Practice Questions DS7-001–DS7-014
For each: Your answer: ___ · Confidence: _/5 · Time: ___ sec · Review: ☐
DS7-001 — Definition · Foundational · Recall
Which statement best matches Chapter 7's definition of Data Security? - A. Planning, developing, and executing security policies and procedures to provide proper authentication, authorization, access, and auditing of data and information assets. - B. Designing only network firewalls and intrusion-prevention devices. - C. Creating conceptual and logical data models for sensitive information. - D. Managing records retention schedules and legal holds.
DS7-002 — Requirement Sources · Foundational · Recall
Which item is one of Chapter 7's stated sources of data-security requirements? - A. Only technical limitations of the DBMS. - B. Legitimate business access needs. - C. Only the preferences of the security administrator. - D. Only government regulation.
DS7-003 — Business Drivers · Foundational · Recall
What two primary business drivers does Chapter 7 identify for Data Security? - A. Data quality and metadata reuse. - B. Storage efficiency and database performance. - C. Risk reduction and business growth. - D. Application modernization and cloud migration.
DS7-004 — Goals · Standard · Understand
Which statement is one of the three Chapter 7 goals? - A. Eliminate all external access to enterprise data. - B. Require every data set to use the same encryption algorithm. - C. Move all sensitive data into a single application. - D. Enable appropriate access while preventing inappropriate access to enterprise data assets.
DS7-005 — Guiding Principles · Foundational · Recall
Which Chapter 7 principle says sensitive/confidential data should be minimized, especially in non-production environments? - A. Reduce risk by reducing exposure. - B. Proactive management. - C. Enterprise approach. - D. Clear accountability.
DS7-006 — Vulnerability vs Threat · Standard · Distinguish
A server is missing a critical security patch. In Chapter 7 terminology, what is the missing patch condition? - A. A threat. - B. A vulnerability. - C. A risk classification. - D. An entitlement.
DS7-007 — Threat · Standard · Distinguish
A malicious email attachment is sent to employees in hopes that someone opens it. What is it in Chapter 7 terminology? - A. A vulnerability. - B. A confidentiality level. - C. A threat. - D. A role assignment.
DS7-008 — Risk · Difficult · Apply
A team estimates how often an attack may occur, the damage each occurrence could cause, revenue impact, remediation cost, prevention cost, and attacker intent. What is the team assessing? - A. A confidentiality classification. - B. A regulatory family. - C. An authorization profile. - D. Risk.
DS7-009 — Risk Classifications · Foundational · Recall
What do CRD, HRD, and MRD represent in Chapter 7? - A. Examples of risk classifications for data sensitivity and attractiveness to misuse. - B. Three confidentiality levels required by every organization. - C. Three types of encryption keys. - D. Three types of security audits.
DS7-010 — Security Organization · Foundational · Understand
Why does Chapter 7 emphasize an enterprise data model in security work? - A. It replaces the need for access controls. - B. It helps locate and identify sensitive data so a comprehensive protection program can be designed. - C. It automatically encrypts classified data. - D. It removes the need for Information Security staff.
DS7-011 — Collaboration · Standard · Apply
A new application project begins with no process for Data Management and Information Security to share regulatory and protection requirements. What would Chapter 7 most strongly recommend? - A. Let each group discover the requirements independently after deployment. - B. Have only Corporate Counsel define technical controls. - C. Establish a standard procedure for the groups to share regulations, threats, and protection requirements at project commencement. - D. Defer security work until testing.
DS7-012 — Chain of Custody · Standard · Understand
Which guiding principle is most directly concerned with clearly defined roles and the chain of custody for data across organizations and roles? - A. Metadata-driven. - B. Collaboration. - C. Proactive management. - D. Clear accountability.
DS7-013 — Authentication · Foundational · Recall
Which security process answers, “Is this user really who they claim to be?” - A. Authentication. - B. Authorization. - C. Access. - D. Audit.
DS7-014 — Authorization · Foundational · Recall
Which process grants an individual privileges to access specific views of data appropriate to a role? - A. Authentication. - B. Authorization. - C. Audit. - D. Monitoring.