Tüm alıştırma soruları

2232 soru

Soru 2221Soru

A municipal water authority completes a Business Impact Analysis (BIA) for its critical SCADA telemetry database and central monitoring system. The BIA establishes that regulatory compliance permits a maximum data loss threshold of 15 minutes of historical sensor readings, while total system downtime before severe operational disruption occurs must not exceed 4 hours. Which of the following statements accurately interpret these business continuity metrics? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: The Recovery Point Objective (RPO) for the SCADA telemetry database is 15 minutes.; The Recovery Time Objective (RTO) for the central monitoring system is 4 hours.

Cevap

The statement specifying an RPO of 15 minutes for the telemetry database and the statement specifying an RTO of 4 hours for the central monitoring system are both correct.
The BIA defines two distinct metric constraints: maximum allowable data loss (15 minutes), which directly represents the Recovery Point Objective (RPO), and maximum allowable system downtime (4 hours), which directly represents the Recovery Time Objective (RTO). Identifying these two correctly satisfies both parts of the BIA requirement.

Adım Adım Çözüm

1
Analyze the business metric for data loss tolerance.
The requirement allows at most 15 minutes of sensor data loss, which maps directly to the Recovery Point Objective (RPO).
RPO defines the maximum tolerable age of unrecovered data resulting from an outage.
2
Analyze the business metric for system outage duration tolerance.
The requirement limits total system downtime to 4 hours, which maps directly to the Recovery Time Objective (RTO).
RTO defines the maximum acceptable duration of time system operations can be offline.
3
Evaluate candidate options against RPO and RTO definitions and control categories.
Statements designating 15 minutes as RPO and 4 hours as RTO are accurate. Statements swapping RTO/RPO or misclassifying redundancy as a detective control are incorrect.
Correct mapping ensures alignment between BIA metrics and recovery implementation plans.

Anahtar Kavram

Distinction between Recovery Point Objective (RPO) and Recovery Time Objective (RTO) in Business Impact Analysis
Soru 2222Soru

A specialized pharmaceutical research firm is establishing its enterprise data governance framework for clinical trial data stored in a cloud repository. A database administrator has been assigned the daily responsibility of configuring access control lists, managing data encryption at rest, performing scheduled system backups, and ensuring the technical integrity of the storage environment based on policies defined by business executives. Which data governance role best describes the operational duties assigned to this database administrator?

Cevabı ve açıklamayı göster

Cevap: Data custodian

Cevap

The role that best describes the database administrator's operational duties is the Data Custodian.
The data custodian is responsible for operational and technical implementation of security controls, including performing backups, configuring technical permissions, maintaining system integrity, and implementing data protection mechanisms like encryption according to directives set by the data owner.

Adım Adım Çözüm

1
Analyze the administrative duties described in the scenario.
The tasks involve configuring technical access controls, applying encryption, running backups, and maintaining storage infrastructure integrity.
Identifying whether the responsibilities are technical/operational versus strategic/executive is key to assigning the correct governance role.
2
Map the identified technical duties to standardized CompTIA Security+ data governance roles.
The individual implementing technical controls and maintaining storage assets under business policy directives is acting as a Data Custodian.
Data custodians handle hands-on system administration and technical enforcement of data protection policies.

Anahtar Kavram

Data Governance Roles (Data Owner vs. Data Custodian)
Soru 2223Soru

During a Business Impact Analysis (BIA) for a national retail organization's cloud-hosted Point-of-Sale (POS) transaction engine, executive leadership establishes that an operational disruption exceeding 44 hours would cause irreversible financial loss and regulatory non-compliance. In response, the cybersecurity team configures failover procedures to restore transaction processing capabilities within 22 hours of an outage. Which of the following metrics is represented by the 44-hour threshold?

Cevabı ve açıklamayı göster

Cevap: Maximum Tolerable Downtime (MTD)

Cevap

Maximum Tolerable Downtime (MTD)
Maximum Tolerable Downtime (MTD) is the maximum period of time that an enterprise service or process can be unavailable without causing irreparable harm to the organization. In this scenario, exceeding 44 hours triggers irreversible damage, making 44 hours the MTD.

Adım Adım Çözüm

1
Analyze the stem requirements and time thresholds
Identified two time periods: a 44-hour threshold beyond which irreversible business damage occurs, and a 22-hour target for service restoration.
BIA metrics separate total allowable outage time from tactical technical recovery goals.
2
Differentiate between business limits and IT recovery targets
The 44-hour mark represents the maximum duration the business process can be down before catastrophic impact (MTD), while the 22-hour goal is the targeted restoration time (RTO).
RTO must always be scheduled within the window of the MTD to ensure business viability (RTOMTDRTO \le MTD).

