WorksheetsAIS Chapter 12: Confidentiality and Privacy Controls
Total questions: 20
Worksheet time: 10mins
Which of the following is not one of the basic actions that an organization must take to preserve the confidentiality of sensitive information?
Identification of information to be protected.
Backing up the information.
Controlling access to the information.
Training.
After the information that needs to be protected has been identified, what step should be completed next?
The information needs to be placed in a secure, central area.
The information needs to be encrypted.
The information needs to be classified in terms of its value to the organization.
The information needs to be depreciated.
Which type of software blocks outgoing messages containing key words or phrases associated with an organization's sensitive data?
Anti-virus software.
Data loss prevention software.
A digital watermark.
Information rights software.
Which type of software provides an additional layer of protection to sensitive information that is stored in digital format, offering the capability not only to limit access to specific files or documents but also to specify the actions that individuals who are granted access to that resource can perform?
Anti-virus software.
Data loss prevention software.
A digital watermark.
Information rights software.
The Bear Corporation uses a tool that embeds a code into all of its digital documents. It then scours the internet, searching for codes that it has embedded into its files. When Bear finds an embedded code on the internet, it knows that confidential information has been leaked. Bear then begins identifying how the information was leaked and who was involved with the leak. Bear is using
An information rights management software.
A data loss prevention software.
A digital watermark.
A stop leak software.
Which of the following is not one of the 10 internationally recognized best practices for protecting the privacy of customers' personal information?
Provide free credit report monitoring for customers.
Inform customers of the option to opt-out of data collection and use of their personal information.
Allow customers' browsers to decline to accept cookies.
Utilize controls to prevent unauthorized access to, and disclosure of, customers' information.
A client approached Paxton Uffe and said, "Paxton, I need for my customers to make payments online using credit cards, but I want to make sure that the credit card data isn't intercepted. What do you suggest?" Paxton responded, "The most effective solution is to implement
A data masking program.
A virtual private network.
A private cloud environment.
An encryption system with digital signatures.
Abbie Johnson is a programmer at Healtheast network. Abbie has recently developed a new computer program for Healtheast. As part of the testing process, Abbie needs to use realistic patients' data to ensure that the system is working properly. To protect privacy, management at Healtheast uses a program that replaces private patient information with fake values before sending the data to Abbie for testing. The program that replaces patient information with fake values is called
data encrypting
data masking
data wiping
data redacting
If an organization asks you to disclose your social security number, but fails to tell you about its privacy policies and practices, the organization has likely violated which of the Generally Accepted Privacy Principles?
Management
Notice
Choice and consent
Use and retention
If an organization asks you to disclose your date of birth and your address, but refuses to let you review or correct the information you provided, the organization has likely violated which of the Generally Accepted Privacy Principles?
Collection
Access
Security
Choice and consent
Which of the following is not true regarding virtual private networks (VPN)?
VPNs provide the functionality of a privately owned network using the Internet
Using VPN software to encrypt information while it is in transit over the Internet in effect creates private communication channels, often referred to as tunnels, which are accessible only to those parties possessing the appropriate encryption and decryption keys
It is more expensive to reconfigure VPNs to include new sites than it is to add or remove the corresponding physical connections in a privately owned network
The cost of the VPN software is much less than the cost of leasing or buying the infrastructure (telephone lines, satellite links, communications equipment, etc.) needed to create a privately owned secure communications network
All of the following are associated with asymmetric encryption except
speed
private keys
public keys
no need for key exchange
Text that was transformed into unreadable gibberish using encryption is called
plaintext
ciphertext
encryption text
private text
Identify one weakness of encryption below.
Encrypted packets cannot be examined by a firewall.
Encryption provides for both authentication and non-repudiation.
Encryption protects the privacy of information during transmission.
Encryption protects the confidentiality of information while in storage.
Which systems use the same key to encrypt communications and to decrypt communications?
Asymmetric encryption.
Symmetric encryption.
Hashing encryption.
Public key encryption
Information encrypted with the creator's private key that is used to authenticate the sender is called
asymmetric encryption.
digital certificate.
digital signature.
public key.
Which of the following is not one of the three important factors determining the strength of any encryption system?
Key length.
Policies for managing cryptographic keys.
Encryption algorithm.
Storage of digital signatures.
A process that takes plaintext of any length and transforms it into a short code is called
asymmetric encryption.
encryption.
hashing.
symmetric encryption.
What is the term for the process of converting encrypted data back into its original form?
Encryption
Decryption
Hashing
Encoding
What type of encryption uses different keys for encrypting and decrypting data?
Asymmetric encryption.
Symmetric encryption.
Hashing encryption.
Public key encryption
