CMO CMO Data Security & Privacy Management 1 — Questions and Answers
Question 1: Which encryption standard is recommended for protecting data transmitted between Mobilyze field devices and the central server?
- MD5
- TLS 1.2 or higher (Correct answer)
- Base64 encoding
- FTP over SSH
Correct answer: TLS 1.2 or higher
TLS 1.2 or higher is the industry-recommended protocol for encrypting data in transit between Mobilyze field devices and servers.
Question 2: What is the primary purpose of role-based access control (RBAC) within the Mobilyze platform?
- To speed up data uploads
- To limit system access to authorized personnel only (Correct answer)
- To generate automatic reports
- To configure device firmware
Correct answer: To limit system access to authorized personnel only
RBAC ensures that only authorized personnel can access specific functions and data within the Mobilyze platform, reducing insider threat risk.
Question 3: When a Mobilyze operator leaves a company, what is the FIRST step to protect data security?
- Archive their reports
- Immediately revoke their system credentials and access tokens (Correct answer)
- Transfer their device to another operator
- Delete their data logs
Correct answer: Immediately revoke their system credentials and access tokens
Immediately revoking credentials and access tokens prevents former employees from accessing sensitive Mobilyze data.
Question 4: Which of the following is a best practice for password management on Mobilyze operator accounts?
- Sharing passwords between team members for efficiency
- Using the same password across all systems
- Using complex, unique passwords and rotating them regularly (Correct answer)
- Writing passwords on the device for quick access
Correct answer: Using complex, unique passwords and rotating them regularly
Using complex, unique passwords and rotating them regularly minimizes the risk of unauthorized account access.
Question 5: Under US data privacy regulations, what must a CMO operator do before sharing client-collected field data with a third party?
- Export the data to CSV first
- Obtain proper authorization or consent as required by the data agreement (Correct answer)
- Archive the data in the cloud
- Re-calibrate devices
Correct answer: Obtain proper authorization or consent as required by the data agreement
US data privacy frameworks require that proper authorization or consent be obtained before sharing client data with any third party.
Question 6: What should a CMO operator do if they suspect a data breach has occurred on a Mobilyze-connected device?
- Continue working and document it later
- Immediately isolate the device and report the incident per the incident response plan (Correct answer)
- Restart the device and run a system update
- Delete all recent data logs
Correct answer: Immediately isolate the device and report the incident per the incident response plan
Isolating the affected device and following the incident response plan limits breach exposure and complies with notification requirements.
Which encryption standard is recommended for protecting data transmitted between Mobilyze field devices and the central server?