Confidentiality & Data Security Flashcards
7 cards from real CET practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Confidentiality & Data Security flashcards as text
A technician is asked to repair a device that may contain evidence in a criminal investigation. The technician should FIRST:
Answer: Consult with law enforcement or legal counsel before proceeding
Devices involved in legal investigations must be handled according to legal protocols; proceeding without guidance could compromise evidence or expose the technician to liability.
What does the principle of 'least privilege' mean in data security?
Answer: Users should have the minimum access rights needed to perform their job
Least privilege limits each user's access rights to only what is necessary for their role, reducing the potential damage from breaches or errors.
Which of the following is an example of social engineering in a cybersecurity context?
Answer: Tricking an employee into revealing login credentials via a fake phone call
Social engineering manipulates people—rather than technology—into divulging confidential information, as in phishing calls or impersonation.
A Non-Disclosure Agreement (NDA) in an electronics service context is primarily designed to:
Answer: Prevent the technician from sharing confidential customer or company information
An NDA legally obligates parties to keep specified information confidential, protecting both customer data and proprietary business information.
Which type of malware encrypts a user's files and demands payment for the decryption key?
Answer: Ransomware
Ransomware encrypts victim files and extorts payment (often in cryptocurrency) in exchange for the decryption key.
When a technician remotely accesses a customer's device for support, which practice is most important for data security?
Answer: Conducting the session over an encrypted, authenticated connection with customer consent
Remote support must be conducted over encrypted, authenticated connections with explicit customer consent to protect data and comply with privacy obligations.
What is 'data at rest' in the context of electronics security?
Answer: Data stored on a device or media not currently being transferred
Data at rest refers to inactive data stored physically on drives, SSDs, USB sticks, or other media, as opposed to data in transit or in use.