Skip to content

Rapid Recall Answer Key 01–23

Use only after attempting retrieval. Full credit requires the deciding distinction, not just a familiar word.

  1. Data Security: planning, development, execution of policies/procedures providing proper Authentication, Authorization, Access, and Audit of data/information assets.
  2. Requirement sources: stakeholder/business needs; government regulation; proprietary/confidentiality concerns; legitimate access; contracts/industry obligations.
  3. Drivers: reduce/manage risk and support business growth while satisfying obligations and legitimate use.
  4. Goals: enable appropriate access; protect confidentiality/integrity and sensitive/regulated data; make controls monitorable/auditable/compliant.
  5. Guiding principles: align security to business need/risk; reduce exposure; enterprise consistency; clear accountability/chain of custody; collaboration; proactive management/improvement. Use Artifact 01 wording if memorizing exact labels.
  6. Vulnerability: weakness/defect that can be exploited or contribute to loss.
  7. Threat: potential adverse/offensive action/event that may exploit a vulnerability.
  8. Risk: evaluated possibility of loss using likelihood/probability + impact/cost; factors include asset sensitivity/value, threat likelihood, vulnerability/exposure, business/financial/legal/reputation damage, repair/prevention cost, intent.
  9. CRD/HRD/MRD: example Critical/High/Moderate Risk Data classifications for sensitivity/attractiveness; not the confidentiality hierarchy.
  10. Enterprise data model: helps locate sensitive entities/attributes/relationships across systems so classification/protection can be designed consistently.
  11. Four A’s: Authentication, Authorization, Access, Audit.
  12. Entitlement: full data/capability scope exposed by an Authorization/access decision.
  13. Active: real-time detect/alert/interrupt. Passive: periodic snapshots/trend comparison.
  14. Integrity: protection from improper/unauthorized alteration, deletion, addition, corruption.
  15. Hash: mathematical integrity/verification representation. Private/symmetric: same shared key encrypts/decrypts. Public/asymmetric: paired public/private keys.
  16. Persistent masking: permanently changes stored masked copy. Dynamic: source remains unchanged; visible representation changes.
  17. In-flight: mask while moving source → target. In-place: overwrite/alter data in same location.
  18. Methods include substitution, shuffling, temporal/date variance, value/numeric variance, nulling/deletion, randomization, encryption-based masking, expression, key masking. Be able to name at least five.
  19. Key masking: preserve uniqueness and repeatability/relationship integrity so joins remain consistent.
  20. Backdoor: hidden/bypass path; bot/zombie: remotely controlled compromised machine; firewall: traffic filtering boundary; DMZ: separated zone for exposed services; key logger: captures keystrokes/credentials; penetration testing: authorized probing for exploitable weaknesses; VPN: protected network tunnel.
  21. Surfaces: facility, device, credential, electronic communication.
  22. SSO: one successful Authentication reused across approved resources/services.
  23. Multiple-factor: more than one independent identification factor/type used to establish identity.

Source boundary: DAMA-DMBOK2 Revised, Chapter 7, pp. 209–256.

← Recall 24–45 · Key 24–45 →