wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

A+ - 19C - Explain Data Handling Best Practices

Total questions: 2

Worksheet time: 12mins

Name
Class
Date
1-19.

Regulated data classification is essential for organizations to comply with federal and/or state legislation regarding the collection, processing, and storage of sensitive information. This classification includes several types of data, such as personally identifiable information (PII), personal government-issued information, healthcare data, and credit card transactions.

Employees should be trained to handle sensitive data appropriately and avoid unauthorized access or disclosure. Data retention requirements dictate the maximum and minimum periods for retaining data based on regulatory standards. Prohibited content and licensing issues encompass ensuring that workstations are used appropriately and that software licenses are compliant with usage terms.

Incident response procedures are crucial for addressing security incidents promptly and effectively. Organizations must have an incident response plan (IRP) and a Computer Security Incident Response Team (CSIRT) to manage security incidents. Digital forensics plays a vital role in collecting evidence from computer systems for potential legal proceedings, emphasizing the importance of maintaining data integrity and preserving evidence through proper documentation and chain of custody procedures.

Data destruction methods are necessary for securely disposing of data storage media, including erasing/wiping, low-level formatting, and physical destruction through shredding, incineration, or degaussing. Outsourcing disposal to third-party vendors ensures proper destruction and provides certificates of destruction/recycling for verification.

1.

What is regulated data?

a)

Information that must comply with organizational policies

b)

Information collected, processed, and stored in compliance with federal and/or state legislation

c)

Information accessible to all employees

d)

Information stored without any security measures

2.

What is a breach?

a)

Authorized access to data

b)

Unauthorized access to data

c)

Secure transfer of data

d)

Routine maintenance of data

3.

Which of the following is an example of personally identifiable information (PII)?

a)

Company's address

b)

Generic email address

c)

Social security number (SSN)

d)

Public domain information

4.

What is an example of personal government-issued information?

a)

Employee ID card

b)

Company logo

c)

Internal memo

d)

Public website

5.

Which standard governs the processing of credit card transactions?

a)

ISO 9001

b)

PCI DSS

c)

HIPAA

d)

GDPR

6.

What is the purpose of an end-user license agreement (EULA)?

a)

To limit the number of users

b)

To permit unlimited distribution

c)

To set terms and conditions for software use

d)

To prohibit software installation

7.

Which method ensures old data is destroyed by writing to each location on a hard disk drive?

a)

Low level format

b)

Degaussing

c)

Incineration

d)

Shredding

8.

What is the role of a Computer Security Incident Response Team (CSIRT)?

a)

Data encryption

b)

Incident reporting

c)

Physical security

d)

Software licensing

9.

What is the purpose of documenting the scene of a security incident?

a)

To preserve evidence

b)

To erase data

c)

To delete evidence

d)

To share information

10.

Which method of data destruction involves melting a disk's components with high heat?

a)

Degaussing

b)

Shredding

c)

Incineration

d)

Low level format

11.

What is digital forensics?

a)

Collecting evidence from computer systems for legal proceedings

b)

Regular maintenance of computer systems

c)

Data encryption techniques

d)
  1. Software development process

12.

Which type of data is highly sensitive and associated with medical and insurance records?

a)

Personally Identifiable Information (PII)

b)

Personal Government-issued Information

c)

Healthcare Data

d)

Credit Card Transactions

13.

What does an incident response plan (IRP) outline?

a)

Guidelines for data retention

b)

Procedures for handling security incidents

c)

Licensing terms for software usage

d)
  1. Techniques for data destruction

14.

What must be recorded in a chain of custody form?

a)

Information about prohibited content

b)

Methods for data destruction

c)

Details of evidence collection and handling

d)

Instructions for software installation

15.

What is the primary purpose of data retention requirements?

a)

To ensure secure data handling

b)

To set standards for software licensing

c)

To comply with regulatory standards

16.

Which type of data is subject to specific privacy legislation, such as the US Privacy Act?

a)

Personally Identifiable Information (PII)

b)

Personal Government-issued Information

c)

Healthcare Data

d)

Credit Card Transactions

17.

Which type of data is often used for password reset mechanisms and confirming identity over the telephone?

a)

Personally Identifiable Information (PII)

b)

Personal Government-issued Information

c)

Healthcare Data

d)

Credit Card Transactions

18.

What must be included in documentation of the scene of a security incident?

a)

Photographs and video only

b)

Video and audio only

c)

Photographs, video, and audio

d)

Text description only

19.

Which method of data destruction involves exposing a hard disk to a powerful electromagnet?

a)

Shredding

b)

Incineration

c)

Degaussing

d)
  1. Low level format

20.

Have you submitted your standup form yet?

Click the link below

https://airtable.com/appg2CeX4DA9Y7hDi/shrUyD9aoryvXZgfu

a)

Not yet

b)

I have now.