Legal Technology & Information Management Flashcards
7 cards from real CLM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Legal Technology & Information Management flashcards as text
Multi-factor authentication (MFA) in law firm systems requires users to verify identity using:
Answer: Two or more independent credentials from different factor categories
MFA requires two or more verification factors from different categories (something you know, something you have, something you are) to reduce unauthorized access risk.
When a law firm experiences a data breach involving client personal information, attorneys' professional responsibility obligations typically include:
Answer: Notifying affected clients promptly and taking reasonable remediation steps
Attorneys must notify affected clients of a data breach under both professional responsibility rules (duty of communication) and applicable state breach notification laws.
In legal practice management software, a 'matter' is defined as:
Answer: A specific legal case, transaction, or project for a client
In practice management software, a 'matter' represents a specific legal case, transaction, or project linked to a client, used to track all related time, documents, and tasks.
Which principle from information security frameworks requires that users be granted only the minimum level of system access necessary to perform their job functions?
Answer: Principle of least privilege
The principle of least privilege limits user access rights to only what is strictly necessary for their job, reducing the risk of unauthorized access or accidental data exposure.
When law firms use AI-assisted legal research tools, which professional responsibility concern is most critical?
Answer: Verifying AI-generated citations and legal conclusions for accuracy before relying on them
Attorneys must verify AI-generated legal research for accuracy because AI tools can produce hallucinated or inaccurate citations, and blind reliance would violate the duty of competence.
The concept of 'information governance' in a law firm context encompasses:
Answer: The policies, processes, and controls for managing information assets across their full lifecycle
Information governance is a holistic framework of policies, processes, and controls that manages information assets throughout their entire lifecycle, from creation through destruction.
A law firm's Bring Your Own Device (BYOD) policy should address which of the following to protect client confidentiality?
Answer: Required security measures and the firm's right to remotely wipe firm data from personal devices
A BYOD policy must address required security controls and establish the firm's right to remotely wipe firm data from personal devices to protect client confidential information.