WorksheetsBSE UNIT 8 Data Protection Act 2018 Quiz
Total questions: 52
Worksheet time: 26mins
What does the Data Protection Act 2018 relate to?
The implementation of the General Data Protection Regulation (GDPR)
The creation of the Data Protection Act 2000
The guidelines for internet usage
The principles of data storage
Which of the following is NOT one of the data protection principles that must be followed when using personal data?
Fairly
Lawfully
Secretively
Transparently
How many data protection principles are mentioned in the material?
One
Two
Three
Four
What is one of the seven key principles of GDPR that requires explaining to people why their data is held, what will be done with it, and how long it will be kept before disposal?
Data minimization
Integrity and confidentiality
Lawfulness, fairness and transparency
Accountability
According to GDPR, what must be created before collecting any information from anyone?
Data protection impact assessment
Privacy notice
Consent form
Data processing agreement
What does the principle of 'purpose limitation' under GDPR imply?
Data should be processed only for the purpose of storage.
Data should be collected for unspecified purposes.
Information must be collected for specified, explicit and legitimate purposes and not further processed in a manner that is incompatible with those purposes.
Data can be processed for any purpose as long as it is lawful.
What does data minimisation in GDPR refer to?
Storing the maximum amount of data possible
Collecting only the data that is not relevant to the purposes of collection
Information must be adequate, relevant and limited to what is necessary in relation to the purposes of collection
Keeping all data indefinitely, regardless of its relevance
Under GDPR, what is required for the accuracy of data?
Data should be deleted immediately after collection
Information held should be inaccurate and outdated
Information held should be accurate and, where necessary, kept up to date
Accuracy is not a concern under GDPR
What is the principle of storage limitation in GDPR?
Data must be stored forever, without any time constraints
Data must be kept in a form which permits identification of data subjects for no longer than is necessary for the purposes for which the personal data are processed
Data should be stored in an identifiable form for ease of access
There are no limitations on how long data can be stored
What should security measures be commensurate with according to GDPR principles?
The cost of the data protection systems
The sensitivity of the data held
The number of people affected by the data
The geographical location of the data storage
What must be done if there is a data breach involving personal data?
It should be kept confidential and not reported
It must be reported to the Information Commissioner's Office (ICO)
It should be reported to the media
It must be ignored unless it happens repeatedly
Which of the following is an example of a measure to ensure integrity and confidentiality of data?
Using weak passwords for convenience
Sharing passwords among employees
Locking filing cabinets and using strong passwords on devices
Storing all data in a single location
According to the GDPR, what lies at the heart of an approach to processing personal data?
Speed and efficiency
Profitability and cost-saving
These principles
Flexibility and adaptability
What is the term used for the right of access to the data you have on someone?
Data access request
Subject access request (SAR)
Personal data inquiry
Individual data claim
How long do you have to deal with a subject access request (SAR)?
One week
One month
Two months
Immediately
Which right allows individuals to object to specific processing of their personal data?
The right to be informed
The right to rectification
The right to access
The right to object to specific processing
What can individuals request if the data held about them isn't accurate?
Rectification
Deletion
Access
Information
What does the right to erasure allow an individual to request?
To have their data stored indefinitely
To have their data transferred to another organization
To have their data deleted
To restrict the processing of their data
Under the right to restrict processing, what is allowed regarding an individual's data?
The data must be deleted immediately
The data can be stored but not used
The data can be used without restrictions
The data must be made publicly available
What does the right to data portability provide to individuals?
The ability to have their data deleted upon request
The ability to have their data stored without any use
The ability to have their data made easily accessible and transferable
The ability to have their data processed automatically
What rights are associated with automated decision-making?
The right to have data stored indefinitely
The right to have data transferred upon request
The right to restrict the processing of data
The right to erasure
What is the best way to avoid a data disaster according to the learning material?
Ignoring potential risks
Regularly updating software
Always being prepared for a data disaster
Frequently changing data formats
Which of the following is NOT listed as an example of a data disaster in the learning material?
Device failure
Outdated formats
Natural disasters
Software updates
According to the document, what should you always have to avoid a disaster in data management?
A single copy of data in a secure location
More than one copy of data, accessible by more than one person
A backup on a cloud service only
Encrypted data in one place
What is recommended to do regularly to prevent data loss?
Delete old information
Move information to current storage formats
Store information on a single device
Avoid scanning original documents
What should be done with original photographs and documents to prepare for the worst?
Store them in a physical safe
Scan all original photographs and documents
Keep them in a locked drawer
Upload them to social media for safekeeping
What immediate action should be taken if a storage device fails or is damaged?
