Tüm alıştırma soruları
2232 soru
An enterprise organization is establishing its formal data governance framework to satisfy regulatory compliance requirements. Match each data governance role on the left with its primary operational responsibility on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An enterprise compliance officer is reviewing legal responsibilities for handling sensitive user data and healthcare information across international and regional privacy mandates. Match each regulatory compliance role or entity designation on the left with its corresponding legal definition and operational scope on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A logistics firm is assigning operational responsibilities for its core database engine. A systems administrator is delegated the tasks of running daily backups, enforcing file permissions, and applying vendor security updates in accordance with established enterprise directives. Which data governance role BEST describes the function performed by the systems administrator?
A municipal public safety agency is establishing continuity metrics for its computer-aided dispatch (CAD) emergency response system following a Business Impact Analysis (BIA). Match each business continuity metric on the left with its corresponding operational definition on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An e-commerce merchant processes payment card transactions through its internal application servers and stores transaction history in an on-premises database. To align with Payment Card Industry Data Security Standard (PCI-DSS) requirements and minimize compliance audit costs, the chief information security officer (CISO) wants to reduce the overall scope of the Cardholder Data Environment (CDE). Which of the following technical controls will most effectively reduce the organization's PCI-DSS compliance scope?
A multinational online retail corporation is designing a automated data privacy lifecycle and governance framework for its customer analytics platform across international jurisdictions. Which of the following governance controls and privacy principles should the security architecture team implement to meet data protection obligations? (Select TWO).
Geçerli olan tümünü seçin
A biotechnology organization needs to share clinical trial data with an external analytics firm. To comply with privacy requirements, the security team must replace sensitive patient identifiers with non-sensitive placeholder values. The system must maintain an internal mapping database that allows authorized internal personnel to reverse the process when necessary, while ensuring external analysts cannot mathematically derive original identities from the placeholders alone. Which of the following privacy-enhancing techniques should the organization implement?
An international healthcare organization headquartered in the United States processes patient medical records for US citizens and manages service accounts for European Union residents within a public cloud environment. A recent compliance review reveals that cloud storage repositories containing sensitive records lack proper regulatory safeguards. Which of the following compliance actions must the organization implement to meet its legal obligations under HIPAA and GDPR? (Select TWO.)
Geçerli olan tümünü seçin
A regional financial institution conducts a Business Impact Analysis (BIA) for its core wire-transfer processing gateway. The assessment determines that to avoid regulatory non-compliance fines, the service must be fully operational and accessible within 3 hours following an unplanned outage. Additionally, the risk assessment establishes that the organization can tolerate a maximum of 5 minutes of lost transaction data updates. Which of the following correctly classifies these business continuity targets?
An enterprise organization is updating its global data governance standards to comply with privacy regulations. Match each data privacy control on the left with its corresponding operational implementation on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each business continuity and resiliency metric on the left with its corresponding operational impact definition on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
A regional hospital network is updating its data governance framework prior to deploying a new cloud-based electronic health records system. To align with data privacy regulations, the security steering committee must clearly separate administrative authority from technical execution responsibilities. Which of the following responsibilities is primarily assigned to the data owner?
A regional healthcare system is conducting a Business Impact Analysis (BIA) for its clinical Picture Archiving and Communication System (PACS). The operational team determines that the application must be fully restored and operational within 4 hours of an unplanned outage to avoid catastrophic disruption to surgical scheduling. Additionally, clinical governance rules mandate that the system must not lose more than 15 minutes of newly ingested radiology scan data during a disruption. Which of the following metric configurations correctly aligns with these BIA parameters?
An enterprise security architecture team is defining continuity metrics for a critical containerized payment gateway during a Business Impact Analysis (BIA). Executive leadership establishes that customer transaction records can tolerate a maximum data loss timeframe of minutes, and the payment gateway system must be fully restored and operational within hours following an uncontained infrastructure failure. Which of the following statements correctly align these operational requirements with business continuity metrics? (Select TWO.)
Geçerli olan tümünü seçin
A financial software company is formalizing its data governance roles to align with security frameworks and compliance standards. The security steering committee must separate technical operational management from executive business governance. Which of the following responsibilities fall directly under the role of the Data Custodian? (Select TWO.)
Geçerli olan tümünü seçin
A municipal smart-grid utility provider plans to share residential electricity consumption logs with an external research agency for energy forecasting analysis. To satisfy data privacy regulations, the dataset must prevent researchers from identifying individual customer accounts. However, the researchers must remain able to link distinct records belonging to the same household across separate quarterly files using a consistent, non-reversible surrogate key. Which of the following privacy-enhancing techniques should the security team implement?
A pharmaceutical manufacturing enterprise conducts a Business Impact Analysis (BIA) for its automated batch control system. The BIA determines that losing operational data generated within the last 30 minutes would cause severe regulatory non-compliance, whereas the application itself can remain offline for up to 8 hours before batch delivery schedules suffer unacceptable financial impacts. Which of the following sets of metrics accurately establishes the recovery criteria for this system?
A global telecommunications provider is updating its data governance framework and enterprise Data Loss Prevention (DLP) policy across cloud and on-premises environments. Match each data classification tier on the left with its corresponding mandatory technical and privacy handling control on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
Match each Business Impact Analysis (BIA) and business continuity metric on the left with its corresponding operational definition in an enterprise airport operations management system on the right.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
During a Business Impact Analysis (BIA), a regional logistics enterprise evaluates its real-time vehicle dispatch database. The analysis establishes that the enterprise can sustain a maximum of 15 minutes of unrecoverable data loss from ongoing transactions, while the service itself must be fully restored within 4 hours to avoid breaching contractual service level agreements. Which metrics correctly define the Recovery Point Objective (RPO) and Recovery Time Objective (RTO) for this database?