Diagnostic Answers DS7-001–DS7-014
DS7-001 — A · pp. 209–211
Why: DMBOK defines Data Security around security policies/procedures and proper Authentication, Authorization, Access, Audit.
Distractors: B is too network-only; C is primarily Data Modeling & Design; D is records/content management.
Confusion pair: Data Security vs cybersecurity infrastructure.
DS7-002 — B · pp. 209–211
Why: legitimate business access is explicitly a requirement source alongside stakeholder, regulatory, proprietary, contractual needs.
Distractors: A/C are too narrow; D is one source, not the only source.
Pair: requirements vs technical-only thinking.
DS7-003 — C · p. 212
Why: Chapter 7 names risk reduction and business growth.
Distractors: A/B/D belong to adjacent goals or possible contexts, not the two stated drivers.
Pair: security drivers vs adjacent data goals.
DS7-004 — D · pp. 211, 214
Why: the chapter balances enabling appropriate access with preventing inappropriate access.
Distractors: A over-restricts; B invents a universal algorithm; C invents a single-application requirement.
Pair: secure access vs total restriction.
DS7-005 — A · p. 214
Why: reduce risk by reducing exposure directly targets sensitive-data proliferation, especially non-production.
Distractors: Proactive management, enterprise approach, and clear accountability are separate principles.
Pair: exposure reduction vs other principles.
DS7-006 — B · pp. 214–215
Why: an unpatched condition is a weakness/defect = Vulnerability.
Distractors: Threat is what may exploit it; risk classification concerns data sensitivity; entitlement concerns granted data scope.
Pair: Vulnerability vs Threat.
DS7-007 — C · p. 215
Why: malicious attachment is a potential offensive action/event = Threat.
Distractors: Vulnerability is the weakness enabling compromise; confidentiality/role assignment classify/control access.
Pair: Threat vs Vulnerability.
DS7-008 — D · p. 215
Why: frequency, damage, revenue effect, remediation/prevention cost, intent are risk-evaluation factors.
Distractors: confidentiality, regulatory family, and authorization profile do not evaluate likelihood/impact.
Pair: Risk vs classification.
DS7-009 — A · pp. 215–216
Why: CRD/HRD/MRD are example risk classifications tied to data sensitivity/attractiveness.
Distractors: not universal confidentiality levels, encryption keys, or audit types.
Pair: Risk classification vs Confidentiality.
DS7-010 — B · pp. 216–217
Why: enterprise modeling helps locate sensitive data and design comprehensive protection.
Distractors: it does not replace controls/security staff or encrypt automatically.
Pair: enterprise data model vs controls.
DS7-011 — C · pp. 216–217
Why: DMBOK calls for standard collaboration/sharing of regulations, threats, protection requirements at project commencement.
Distractors: A/D defer work; B gives Counsel a role that does not replace cross-functional design.
Pair: collaboration vs siloed work.
DS7-012 — D · p. 214
Why: Clear Accountability concerns explicit roles and chain of custody.
Distractors: Metadata-driven, collaboration, proactive management address different principles.
Pair: Accountability vs Collaboration.
DS7-013 — A · pp. 217–218
Why: Authentication validates identity.
Distractors: Authorization grants privileges; Access is actual use; Audit reviews evidence.
Pair: Authentication vs Authorization.
DS7-014 — B · pp. 217–218
Why: Authorization grants role-appropriate privileges.
Distractors: Authentication verifies identity; Audit evaluates; Monitoring observes/detects.
Pair: Authorization vs Authentication.