IGP Technology & Information Security 5 — Questions and Answers
Question 1: In an IG program, what is the primary purpose of a data map or data inventory?
- Document the geographic location of all company offices
- Catalog where personal and sensitive data is created, stored, used, and shared (Correct answer)
- Track software licensing compliance across the enterprise
- Monitor employee access to corporate email systems
Correct answer: Catalog where personal and sensitive data is created, stored, used, and shared
A data map catalogs the full lifecycle of data — where it originates, how it flows, where it is stored, and who accesses it — enabling effective governance and risk management.
Question 2: Which security principle ensures that no single individual can complete a critical process alone, reducing fraud risk?
- Least privilege
- Need to know
- Separation of duties (Correct answer)
- Defense in depth
Correct answer: Separation of duties
Separation of duties requires that critical tasks be divided among multiple individuals, so no single person can both initiate and approve a transaction or action.
Question 3: An organization receives a ransomware attack that encrypts all files on a shared drive. Which backup strategy would BEST minimize data loss?
- Weekly full backups stored on the same network
- Daily incremental backups stored offline or in an isolated environment (Correct answer)
- Monthly full backups stored in the cloud
- Real-time replication to another folder on the same drive
Correct answer: Daily incremental backups stored offline or in an isolated environment
Daily incremental backups stored offline or in an air-gapped environment ensure minimal data loss and prevent ransomware from encrypting backup copies.
Question 4: Under the GDPR, what right allows individuals to request that their personal data be erased?
- Right to data portability
- Right to erasure (right to be forgotten) (Correct answer)
- Right of access
- Right to restriction of processing
Correct answer: Right to erasure (right to be forgotten)
Article 17 of the GDPR grants individuals the right to erasure, allowing them to request deletion of their personal data under specific circumstances.
Question 5: What is the purpose of a Certificate Revocation List (CRL) in a PKI environment?
- List all certificates due for renewal in the next 30 days
- Identify digital certificates that have been invalidated before their expiration date (Correct answer)
- Store the private keys of revoked certificates
- Track certificate issuance costs for audit purposes
Correct answer: Identify digital certificates that have been invalidated before their expiration date
A CRL is a list maintained by a Certificate Authority that contains serial numbers of certificates revoked due to compromise, policy violations, or other reasons.
Question 6: Which type of malware disguises itself as legitimate software but performs malicious actions when executed?
- Worm
- Rootkit
- Trojan horse (Correct answer)
- Adware
Correct answer: Trojan horse
A Trojan horse masquerades as benign or useful software while secretly performing malicious functions such as opening backdoors or stealing credentials.
Question 7: An organization's IG policy requires that all sensitive emails be retained for 7 years. Which technology BEST enforces this automatically?
- Spam filtering gateway
- Email archiving solution with retention policies (Correct answer)
- Endpoint antivirus software
- Intrusion prevention system (IPS)
Correct answer: Email archiving solution with retention policies
An email archiving solution with configurable retention policies automatically captures, stores, and enforces retention periods for messages, ensuring compliance without relying on users.
In an IG program, what is the primary purpose of a data map or data inventory?