CRM Information Security & Privacy 3 — Questions and Answers
Question 1: Under the GDPR, a data subject's 'right to erasure' is also known as the:
- Right to portability
- Right to be forgotten (Correct answer)
- Right to rectification
- Right to access
Correct answer: Right to be forgotten
The GDPR's right to erasure (Article 17) is commonly called the 'right to be forgotten,' allowing individuals to request deletion of their personal data.
Question 2: Which records management practice BEST supports compliance with breach notification laws?
- Retaining all records indefinitely
- Maintaining an accurate inventory of where personal data is stored (Correct answer)
- Encrypting only financial records
- Limiting digital recordkeeping to reduce exposure
Correct answer: Maintaining an accurate inventory of where personal data is stored
Knowing where personal data resides enables organizations to quickly identify affected records and comply with breach notification timelines.
Question 3: An organization uses 'tokenization' for protecting credit card numbers in records. What does tokenization do?
- Compresses data to reduce storage size
- Replaces sensitive data with a non-sensitive surrogate value (Correct answer)
- Deletes sensitive fields from records permanently
- Encrypts data using a public key infrastructure
Correct answer: Replaces sensitive data with a non-sensitive surrogate value
Tokenization substitutes sensitive data with a placeholder token, so the original value is never stored in operational systems.
Question 4: Which federal law primarily governs privacy of student education records in the United States?
- HIPAA
- GLBA
- FERPA (Correct answer)
- SOX
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records at institutions receiving federal funding.
Question 5: A records manager is developing a security policy for email records containing PII. The FIRST step should be to:
- Immediately encrypt all email archives
- Identify and classify the PII contained in email records (Correct answer)
- Delete emails older than one year
- Migrate all email records to cloud storage
Correct answer: Identify and classify the PII contained in email records
Before applying controls, the manager must identify and classify what PII exists in email records to determine the appropriate protection level.
Question 6: Which security control is specifically designed to detect unauthorized changes to records?
- Firewall rules
- Role-based access control (RBAC)
- Audit trails and hash verification (Correct answer)
- Data loss prevention (DLP) software
Correct answer: Audit trails and hash verification
Audit trails log all access and modifications, while cryptographic hashing can detect if a record's content has been altered.
Question 7: When records are transferred to a third-party vendor for storage or processing, which document BEST protects the organization's privacy obligations?
- A service level agreement (SLA) for uptime
- A data processing agreement (DPA) specifying security and privacy requirements (Correct answer)
- An internal retention schedule
- A records destruction certificate
Correct answer: A data processing agreement (DPA) specifying security and privacy requirements
A DPA contractually obligates third-party vendors to uphold the organization's data protection standards when handling personal information.
Under the GDPR, a data subject's 'right to erasure' is also known as the: