Practice Questions DS7-015–DS7-028
For each: Your answer: ___ · Confidence: _/5 · Time: ___ sec · Review: ☐
DS7-015 — Entitlement · Standard · Distinguish
A manager approves one authorization that exposes customer name, address, account number, and purchase history. What does Chapter 7 call the complete set of exposed data elements? - A. Access token. - B. Role hierarchy. - C. Entitlement. - D. Risk classification.
DS7-016 — Audit · Standard · Apply
Security staff review logs and documents to validate that user activity conforms to regulation, policy, and standards, then publish findings. Which Four-A process is this? - A. Access. - B. Authentication. - C. Authorization. - D. Audit.
DS7-017 — Active Monitoring · Foundational · Distinguish
A sensitive financial system alerts an administrator immediately and can interrupt a suspicious transaction. What type of monitoring is this? - A. Active monitoring. - B. Passive monitoring. - C. Formal audit. - D. Role-based access.
DS7-018 — Passive Monitoring · Standard · Distinguish
A system takes weekly snapshots of access behavior and compares trends against a benchmark. What is this? - A. Active monitoring. - B. Passive monitoring. - C. Authorization. - D. Penetration testing.
DS7-019 — Data Integrity · Standard · Understand
In Chapter 7's security context, what does data integrity mean? - A. The data is available to every employee. - B. The data is always encrypted. - C. The data remains whole and protected from improper alteration, deletion, or addition. - D. The data has only one confidentiality level.
DS7-020 — Encryption · Difficult · Distinguish
A sender uses a freely available key, while the receiver uses a different private key to reveal the original data. Which method does Chapter 7 describe? - A. Hashing. - B. Private-key encryption. - C. Dynamic masking. - D. Public-key encryption.
DS7-021 — Persistent Masking · Standard · Apply
A team must create a non-production copy in which sensitive values are permanently and irreversibly altered but relationships remain usable for testing. Which approach fits best? - A. Persistent data masking. - B. Dynamic data masking. - C. Passive monitoring. - D. Role hierarchy.
DS7-022 — In-Flight Masking · Standard · Distinguish
Sensitive Production data is masked while moving to a test environment so no intermediate unmasked copy is left. What type is this? - A. In-place persistent masking. - B. In-flight persistent masking. - C. Dynamic masking. - D. Encryption-only search.
DS7-023 — Dynamic Masking · Standard · Apply
The database stores a full national ID, but a call-center user sees only the last four digits. The stored value remains unchanged. What is this? - A. Persistent masking. - B. Key masking. - C. Dynamic data masking. - D. Nulling.
DS7-024 — Key Masking · Difficult · Understand
Why does Chapter 7 say key masking must be unique and repeatable? - A. So encrypted data can be searched faster. - B. So masking can be reversed by all users. - C. So every masked key looks identical. - D. So relationships and integrity around key fields remain valid across related data.
DS7-025 — Confidentiality vs Regulation · Foundational · Distinguish
Which statement correctly distinguishes confidentiality restrictions from regulatory restrictions? - A. Confidentiality originates internally; regulatory restrictions originate externally. - B. Confidentiality is always legal; regulation is always optional. - C. Confidentiality categories are additive while regulations use only the highest level. - D. They are the same concept with different names.
DS7-026 — Need-to-Know vs Allowed-to-Know · Standard · Distinguish
Which phrase does Chapter 7 associate with regulatory information sharing? - A. Need-to-know. - B. Allowed-to-know. - C. Public-by-default. - D. Owner-to-know.
DS7-027 — Aggregation Rules · Difficult · Apply
A report contains one Restricted Confidential field and data governed by three separate regulatory categories. How should protections be determined? - A. Apply only the single strictest regulatory category. - B. Average confidentiality levels and choose the middle one. - C. Use one confidentiality level based on the most sensitive item and apply all three regulatory categories. - D. Ignore confidentiality once regulation applies.
DS7-028 — Confidentiality Levels · Standard · Recall
Which Chapter 7 confidentiality level describes information so sensitive that anyone accessing it must sign a legal agreement and assume responsibility for secrecy? - A. Internal use only. - B. Confidential. - C. Restricted confidential. - D. Registered confidential.