Diagnostic Answers DS7-015–DS7-028
DS7-015 — C · pp. 217–218
Why: Entitlement = sum total of data exposed by an authorization.
Distractors: access token is mechanism; role hierarchy organizes roles; risk classification concerns sensitivity.
Pair: Authorization vs Entitlement.
DS7-016 — D · pp. 217–218
Why: Audit reviews actions/evidence for compliance.
Distractors: Access = use; Authentication = identity; Authorization = grants.
Pair: Audit vs Monitoring.
DS7-017 — A · pp. 217–218
Why: immediate alert/interruption = Active monitoring.
Distractors: Passive = periodic; Audit = independent assurance; RBAC = access design.
Pair: Active vs Passive.
DS7-018 — B · p. 218
Why: weekly snapshots/trends against benchmark = Passive monitoring.
Distractors: Active is real-time; Authorization grants; penetration testing probes vulnerabilities.
Pair: Passive vs Active.
DS7-019 — C · p. 218
Why: Integrity means data remains whole and protected from improper alteration/deletion/addition.
Distractors: universal availability conflicts with access control; encryption is a technique; confidentiality level is separate.
Pair: Integrity vs Confidentiality.
DS7-020 — D · pp. 218–219
Why: different freely distributed public key and protected private key = Public-key encryption.
Distractors: Hash is verification representation; private-key uses same key; masking is different.
Pair: Private-key vs Public-key.
DS7-021 — A · pp. 219–220
Why: Persistent masking permanently changes the stored masked non-production copy.
Distractors: Dynamic preserves source; Passive monitoring and role hierarchy do not alter data.
Pair: Persistent vs Dynamic masking.
DS7-022 — B · p. 219
Why: transform while moving source → target = In-flight persistent masking.
Distractors: In-place changes same location; Dynamic changes display; encrypted search is separate.
Pair: In-flight vs In-place.
DS7-023 — C · pp. 219–220
Why: source stays full while user sees last four = Dynamic masking.
Distractors: Persistent changes stored copy; Key masking protects key relationships; Nulling removes values.
Pair: Dynamic vs Persistent.
DS7-024 — D · p. 220
Why: unique/repeatable masked keys preserve relational/key integrity across related data.
Distractors: not for search speed, universal reversibility, or identical keys.
Pair: Key masking vs ordinary randomization.
DS7-025 — A · pp. 225–226
Why: Confidentiality originates internally; Regulation externally.
Distractors: B is false; C reverses aggregation rules; D collapses distinct concepts.
Pair: Confidentiality vs Regulation.
DS7-026 — B · pp. 225–226
Why: Regulation uses “allowed-to-know”; Confidentiality uses “need-to-know.”
Distractors: A is the internal rule; C/D are not DMBOK phrases.
Pair: Need-to-know vs Allowed-to-know.
DS7-027 — C · pp. 225–226
Why: one highest confidentiality level + all applicable regulatory categories.
Distractors: regulations do not collapse to one; confidentiality is not averaged; regulation does not erase confidentiality.
Pair: Confidentiality aggregation vs Regulatory aggregation.
DS7-028 — D · p. 226
Why: Registered Confidential is the highest example level and includes signed legal responsibility.
Distractors: Internal Use/Confidential are less restrictive; Restricted is need-to-know/clearance but not the described signed responsibility.
Pair: Restricted vs Registered Confidential.