Information Security & Privacy Flashcards
7 cards from real CRM practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Information Security & Privacy flashcards as text
Which of the following is an example of 'data minimization' in records management?
Answer: Collecting only the personal data necessary for a specified purpose
Data minimization means collecting only the personal data actually needed for a defined purpose, reducing privacy risk.
A Certified Records Manager discovers that legacy paper records containing SSNs were improperly disposed of in a recycling bin. The MOST immediate response should be:
Answer: Retrieve the records and initiate the organization's incident response process
Improper disposal of records with SSNs constitutes a potential data breach, requiring immediate retrieval and activation of the incident response plan.
In the context of records security, 'chain of custody' refers to:
Answer: The documented history of who has accessed, transferred, or handled a record
Chain of custody tracks every person who has accessed or handled a record, ensuring its integrity and admissibility as evidence.
Which regulation requires financial institutions to protect the privacy of consumers' nonpublic personal information (NPI)?
Answer: GLBA (Gramm-Leach-Bliley Act)
The GLBA mandates that financial institutions safeguard the nonpublic personal information of their customers.
What is the purpose of 'redaction' in records management?
Answer: To remove or obscure sensitive information before releasing a record
Redaction removes or blacks out sensitive portions of a document before it is shared or released, protecting private or privileged information.
An organization's records retention policy conflicts with a state privacy law requiring earlier deletion of personal data. How should this conflict be resolved?
Answer: The more protective legal requirement takes precedence; consult legal counsel
When retention requirements conflict with privacy laws mandating deletion, the stricter legal obligation applies and legal counsel should be consulted.
Which type of attack involves an attacker intercepting communication between two parties to steal or alter records in transit?
Answer: Man-in-the-middle (MITM) attack
A MITM attack positions the attacker between sender and receiver, enabling interception or manipulation of data in transit.