Try to fix the device yourself
Transfer the data to a safe location and replace the device
Wait for a professional to look at it
Continue using the device until it is completely unusable
What is the final step mentioned in the document after experiencing a digital data catastrophe?
Ignore the incident and continue as usual
Learn from mistakes and tragedies to prevent them in the future
Blame the person responsible for the loss
Outsource data management to another company
What is a critical first step in protecting sensitive company data?
Consulting IT security experts
Developing a disaster recovery plan
Creating a backup and choosing a firewall and antivirus solution
Keeping computer systems dust-free and dry
What should companies do to protect data from power surges?
Specify access levels
Use an uninterruptible power supply
Keep computer systems dust-free and dry
Consult IT security experts
Why is it important for companies to develop a disaster recovery plan?
To keep computer systems dust-free and dry
To specify access levels
To ensure employees know what to do when a threat emerges
To create a backup of all company data
What is one of the recommendations for maintaining computer systems in a company?
Consulting IT security experts regularly
Developing a disaster recovery plan
Keeping computer systems dust-free and dry
Using an uninterruptible power supply
Who should companies consult for advice and guidance on IT security?
Disaster recovery experts
Uninterruptible power supply vendors
IT security experts
Data backup service providers
What does the processor in a hardware-based encryption system contain to generate an encryption key?
A random password generator
A random number generator
A dedicated encryption software
A user's password database
Where does authentication take place in a hardware-based encryption system?
On the user's password
On the encrypted drive
On the hardware
Within the encryption software
What is enhanced by offloading encryption from the host system in a hardware-based encryption system?
Cost-effectiveness
Authentication
Performance
Security parameters
Where are safeguard keys and critical security parameters located in a hardware-based encryption system?
In the user's password
Within the host system
Within crypto-hardware
On the encrypted drive
What is a characteristic of encryption in a hardware-based encryption system regarding its application environments?
It is less effective in larger environments.
It is only effective in small environments.
It is cost-effective in medium and larger application environments.
It is always tied to a user's password.
How is encryption availability described in a hardware-based encryption system?
It is 'always off' until activated by the user.
It is 'always on' and tied to a specific device.
It is available only during business hours.
It is manually turned on by the system administrator.
What is a cold boot attack?
An attack that overheats a computer's CPU
A type of 'side channel' attack where an attacker with physical access to a computer performs a memory dump of the computer's RAM
A method of infecting a computer with a virus through email
A security measure to prevent unauthorized access to a computer
What does malicious code do?
Enhances the performance of a software system
Fixes security vulnerabilities in a system
Inserts advertisements into web pages
Causes undesired effects, security breaches, or damage to a system
What are brute force attacks?
Attacks that exploit hardware vulnerabilities
Attacks that use advanced algorithms to bypass encryption
Attacks consisting of submitting many passwords or phrases with the hope of eventually guessing a combination correctly
Attacks that target the physical components of a computer
What does software-based encryption use to encrypt data?
A) A unique hardware key
B) The user's password
C) A physical token
D) Biometric data
Software-based encryption is only as safe as what?
A) The encryption software's complexity
B) The user's computer
C) The strength of the internet connection
D) The physical security of the data center
What is a disadvantage of software-based encryption?
A) It does not require any updates
B) It is immune to brute force attacks
C) It is susceptible to brute force attacks
D) It is expensive in large applications
Which of the following is an advantage of software-based encryption?
A) It shares resources with other computer programs
B) It is cost-effective in small applications
C) It can only be implemented on one type of media
D) It requires a separate encryption device
Can software-based encryption be implemented on different types of media?
A) Yes, but only on optical media
B) No, it is restricted to USB drives
C) Yes, it can be implemented on all types of media
D) No, it only works on cloud storage
What is the purpose of firmware updates according to the text?
To change the physical components of the device
To install new hardware into the device
To enable the corresponding devices to operate efficiently and fix bugs for better security
To reduce the efficiency of the device
What needs to be installed to update a device's firmware?
A new device
An antivirus software
A hardware upgrade
An update
What is one of the advantages of updating to the most recent firmware according to the document?
It requires the device to be replaced with a new model.
It will degrade the device's performance over time.
It will optimise the device's performance.
It increases the need for expensive repairs.
How does firmware update contribute to the user experience of a device?
It limits the features available on the device.
It provides an enhanced user experience by adding new features.
It prevents users from interacting with the device.
It removes existing features to simplify the device.
What is a benefit of regular firmware updates mentioned in the material?
They increase the device's obsolescence.
They require frequent hardware upgrades.
They reduce the need for expensive repairs or bug fixes.
They complicate the operational instructions of the device.
