Wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

AIS Chapter 12: Confidentiality and Privacy Controls

Total questions: 20

Worksheet time: 10mins

Name
Class
Date
1.

Which of the following is not one of the basic actions that an organization must take to preserve the confidentiality of sensitive information?

a)

Identification of information to be protected.

b)

Backing up the information.

c)

Controlling access to the information.

d)

Training.

2.

After the information that needs to be protected has been identified, what step should be completed next?

a)

The information needs to be placed in a secure, central area.

b)

The information needs to be encrypted.

c)

The information needs to be classified in terms of its value to the organization.

d)

The information needs to be depreciated.

3.

Which type of software blocks outgoing messages containing key words or phrases associated with an organization's sensitive data?

a)

Anti-virus software.

b)

Data loss prevention software.

c)

A digital watermark.

d)

Information rights software.

4.

Which type of software provides an additional layer of protection to sensitive information that is stored in digital format, offering the capability not only to limit access to specific files or documents but also to specify the actions that individuals who are granted access to that resource can perform?

a)

Anti-virus software.

b)

Data loss prevention software.

c)

A digital watermark.

d)

Information rights software.

5.

The Bear Corporation uses a tool that embeds a code into all of its digital documents. It then scours the internet, searching for codes that it has embedded into its files. When Bear finds an embedded code on the internet, it knows that confidential information has been leaked. Bear then begins identifying how the information was leaked and who was involved with the leak. Bear is using

a)

An information rights management software.

b)

A data loss prevention software.

c)

A digital watermark.

d)

A stop leak software.

6.

Which of the following is not one of the 10 internationally recognized best practices for protecting the privacy of customers' personal information?

a)

Provide free credit report monitoring for customers.

b)

Inform customers of the option to opt-out of data collection and use of their personal information.

c)

Allow customers' browsers to decline to accept cookies.

d)

Utilize controls to prevent unauthorized access to, and disclosure of, customers' information.

7.

A client approached Paxton Uffe and said, "Paxton, I need for my customers to make payments online using credit cards, but I want to make sure that the credit card data isn't intercepted. What do you suggest?" Paxton responded, "The most effective solution is to implement

a)

A data masking program.

b)

A virtual private network.

c)

A private cloud environment.

d)

An encryption system with digital signatures.

8.

Abbie Johnson is a programmer at Healtheast network. Abbie has recently developed a new computer program for Healtheast. As part of the testing process, Abbie needs to use realistic patients' data to ensure that the system is working properly. To protect privacy, management at Healtheast uses a program that replaces private patient information with fake values before sending the data to Abbie for testing. The program that replaces patient information with fake values is called

a)

data encrypting

b)

data masking

c)

data wiping

d)

data redacting

9.

If an organization asks you to disclose your social security number, but fails to tell you about its privacy policies and practices, the organization has likely violated which of the Generally Accepted Privacy Principles?

a)

Management

b)

Notice

c)

Choice and consent

d)

Use and retention

10.

If an organization asks you to disclose your date of birth and your address, but refuses to let you review or correct the information you provided, the organization has likely violated which of the Generally Accepted Privacy Principles?

a)

Collection

b)

Access

c)

Security

d)

Choice and consent

11.

Which of the following is not true regarding virtual private networks (VPN)?

a)

VPNs provide the functionality of a privately owned network using the Internet

b)

Using VPN software to encrypt information while it is in transit over the Internet in effect creates private communication channels, often referred to as tunnels, which are accessible only to those parties possessing the appropriate encryption and decryption keys

c)

It is more expensive to reconfigure VPNs to include new sites than it is to add or remove the corresponding physical connections in a privately owned network

d)

The cost of the VPN software is much less than the cost of leasing or buying the infrastructure (telephone lines, satellite links, communications equipment, etc.) needed to create a privately owned secure communications network

12.

All of the following are associated with asymmetric encryption except

a)

speed

b)

private keys

c)

public keys

d)

no need for key exchange

13.

Text that was transformed into unreadable gibberish using encryption is called

a)

plaintext

b)

ciphertext

c)

encryption text

d)

private text

14.

Identify one weakness of encryption below.

a)

Encrypted packets cannot be examined by a firewall.

b)

Encryption provides for both authentication and non-repudiation.

c)

Encryption protects the privacy of information during transmission.

d)

Encryption protects the confidentiality of information while in storage.

15.

Which systems use the same key to encrypt communications and to decrypt communications?

a)

Asymmetric encryption.

b)

Symmetric encryption.

c)

Hashing encryption.

d)

Public key encryption

16.

Information encrypted with the creator's private key that is used to authenticate the sender is called

a)

asymmetric encryption.

b)

digital certificate.

c)

digital signature.

d)

public key.

17.

Which of the following is not one of the three important factors determining the strength of any encryption system?

a)

Key length.

b)

Policies for managing cryptographic keys.

c)

Encryption algorithm.

d)

Storage of digital signatures.

18.

A process that takes plaintext of any length and transforms it into a short code is called

a)

asymmetric encryption.

b)

encryption.

c)

hashing.

d)

symmetric encryption.

19.

What is the term for the process of converting encrypted data back into its original form?

a)

Encryption

b)

Decryption

c)

Hashing

d)

Encoding

20.

What type of encryption uses different keys for encrypting and decrypting data?

a)

Asymmetric encryption.

b)

Symmetric encryption.

c)

Hashing encryption.

d)

Public key encryption