Anahtar Kavram

Business Impact Analysis Metrics: MTD vs RTO
Soru 2224Soru

A connected vehicle enterprise is updating its privacy engineering controls across its telemetry ingestion pipeline, billing service, and customer support portal. Match each privacy-enhancing technology on the left with its correct operational implementation on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Pseudonymization
Tokenization
Dynamic Data Masking
Anonymization

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Pseudonymization matches with replacing identifiers using separate secure keys for reversible correlation; Tokenization matches with exchanging payment card data for surrogate vault tokens; Dynamic Data Masking matches with real-time on-screen obfuscation based on user roles; and Anonymization matches with permanently stripping identifiers to prevent re-identification.
Each technology corresponds to a distinct privacy mechanism: Pseudonymization replaces direct identifiers with reversible keys stored in a separate system; Tokenization substitutes sensitive data with non-sensitive surrogate tokens using a secure vault; Dynamic Data Masking alters displayed data at runtime for unauthorized roles while preserving the underlying storage; and Anonymization permanently removes all identifiable traits so re-identification is impossible.

Adım Adım Çözüm

1
Analyze Pseudonymization requirements.
Identified that pseudonymization keeps data linked via a separate key, allowing reversible identification under strict access controls.
Pseudonymization protects privacy while maintaining data utility for authorized analysis.
2
Evaluate Tokenization characteristics.
Matched tokenization with substituting sensitive financial identifiers with random non-sensitive tokens managed via a vault.
Tokenization removes credit card numbers from application storage and downstream logging environments.
3
Differentiate Dynamic Data Masking from storage encryption.
Matched masking with real-time presentation obfuscation without altering underlying database values.
Masking enforces role-based view restrictions for personnel who do not need full data access.
4
Verify Anonymization irreversibility.
Matched anonymization with irreversible removal of identifying links across datasets.
Anonymized data is no longer subject to regulatory privacy constraints once re-identification is rendered impossible.

Anahtar Kavram

Privacy-Enhancing Technologies and Technical Privacy Controls
Tahmini Süre:1m 30s
Soru 2225Soru

A multinational logistics company is formalizing its enterprise data governance structure to align with international privacy regulations. During the implementation phase, executive leadership must designate the specific role responsible for defining data sensitivity classifications, establishing access approval policies, and approving retention and destruction timelines for customer transport records. Which of the following roles holds ultimate business accountability for making these governance decisions?

Cevabı ve açıklamayı göster

Cevap: Data owner

Cevap

The data owner is the role accountable for establishing classification rules, access governance policies, and retention requirements.
The data owner is the individual or entity holding ultimate business authority over a dataset. They determine data classification tiers, specify access permissions, mandate encryption standards, and set retention policy guidelines.

Adım Adım Çözüm

1
Analyze the organizational scenario requirements
Identified tasks: defining classification levels, establishing access approval rules, and approving retention/destruction schedules.
Governance tasks require identifying the role with strategic governance authority rather than operational maintenance duties.
2
Differentiate between data ownership and technical administration roles
The data owner holds ultimate business responsibility for data assets, whereas custodians handle technical enforcement.
CompTIA Security+ governance principles assign data asset classification authority explicitly to data owners.

Anahtar Kavram

Data Owner vs Data Custodian Responsibilities
Soru 2226Soru

A smart home technology platform is updating its data governance framework to comply with international privacy regulations regarding customer telemetry and voice interaction logs stored in cloud repositories. Which of the following actions correctly align with standard data governance roles and privacy control implementations? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: The business unit leader functioning as the data owner defines data classification levels and determines access requirements based on organizational risk.

Cevap

The correct statements are that the business unit leader functioning as the data owner defines classification levels and determines access requirements, and that pseudonymization replaces direct identifiers with tokens while preserving the capability to re-identify data using a separate secure key.
Data owners are business executives responsible for defining data sensitivity classifications and determining who receives access to data assets under their purview. Additionally, pseudonymization is a privacy technique that substitutes identity fields with pseudonyms or tokens while storing mapping keys separately, allowing legitimate re-identification under controlled privacy conditions.

