wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Cyber L&P CHP 6 contd....

Total questions: 56

Worksheet time: 1hrs 11mins

Name
Class
Date
1.

Program policies are ________ and program procedures are __________.

a)

prescriptive, descriptive

b)

descriptive, prescriptive

2.

No cryptography algorithms shall be used unless the patent has either expired or the company maintains a valid license. License arrangement must meet the expected use of the product or service life as well as comply with export control guidelines

a)

Encryption Personal Use Exemption

b)

International Encryption Law Compliance

c)

Cryptography Patent Infringement

d)

Export Control Law

e)

State Encryption Safe Harbor Provisions

3.

Travel by employees to countries that do not extend personal use exemptions will require authorization by the legal department and the filing of an encryption import license

a)

Encryption Personal Use Exemption

b)

International Encryption Law Compliance

c)

Cryptography Patent Infringement

d)

Export Control Law

e)

State Encryption Safe Harbor Provisions

4.

Software or hardware products containing an encryption level higher than 512-bit key encryption will not be sent or used outside of the US.

a)

Encryption Personal Use Exemption

b)

International Encryption Law Compliance

c)

Cryptography Patent Infringement

d)

Export Control Law

e)

State Encryption Safe Harbor Provisions

5.

Personal healthcare information (PHI) of employees or customers, regardless of the Health Insurance Portability and Accountability Act (HIPAA) compliance requirements, will be encrypted with an algorithm and processes prescribed by the company’s PHI risk assessment

a)

Encryption Personal Use Exemption

b)

International Encryption Law Compliance

c)

Healthcare Data Privacy

d)

Import Control Law

e)

State Encryption Safe Harbor Provisions

6.

In the event travel or equipment deployment is required within an import restricted country, an appropriate license will be filed, and only after US Department of State approval will the activity proceed.

a)

Encryption Personal Use Exemption

b)

International Encryption Law Compliance

c)

Healthcare Data Privacy

d)

Import Control Law

e)

State Encryption Safe Harbor Provisions

7.

Data sent to and stored in foreign countries will comply with all local encryption laws. If local encryption law requires a lower level of key length than currently used, an application for an export license will be necessary.

a)

Encryption Personal Use Exemption

b)

International Encryption Law Compliance

c)

Healthcare Data Privacy

d)

Import Control Law

e)

State Encryption Safe Harbor Provisions

8.

Employees traveling to countries that require key disclosure will abide by all local encryption laws including providing the password to decrypt information requested by local authorities. Any time a request is made the employee will immediately notify the legal department

a)

Key Disclosure Laws

b)

International Encryption Law Compliance

c)

Healthcare Data Privacy

d)

Import Control Law

e)

State Encryption Safe Harbor Provisions

9.

Encryption of personal data at a level meeting or exceeding the highest-level key length of any state will be followed to ensure compliance with all state safe harbor provisions.

a)

Key Disclosure Laws

b)

International Encryption Law Compliance

c)

Healthcare Data Privacy

d)

Import Control Law

e)

State Encryption Safe Harbor Provisions

10.

Applications or systems that interact with minors (13 and under) will comply with the standards of the Internet Keep Safe Coalition (iKeepSafe) and its Safe Harbor program under the Children’s Online Privacy Protection Act (COPPA).

a)

Federal Children’s Online Privacy Law

b)

Privacy Law Library

c)

State Minor’s Privacy Acts

11.

A current library of state, federal, and international privacy laws will be maintained. A cross-mapping of security controls with legal requirements will be maintained to ensure alignment with the cybersecurity program.

a)

Federal Children’s Online Privacy Law

b)

Privacy Law Library

c)

State Minor’s Privacy Acts

12.

Applications or systems that interact with minors (17 and under) will abide by all provisions of any state’s child privacy law including prohibiting the sale of dangerous products and complying with requests to remove personal data

a)

Federal Children’s Online Privacy Law

b)

Privacy Law Library

c)

State Minor’s Privacy Acts

13.

Digital evidence will be gathered according to the Federal Rules of Evidence under the oversight of the legal department

a)

Digital Best Evidence Rule

b)

Digital Chain of Custody

c)

Digital Data Spoliation

d)

Preservation Order

e)

Search and Seizure of Encrypted Data

14.

To ensure evidence in a cybercrime investigation is admissible in a court of law, all evidence will be gathered according to the US Department of Justice’s Searching and Seizing Computers and Obtaining Electronic Evidence in Criminal Investigations manual under the oversight of the legal department.

a)

Digital Best Evidence Rule

b)

Digital Chain of Custody

c)

Digital Data Spoliation

d)

Preservation Order

e)

Search and Seizure of Encrypted Data

15.

In the event of a pending lawsuit or issuance of a preservation order, no employee or contractor will destroy or alter in any way the data identified by the court order.

a)

Digital Best Evidence Rule

b)

Digital Chain of Custody

c)

Digital Data Spoliation

d)

Preservation Order

e)

Search and Seizure of Encrypted Data

16.

No action will be taken unless and until the direct oversight of the legal department has begun. All documents requested will be secured in a manner as to preserve them for plaintiff discovery.

a)

Digital Best Evidence Rule

b)

Digital Chain of Custody

c)

Digital Data Spoliation

d)

Preservation Order

e)

Search and Seizure of Encrypted Data

17.

If a discovery order is received to produce information, full cooperation will be provided to the plaintiff’s legal counsel and the data will be decrypted and submitted. This process can only occur under the direction of legal counsel.

a)

Digital Best Evidence Rule

b)

Digital Chain of Custody

c)

Digital Data Spoliation

d)

Preservation Order

e)

Search and Seizure of Encrypted Data

18.

