โ† All CMT Flashcard Decks

Security & Data Protection Standards Flashcards

7 cards from real CMT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security & Data Protection Standards flashcards as text
  1. A customer brings in a phone for repair and requests that their data be backed up before servicing. Which encryption method should be used to protect the backup stored on a technician's workstation?

    Answer: Use AES-256 encryption for the backup file

    AES-256 is the industry standard for encrypting sensitive data backups, providing strong protection against unauthorized access.

  2. Under COPPA (Children's Online Privacy Protection Act), what age threshold determines special data handling requirements for mobile apps?

    Answer: Under 13

    COPPA requires verifiable parental consent before collecting personal information from children under 13.

  3. A technician notices a mobile device is running an app with unusually high background data usage. What is the MOST likely security concern?

    Answer: The app may be exfiltrating data to a remote server

    Unexplained background data usage is a common indicator of spyware or malware transmitting device data to a command-and-control server.

  4. Which mobile device management (MDM) capability allows an IT administrator to erase corporate data from a personal employee device without deleting personal photos and apps?

    Answer: Selective wipe

    Selective wipe (also called corporate wipe) removes only managed corporate data and apps while leaving personal content intact.

  5. What does the term 'data minimization' mean in the context of mobile app privacy standards?

    Answer: Collecting only the data strictly necessary for the app's stated purpose

    Data minimization is a core GDPR and privacy principle requiring apps to collect only data that is necessary for their specific function.

  6. A technician performing a screen replacement must boot the device into a diagnostic mode. Which security feature could prevent unauthorized access to the device during this process?

    Answer: Secure Boot / Bootloader lock

    A locked bootloader enforces Secure Boot, preventing the device from booting unauthorized or modified OS images during repair.

  7. When disposing of a mobile device on behalf of a customer, which step is MOST critical to ensure data protection compliance?

    Answer: Perform a factory reset and verify data destruction

    A factory reset followed by verification ensures all user data is wiped; simply removing accounts or apps does not fully protect against data recovery.