Adım Adım Çözüm

1
Analyze data governance roles (Owner vs. Custodian).
Identify that the business data owner establishes data classification and access policy, while the data custodian enforces operational controls and technical administration.
Clear segregation between strategic data ownership and technical data custody ensures proper oversight and risk management.
2
Evaluate privacy-enhancing technology definitions (Pseudonymization vs. Masking/Anonymization).
Verify that pseudonymization allows reversible linking using a distinct key, whereas masking is an obfuscation control that does not equate to full mathematical anonymization.
Understanding the technical distinctions between data protection mechanisms is necessary to meet specific privacy regulation standards.

Anahtar Kavram

Data Governance Roles and Privacy-Enhancing Technologies
Soru 2227Soru

An online travel reservation platform is updating its data governance framework to comply with international privacy mandates. The database administration team is responsible for configuring encryption at rest, managing daily database backups, and maintaining schema performance for stored customer passport records. However, executive management must formally designate the individual accountable for determining the data classification tier, defining regulatory retention periods, and authorizing access rights to this sensitive dataset. Which of the following roles is directly responsible for establishing these governance policies?

Cevabı ve açıklamayı göster

Cevap: Data owner

Cevap

The data owner is the role responsible for establishing classification levels, determining retention periods, and approving access authorization policies for the dataset.
The data owner is the business entity or manager directly accountable for a specific dataset. They determine data classification tiers, specify retention requirements according to business and legal needs, and authorize who should be granted access permissions. Technical roles enforce these directives once established.

Adım Adım Çözüm

1
Analyze the operational responsibilities described in the scenario
The scenario distinguishes between technical management (configuring encryption, managing backups, maintaining schemas) and policy governance (classifying data, setting retention policies, approving access).
CompTIA Security+ objectives separate technical implementation roles from business governance and accountability roles.
2
Evaluate the role accountable for policy-level data decisions
The data owner (often a department head or business unit manager) holds ultimate accountability for the data asset, including determining classification levels, defining lifecycle policies, and granting access.
Data owners understand the business impact and legal requirements of the specific dataset they oversee.
3
Differentiate the data owner from technical custodians and administrative roles
Data custodians handle technical execution and day-to-day operational protection of data as instructed by the data owner.
Confusing technical execution with business accountability is a common operational misconception in security governance.

Anahtar Kavram

Data owner vs. Data custodian roles and governance responsibilities
Tahmini Süre:1m 15s
Soru 2228Soru

An enterprise financial platform is establishing privacy-enhancing controls across its data processing pipelines. Match each data protection technology to its correct operational application.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Pseudonymization
Data Masking
Tokenization
Anonymization

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Pseudonymization matches with replacing identifiers with reversible artificial aliases requiring separate keys; Data Masking matches with obfuscating explicit characters during user interface rendering; Tokenization matches with replacing sensitive elements with surrogate tokens in a secure vault; Anonymization matches with irreversibly altering personal data.
Each technology aligns with its specific privacy objective: Pseudonymization provides reversible identifier substitution using separate keys; Data Masking obfuscates characters on screen; Tokenization maps values to non-sensitive tokens in a secure vault; and Anonymization permanently removes all re-identification capability.

Adım Adım Çözüm

1
Analyze Pseudonymization requirements
Identify that pseudonymization replaces direct identifiers with pseudonyms while retaining reversibility via separate cryptographic keys or mapping tables.
Regulatory privacy frameworks explicitly define pseudonymization as reversible data de-identification using separate control keys.
2
Analyze Data Masking functionality
Identify that data masking partially redacts or obfuscates characters (e.g., showing **** 1234) for screen output rendering.
Data masking focuses on presentation-layer field obfuscation to protect sensitive values from unauthorized viewers during display.
3
Analyze Tokenization implementation
Identify that tokenization replaces sensitive data with non-sensitive surrogate values resolved through a secure token vault.
Tokenization avoids storing encrypted values in application databases by substituting tokens backed by a centralized lookup vault.
4
Analyze Anonymization properties
Identify that anonymization is an irreversible process that completely removes re-identification capabilities.
Unlike pseudonymization, anonymization permanently strips identity links, removing the dataset from PII compliance scope.

Anahtar Kavram

Privacy-enhancing technologies and data protection controls
Soru 2229Soru

A specialized genomic research organization is implementing data protection controls across its analytical data pipeline. Security policies require that direct patient identifiers, such as names and social security numbers, be replaced with random alphanumeric values in testing environments, while retaining the technical ability to reverse the process back to original records via an encrypted central vault accessible only to authorized compliance personnel. Which of the following privacy-enhancing techniques best satisfies this operational requirement?