The company will carry a cyber liability insurance policy for up to $5 million above the self-insurance loss pool of $1 million with a $100,000 per loss deductible for third party losses.

a)

Cyber Liability Insurance Policy

b)

Annual Coverage Assessment

c)

Preservation Order

d)

Search and Seizure of Encrypted Data

19.

An annual assessment of cyber liability coverage will be performed considering the estimated loss exposure for a data breach based on the projected number of compromised records in the next physical year.

a)

Cyber Liability Insurance Policy

b)

Annual Coverage Assessment

c)

Preservation Order

d)

Search and Seizure of Encrypted Data

20.

The ___________ standard is a set of practices for the ___________ which provides guidance on aligning information technology with the business.

(a)  

21.

Organizations that expect involvement in several data breach lawsuits need to consider a software product specifically designed to manage the litigation process and maintain legal holds This software is called:

(a)  

22.

What do eDiscovery software do?

4 lines
23.

What are the 3 advantages of eDiscovery Software?

4 lines
24.

Your program will require a significant quantity of documents that will need to be stored and easily accessed by program participants. For this, you will create a_________ library in Microsoft ________ where they can be_________ or _________. (use all lower-case letters and commas to separate them)

(a)  

25.

Is a way to flag a document with keywords so that anyone searching for that kind of information may locate it.

(a)  

26.

What are sample meta-tags in documents for each of the following: Category of law, program component, document attributes, geographical applicability, jurisdiction, document type.

4 lines
27.

Is a technology used to track websites and stream updates to a data repository, such as a spreadsheet or database. This makes keeping up with changes in the law more efficient.

a)

RSS

b)

ITIL

c)

ITSM

d)

Law and regulations library

28.

Why would a company need to subscribe to Thomas Reuter's WestLaw or LexisNexis?

4 lines
29.

Are products and services available that can scan your network testing your cybersecurity and privacy controls to the policies you established to maintain compliance.

(a)  

30.

Policy scanners are available as a cloud-based service, meaning they're operated by 3rd parties, and as standalone products in which users can use first-hand.

a)

True

b)

False

31.

When conducting data breach investigations, your organization will require a __________ to either identify evidence destroyed by employees or create evidence according to the best evidence rule.

a)

Forensic Toolkit

b)

Law Library

c)

Network scanners

d)

Preservation order

e)

eDiscovery softwares

32.

Explain how Forensic Toolkits work

4 lines
33.

Describe the process of mapping legal requirements to controls

4 lines
34.

This type of insurance covers non-fraudulent causes of failures or errors occurring in the performance of computer services. Technology companies offering cloud, software, or consulting services typically acquire this type of insurance.

a)

Errors and Omissions

b)

Media Liability

c)

Network Security

d)

Privacy

e)

Network Security and Privacy Liability

35.

This type of insurance covers customer injury claims resulting from intellectual property infringement, copyright or trademark infringement, libel, and slander. Coverage could also be extended to patents or trade secret violations. This coverage is important to organizations with sizable online presences.

a)

Errors and Omissions

b)

Media Liability

c)

Network Security

d)

Privacy

e)

Network Security and Privacy Liability

36.

This type of insurance covers network equipment failures or external attacks against your network including denial of service attacks. Network outages or breaches covered can include data breaches of consumer information, cyber extortion, data alteration or destruction, or malware infestations.

a)

Errors and Omissions

b)

Media Liability

c)

Network Security

d)

Privacy

e)

Network Security and Privacy Liability

37.

This type of insurance covers breach of physical records caused by theft, loss, or accidental disclosure. Other incidents that may be covered include improper disposal of equipment containing sensitive data and inadvertently collecting confidential information

a)

Errors and Omissions

b)

Media Liability

c)

Network Security

d)

Privacy

e)

Network Security and Privacy Liability

38.

This type of insurance is a hybrid policy that also provides coverage for both the insured company and their third-party service providers. It covers the costs for responding to and recovering from data breaches, including penalties assessed from a lawsuit.

a)

Errors and Omissions

b)

Media Liability

c)

Network Security

d)

Privacy

e)

Network Security and Privacy Liability

39.

What are first party losses that insurance companies can cover?

4 lines
40.

What are third party losses that insurance companies can cover?

4 lines
41.

Is an amount of insurance coverage available to cover a specific type of loss.

a)

Sublimit

b)

Residual Risk

c)

Blanket Insurance

42.

The risk that is left after you have applied all your security control

a)

Sublimit

b)

Residual Risk

c)

Blanket Insurance

43.

The 5 ways cyber liability insurance policy can help even when no claim exists by providing:

4 lines
44.

The cost of cyber liability insurance is based on the following factors:

4 lines
45.

_______ companies paid the highest premiums followed by _______ companies.

(a)  

46.

(a)   companies paid the least in premium payments.

47.

_________companies purchased the highest levels of coverage, followed by ________.

(a)  

48.

Define 4 examples where insurance companies would deny paying the claims

4 lines
49.

Difference between insured and uninsured risks

4 lines
50.

(a)   : cyber-related losses stemming from insurance policies that were not specifically designed to cover cyber risk—meaning an insurer may have to pay claims for cyber losses under a policy not designed for that purpose.

51.

Reviews the company's adherence to the policy provisions provided, or just anything they must stick to, in general

(a)  

52.

What are the elements included in the Compliance auditing model?

4 lines
53.

What is the difference between Internal and External Auditing?

4 lines
54.

Compliance with legal and regulatory standards and statutes is a prime focus of many external audit organizations today.

a)

True

b)

False

55.

Verifying the financial statements and risk to the organization is the main focus of external auditors

a)

True

b)

False

56.

Internal auditors________ controls, while external auditors ________ controls.

(a)