CISA Data Management and Privacy Controls 1 — Questions and Answers
Question 1: Which data classification level TYPICALLY requires the most stringent access controls and encryption?
- Public
- Internal use only
- Confidential/Restricted (Correct answer)
- Unclassified
Correct answer: Confidential/Restricted
Confidential or restricted data carries the highest sensitivity, requiring strict access controls, encryption, and audit logging.
Question 2: A data retention policy should PRIMARILY be based on:
- The available storage capacity of the organization
- Legal, regulatory, and business requirements for each data type (Correct answer)
- The preference of the IT department
- The age of the data management system
Correct answer: Legal, regulatory, and business requirements for each data type
Retention periods must align with applicable laws, regulations, and contractual obligations specific to each data category.
Question 3: The principle of data minimization requires organizations to:
- Store as much data as possible to support future analytics
- Collect and retain only the personal data necessary for a specific purpose (Correct answer)
- Encrypt all data regardless of sensitivity
- Share data freely among business units to improve efficiency
Correct answer: Collect and retain only the personal data necessary for a specific purpose
Data minimization limits collection to only what is needed, reducing privacy risk and regulatory exposure.
Question 4: Which of the following BEST describes data sovereignty?
- The right of an individual to access their personal data
- The legal principle that data is subject to the laws of the country in which it is stored (Correct answer)
- The ability to move data freely between cloud providers
- An encryption method that ensures only authorized users can read data
Correct answer: The legal principle that data is subject to the laws of the country in which it is stored
Data sovereignty means that data stored in a particular country is governed by that country's laws and regulations.
Question 5: A database activity monitoring (DAM) tool PRIMARILY helps an IS auditor by:
- Automatically encrypting sensitive database fields
- Providing real-time visibility into who is accessing and modifying database data (Correct answer)
- Replacing the need for database access controls
- Compressing database logs to save storage space
Correct answer: Providing real-time visibility into who is accessing and modifying database data
DAM tools capture and analyze all database activity, enabling detection of unauthorized access, privilege abuse, and policy violations.
Question 6: When personally identifiable information (PII) must be used in a test environment, the BEST practice is to:
- Copy production data directly into the test environment
- Use data masking or anonymization to de-identify the PII (Correct answer)
- Limit test environment access to senior developers only
- Delete test data immediately after each test cycle
Correct answer: Use data masking or anonymization to de-identify the PII
Data masking replaces real PII with realistic but fictitious values, eliminating privacy risk while preserving data format for testing.
Which data classification level TYPICALLY requires the most stringent access controls and encryption?