Practice Questions DS7-043–DS7-056
For each: Your answer: ___ · Confidence: _/5 · Time: ___ sec · Review: ☐
DS7-043 — Role Grid vs Hierarchy · Difficult · Distinguish
A security team starts with data confidentiality/regulatory categories and maps which roles may access each combination. Which method is this? - A. Role hierarchy. - B. RACI matrix. - C. Role assignment grid. - D. Network segmentation.
DS7-044 — Auditable Controls · Difficult · Apply
A policy says employees must complete privacy training before accessing PII, but no record links training completion to authorization. What is the most important weakness? - A. Confidentiality level too high. - B. Need more shared accounts. - C. Firewall necessarily misconfigured. - D. Control is not auditable because no evidence proves the prerequisite was met.
DS7-045 — CRUD/CRUDE · Standard · Recall
What does a CRUD matrix map? - A. Create, Read, Update, Delete permissions between data and processes/roles; some versions add Execute. - B. Risk, Audit, Confidentiality, Integrity requirements. - C. Only backup schedules. - D. Responsible, Accountable, Consulted, Informed.
DS7-046 — Patch Deployment · Standard · Apply
Why does Chapter 7 favor immediate security patch deployment rather than user delay to a later maintenance cycle? - A. Patches eliminate need for monitoring. - B. Known vulnerability can be exploited before the later cycle; one compromised machine can enable a wider attack. - C. Every patch improves database performance. - D. Patching changes confidentiality classifications.
DS7-047 — Security Metadata · Standard · Understand
What should a Metadata repository contain to support Data Security? - A. Only table/column names. - B. Only employee passwords. - C. Security and regulatory classifications for data. - D. Only incident-response tickets.
DS7-048 — Document Sanitization · Difficult · Apply
Before sharing a contract externally, a team removes tracked-change history and hidden comments that could reveal negotiations. Which technique is this? - A. Dynamic masking. - B. Role-based access. - C. Penetration testing. - D. Document sanitization.
DS7-049 — Readiness · Standard · Understand
Which practice is part of Chapter 7's readiness/cultural implementation guidance? - A. Train employees, test awareness, align policies, set vendor security requirements, maintain ongoing communication. - B. Rely on tools so employee behavior no longer matters. - C. Keep policies secret. - D. Measure only number of installed security products.
DS7-050 — Outsourcing · Standard · Apply
A vendor operates a company's data platform. Which statement best reflects Chapter 7? - A. Vendor automatically assumes all legal accountability. - B. Operational control can transfer, but organization retains accountability/liability for protecting its data. - C. Architecture ownership should always be outsourced. - D. Right-to-audit is unnecessary once an SLA exists.
DS7-051 — RACI & Chain of Custody · Difficult · Apply
In an outsourced environment, which pair best clarifies data-operation responsibilities and broader accountability? - A. Only password standards and encryption keys. - B. Only firewall and IDS. - C. CRUD/CRUDE matrices plus RACI, supported by lineage/chain-of-custody tracking. - D. Only vendor list.
DS7-052 — Cloud Shared Responsibility · Difficult · Apply
A cloud provider delivers software over the web, but neither party has defined who owns firewall configuration or server access rights. What is the key governance problem? - A. Data must be public. - B. Stop classifying data. - C. Only provider needs security policy. - D. Shared responsibility, chain of custody, ownership, and custodianship are not explicitly defined.
DS7-053 — Security Architecture · Standard · Understand
What is Data Security architecture in Chapter 7? - A. Enterprise Architecture component describing how data security is implemented to satisfy business rules and external regulations. - B. Only network IP-address list. - C. Replacement for Data Governance policy. - D. Only malware signatures.
DS7-054 — Metrics · Standard · Apply
Which metric best follows the guidance to use actionable, baselined measures? - A. Decorative count of security terms in policies. - B. Percentage of enterprise computers with current security patches, tracked from a baseline over time. - C. Number of dashboard colors. - D. Total pages in security manuals with no target/interpretation.
DS7-055 — Metric Groups · Difficult · Recall
Which set matches the five Chapter 7 metric groupings? - A. Availability, Performance, Capacity, Recovery, Cost. - B. Quality, Metadata, Modeling, Architecture, Retention. - C. Implementation, Awareness, Data Protection, Security Incident, Confidential Data Proliferation. - D. Authentication, Authorization, Access, Audit, Entitlement.
DS7-056 — Confidential Data Proliferation · Expert-Discrimination · Apply
An organization has excellent encryption/access controls but keeps creating confidential Production copies across analytics sandboxes and vendor environments. Which problem remains directly relevant? - A. Only password complexity because encryption eliminates copy risk. - B. Only IDS alert volume because copies are not a concern if encrypted. - C. Only business-growth metrics because security is technically strong. - D. Confidential Data Proliferation: more copies create more locations that must remain protected and increase exposure risk.