โ† All CISSP Flashcard Decks

Asset Security Flashcards

7 cards from real CISSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Asset Security flashcards as text
  1. Under GDPR, which role is responsible for processing personal data on behalf of a data controller?

    Answer: Data processor

    A data processor handles personal data under the instructions of the data controller and must comply with GDPR requirements and contractual obligations.

  2. What is the PRIMARY security concern with end-of-life (EOL) software still running in a production environment?

    Answer: It no longer receives security patches, leaving vulnerabilities unmitigated

    EOL software no longer receives vendor security updates, so discovered vulnerabilities remain permanently unpatched and exploitable in production environments.

  3. A cloud provider stores customer data on shared physical servers. Which technique BEST protects customer data from being accessed by other tenants?

    Answer: Data encryption with tenant-specific keys

    Encrypting data with unique per-tenant keys ensures that even if one tenant accesses another's storage, the data remains unreadable without the correct decryption key.

  4. Which of the following BEST describes the concept of 'scoping' in security baseline selection?

    Answer: Reducing the number of controls applied based on the specific environment and mission

    Scoping allows organizations to eliminate controls that are not applicable to their specific environment, technology, or operational requirements while maintaining the intent of the baseline.

  5. What is the MAIN risk of storing sensitive data in personally identifiable information (PII) beyond its required retention period?

    Answer: Higher exposure to breach liability and regulatory penalties

    Retaining PII beyond the defined period unnecessarily increases breach exposure and violates privacy regulations like GDPR and CCPA, resulting in significant legal and financial penalties.

  6. Which approach to data collection is required by the privacy principle of data minimization?

    Answer: Collect only the data necessary to fulfill the stated purpose

    Data minimization requires organizations to collect only the personal data that is adequate, relevant, and limited to what is necessary for the specified purpose.

  7. A security team discovers that backup tapes contain unencrypted PHI and are transported offsite by a courier. Which is the BEST immediate remediation?

    Answer: Encrypt backup data before writing to tape

    Encrypting data on the tape before transport ensures that even if the tape is lost or stolen in transit, the PHI remains unreadable and the breach reporting obligation may not apply.