Security & Data Protection Standards Flashcards
7 cards from real CMT practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security & Data Protection Standards flashcards as text
Which protocol is used to securely wipe an iOS device remotely when it cannot connect to the internet?
Answer: MDM wipe command queued for next connection
MDM wipe commands are queued on Apple's APNs infrastructure and delivered the next time the device connects to any network, ensuring eventual execution.
A customer's Android device is showing signs of a rogue profile installed via a phishing link. What is the FIRST step a technician should take?
Answer: Navigate to device admin settings and revoke the rogue profile's permissions before removal
Rogue device admin profiles must first be deactivated in settings before they can be removed, as active admin profiles block their own deletion.
What is the primary security benefit of using eSIM technology over a physical SIM card?
Answer: eSIMs cannot be physically removed or swapped, reducing SIM-swap attack risk
Because eSIMs are embedded and not removable, a thief cannot simply swap the SIM to bypass carrier blacklisting or access the mobile number.
Under the California Consumer Privacy Act (CCPA), what right do consumers have regarding personal data collected by mobile apps?
Answer: The right to know what data is collected, opt out of its sale, and request deletion
CCPA grants California consumers the rights to access, delete, and opt out of the sale of their personal information collected by businesses.
A technician is using a USB-C cable to transfer a customer's data during repair. Which attack vector should the technician be aware of if using an untrusted cable?
Answer: BadUSB attack where the cable contains embedded malicious firmware
BadUSB attacks embed malicious firmware in a cable or USB device that can execute commands, inject keystrokes, or install malware when plugged in.
Which concept describes the security practice of granting a mobile app or user only the minimum permissions needed to perform their task?
Answer: Principle of least privilege
The principle of least privilege limits access rights to only what is strictly required, reducing the attack surface if an app or account is compromised.
A mobile device technician shop stores customer device logs for diagnostic purposes. How long should these logs be retained under general best-practice data governance?
Answer: Only as long as necessary for the stated purpose, then securely destroyed
Data retention best practices (and laws like GDPR and CCPA) require keeping personal data only as long as necessary for its original purpose, then securely deleting it.