Confidentiality & Data Security Flashcards
7 cards from real CET practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Confidentiality & Data Security flashcards as text
Which encryption standard is most commonly recommended for securing sensitive data stored on electronic devices in the US?
Answer: AES-256
AES-256 (Advanced Encryption Standard with 256-bit keys) is the current US government-approved standard for protecting sensitive data at rest.
A technician discovers a hard drive containing customer records while repairing a computer. The best course of action is to:
Answer: Avoid accessing personal data and inform the customer
Technicians must avoid accessing personal customer data and should inform the customer of its presence to maintain confidentiality.
What is the primary purpose of a chain of custody document in electronics repair or forensics?
Answer: To document who handled evidence or devices and when
A chain of custody document records every person who handled a device or piece of evidence to maintain integrity and accountability.
Which of the following is considered a 'data breach' under most US privacy regulations?
Answer: Unauthorized access to personally identifiable information (PII)
A data breach occurs when unauthorized parties gain access to personally identifiable information, triggering legal notification requirements.
When disposing of a customer's old hard drive, which method ensures data is unrecoverable?
Answer: Physical destruction or DoD-standard overwriting (7-pass wipe)
Physical destruction or multi-pass overwriting per DoD 5220.22-M standard renders data unrecoverable, unlike simple deletion or formatting.
Two-factor authentication (2FA) improves security because it requires:
Answer: Something you know and something you have or are
2FA combines two different authentication factors—typically a password (something you know) with a token or biometric (something you have or are).
Which regulation specifically governs the privacy of health-related electronic data in the United States?
Answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) sets the standard for protecting sensitive patient health information in the US.