Domain 2: (Asset Security) Flashcards

1
Q

What is the data lifecycle steps?

A

Create
Store
Use
Share
Archive
Destroy

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

What are the data security controls?

A

Marking
Labeling
Handling
Classification
Destruction
Record retention

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

What is the data destruction methods?

A

Erasing
Clearing
Purging
Degaussing
Destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

What creates a strong magnetic field that erases data on a media?

A

Degaussing

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

What is the final stage in the lifecycle of media and is the most secured method for sanitization?

A

Destruction

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What are the four levels of data classification for Non-gov’t (public) orgs?

A

(Class 0) Public
(Class 1) Sensitive
(Class 2) Private
(Class 3) Confidential/Proprietary

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

What role represents someone who is usually a member of senior management and who can delegate some day-to-day duties pertaining to data ownership/management?

A

Data owner

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

What role is usually someone in the IT dept and does not decide what controls are needed but implements controls for the data owner?

A

Data custodian

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Who is responsible for granting appropriate access to personnel?

A

Data Admins

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

What role owns the assets or system that processes sensitive data and associated security plans?

A

Asset Owners

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What person is someone who processes personal data soley on behalf of the data controller?

A

Data processer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

What person is someone who processes personal data solely on behalf of the data controller?

A

Data processer

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

Who is the person or entity that controls the processing of data?

A

data controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

Who restricts data transfers to countries outside the EU?

A

GDPR

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

What represents the process of removing all relevant data so that it is impossible to identify original subject or person?

A

Anonymization

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What represent the process of using pseudonyms to represent other data, when you need information but what to mask the identity of your data?

A

Pseudonymization

17
Q

What is the timeline required for an org or entity to notify a data breach?

A

72 hours