remote access to sensitive systems?
- Single-factor authentication with a strong password
- Multi-factor authentication combining something you know, have, and are (Correct answer)
- Certificate-based authentication alone
- Biometric authentication alone
Correct answer: Multi-factor authentication combining something you know, have, and are
Multi-factor authentication combining knowledge, possession, and inherence factors is most secure because compromising any single factor is insufficient for unauthorized access.
What is the main purpose of a records retention schedule in relation to information security?