← All CISA Flashcard Decks

Data Management and Privacy Controls Flashcards

6 cards from real CISA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 6 Data Management and Privacy Controls flashcards as text
  1. Which of the following BEST describes the role of a Data Protection Officer (DPO)?

    Answer: Overseeing compliance with data privacy regulations and serving as a contact for regulators

    A DPO monitors regulatory compliance, advises on privacy obligations, and acts as a liaison with data protection authorities.

  2. The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to:

    Answer: Protect the confidentiality and security of customers' nonpublic personal information

    GLBA's Safeguards Rule requires financial institutions to implement an information security program protecting customers' NPI.

  3. An IS auditor finds that a third-party vendor processes sensitive customer data without a signed data processing agreement. The PRIMARY risk is:

    Answer: Lack of contractual controls over how the vendor handles, protects, and disposes of the data

    Without a data processing agreement, the organization has no contractual basis to enforce security, privacy, or breach notification obligations on the vendor.

  4. Which data destruction method is MOST appropriate for highly sensitive data stored on solid-state drives (SSDs)?

    Answer: Cryptographic erasure (crypto-shredding) or physical destruction

    SSDs do not respond to degaussing, and overwriting is unreliable due to wear leveling; crypto-shredding or physical destruction ensures complete data elimination.

  5. When auditing data quality, an IS auditor is PRIMARILY concerned with ensuring data is:

    Answer: Accurate, complete, consistent, and timely for its intended use

    Data quality encompasses accuracy, completeness, consistency, and timeliness—all necessary for reliable decision-making and reporting.

  6. Which of the following BEST supports the audit objective of confirming that access to sensitive data is restricted to authorized users only?

    Answer: Examining user access provisioning records, access control lists, and access logs

    Provisioning records, ACLs, and access logs together provide evidence of who has been granted access and who is actually using it.