Skip to content

Diagnostic Answers DS7-043–DS7-056

DS7-043 — C · pp. 240–241

Why: data/classification-first design mapping roles = Role Assignment Grid.
Distractors: hierarchy starts people/workgroups; RACI maps accountability; segmentation is network control.
Pair: Role Grid vs Role Hierarchy.

DS7-044 — D · pp. 244–246

Why: no recorded link between training prerequisite and authorization means the control cannot be proven/audited.
Distractors: no evidence that classification/firewall is wrong; shared accounts worsen accountability.
Pair: Policy statement vs Auditable control.

DS7-045 — A · p. 248

Why: CRUD maps Create, Read, Update, Delete and sometimes Execute permissions between roles/processes and data.
Distractors: B/C unrelated; D is RACI.
Pair: CRUD/CRUDE vs RACI.

DS7-046 — B · p. 248

Why: delayed patching leaves a known exploitable vulnerability open; one compromise may enable wider attack.
Distractors: patching does not eliminate monitoring, guarantee performance, or change classification.
Pair: Immediate vs Periodic patching.

DS7-047 — C · p. 248

Why: Security Metadata should include security/confidentiality and regulatory classifications.
Distractors: structural names alone are insufficient; passwords are not ordinary Metadata; incident tickets are not classification Metadata.
Pair: Security Metadata vs generic Metadata.

DS7-048 — D · p. 249

Why: removing tracked changes/hidden comments/metadata before sharing = Document sanitization.
Distractors: masking alters displayed/data values; RBAC controls access; penetration testing probes vulnerabilities.
Pair: Metadata tracking vs sanitization.

DS7-049 — A · pp. 249–250

Why: Chapter 7 implementation/readiness stresses training, awareness testing, policy alignment, vendor requirements, and ongoing communication.
Distractors: tools do not replace behavior; policies should not be secret; tool counts alone are not meaningful metrics.
Pair: Security culture vs tool-only security.

DS7-050 — B · pp. 250–251

Why: operational control can transfer; accountability/liability for organization data remains.
Distractors: vendor does not automatically absorb liability; architecture ownership need not be outsourced; right-to-audit and SLA serve different purposes.
Pair: Outsourced control vs retained accountability.

DS7-051 — C · p. 251

Why: CRUD/CRUDE defines data-operation permissions; RACI defines broader accountability; lineage/custody tracks movement.
Distractors: A/B are controls without cross-org responsibility mapping; D is just an inventory.
Pair: CRUD/CRUDE vs RACI in outsourcing.

DS7-052 — D · pp. 251–252

Why: undefined firewall/server-access ownership is a shared-responsibility and custody/accountability gap.
Distractors: cloud does not make data public, eliminate classification, or remove organization policy responsibility.
Pair: Cloud shared responsibility vs unclear accountability.

DS7-053 — A · pp. 252–253

Why: Data Security architecture is the Enterprise Architecture component explaining how security satisfies business rules and external regulations.
Distractors: IP lists/malware signatures are narrow technical inventories; architecture does not replace Governance policy.
Pair: Security architecture vs technical inventory.

DS7-054 — B · pp. 253–254

Why: patch coverage tracked against a baseline can drive action and improvement.
Distractors: policy-term counts, dashboard colors, manual page counts lack security decision value.
Pair: Actionable vs Vanity metrics.

DS7-055 — C · pp. 253–255

Why: five groups = Implementation, Awareness, Data Protection, Security Incident, Confidential Data Proliferation.
Distractors: A resembles operations; B other data domains; D is Four A’s + Entitlement rather than metric families.
Pair: Metric groups vs Four A’s.

DS7-056 — D · p. 255

Why: more confidential copies create more protected locations and greater exposure even when encryption/access controls are strong.
Distractors: encryption does not erase copy exposure; IDS volume is different; technical strength does not remove proliferation risk.
Pair: Protection strength vs Proliferation exposure.

← Answers 029–042 · Coverage →