Asset Security Flashcards
7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Asset Security flashcards as text
Which privacy principle requires that personal data collected for one purpose should not be used for a different purpose without consent?
Answer: Purpose limitation
Purpose limitation restricts the use of personal data to the specific purpose declared at the time of collection, which is a core GDPR and privacy principle.
An organization stores customer credit card data. Under PCI DSS, what is the MINIMUM protection required for stored Primary Account Numbers (PAN)?
Answer: Any of: truncation, tokenization, hashing, or encryption
PCI DSS allows PANs to be rendered unreadable via truncation, tokenization, one-way hashing, or strong encryption — organizations may choose any of these approved methods.
What is the MAIN difference between data marking and data labeling?
Answer: Marking is a visible classification indicator; labeling includes metadata embedded in the file
Data marking refers to visible human-readable classification indicators on documents, while labeling typically embeds classification metadata within digital files for automated handling.
Which sanitization method is appropriate for reusing a hard drive within the SAME security domain?
Answer: Purging (overwriting)
Purging (overwriting with multiple passes) is sufficient for media being reused within the same security domain where the classification level remains constant.
A CISO needs to ensure that sensitive R&D files on employee laptops remain protected even if the laptops are stolen. Which control BEST addresses this risk?
Answer: Full-disk encryption (FDE)
Full-disk encryption protects data at rest on stolen or lost devices by making stored data unreadable without the correct decryption key.
Which term describes the legal authority to determine how data is classified and who may access it?
Answer: Data owner
The data owner, typically a senior business manager, has the authority and responsibility to classify data, set access policies, and determine handling requirements.
Which control helps prevent sensitive data from leaving an organization via email or USB drives?
Answer: Data Loss Prevention (DLP)
Data Loss Prevention (DLP) solutions monitor and block the unauthorized transmission of sensitive data across various egress channels including email, USB, and cloud uploads.