Cevabı ve açıklamayı göster

Cevap: Tokenization

Cevap

Tokenization is the correct control because it replaces sensitive elements with surrogate values that can be reversed using a secure mapping vault.
Tokenization replaces sensitive sensitive data elements with surrogate values (tokens) that have no intrinsic or exploitable meaning. The mapping back to the original sensitive data is securely stored in a centralized token vault accessible only under strict authorization controls.

Adım Adım Çözüm

1
Analyze the scenario requirements
Identified the need to substitute identifiers with surrogate values while maintaining reversible access via a central secure lookup database/vault.
The organization needs to protect real PII in test environments but retain mapping capability for authorized compliance workflows.
2
Evaluate privacy-enhancing technology characteristics
Tokenization generates random surrogate tokens tied to a secure lookup vault, matching the exact requirement.
Unlike anonymization, tokenization preserves reversibility when authorized.

Anahtar Kavram

Privacy-Enhancing Technologies (Tokenization vs. Anonymization vs. Masking)
Soru 2230Soru

A hospital network is formalizing its data governance framework to prepare for a multi-cloud Electronic Health Record (EHR) migration. To ensure proper separation of duties, leadership is defining governance roles for handling sensitive patient information. Which of the following responsibilities belong specifically to the data owner rather than the data custodian? (Select TWO.)

Geçerli olan tümünü seçin

Cevabı ve açıklamayı göster

Cevap: Determining the data classification level and defining access control requirements based on regulatory requirements; Approving data disclosure requests and authorizing baseline access permissions for organizational roles

Cevap

The responsibilities specifically assigned to the data owner are determining data classification levels and defining access control requirements, as well as approving data disclosure requests and authorizing baseline access permissions.
The correct responses identify the core administrative responsibilities of a data owner: setting classification levels, defining access rules according to regulatory standards, and granting formal approvals for data disclosure and role access. Data owners are business leaders accountable for data security policies rather than technical implementation.

Adım Adım Çözüm

1
Analyze the core distinction between data owner and data custodian roles in security governance.
Identified that data owners hold ultimate administrative and business accountability for data assets, whereas data custodians carry out hands-on technical management and maintenance.
Separation of duties requires separating policy-defining authority (owner) from technical control execution (custodian).
2
Evaluate each option against data owner responsibilities.
Determining sensitivity classification levels, defining access requirements, and approving formal access disclosures are business decision-making functions belonging to the data owner.
Only business managers or executives acting as data owners have the authority to classify data and grant access approvals.
3
Distinguish data custodian tasks and general authentication controls from data owner duties.
Technical system tasks such as backups, patching, storage encryption, and identity verification belong to system administration, data custodians, or technical authentication systems.
Attributing routine technical operation or authentication handling to data owners confuses practical technical management with administrative governance ownership.

Anahtar Kavram

Data Owner vs. Data Custodian Responsibilities
Soru 2231Soru

A global media streaming service is updating its data governance architecture to comply with international privacy regulations. Match each data governance role on the left with its primary operational responsibility on the right.

Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın

Öğeler

Data Owner
Data Custodian
Data Protection Officer (DPO)
Data Processor

Eşleşmeler

Cevabı ve açıklamayı göster

Cevap

Data Owner pairs with determining classification levels and business accountability; Data Custodian pairs with maintaining database integrity and technical backup procedures; Data Protection Officer (DPO) pairs with monitoring compliance and serving as liaison to supervisory authorities; Data Processor pairs with processing personal data under direct instruction of a data controller.
Each role corresponds strictly to CompTIA Security+ data governance definitions: the Data Owner defines classification and access permissions; the Data Custodian executes technical controls and backup routines; the Data Protection Officer oversees regulatory compliance and privacy assessments; and the Data Processor acts on behalf of an external data controller.

Adım Adım Çözüm

1
Differentiate executive data governance policy roles from technical execution roles.
The Data Owner establishes rules and classification, whereas the Data Custodian carries out technical maintenance and access enforcement.
CompTIA Security+ distinguishes business accountability (Data Owner) from operational technology administration (Data Custodian).
2
Differentiate regulatory privacy oversight roles from external processing entities.
The Data Protection Officer provides compliance oversight and authority liaison, while the Data Processor is a vendor executing instructions.
Privacy frameworks mandate independent internal oversight (DPO) while regulating contracted third-party processing activities (Data Processor).

Anahtar Kavram

Data Governance Roles and Operational Responsibilities
Soru 2232Soru

A digital publishing platform is updating its enterprise data governance model to ensure proper management of sensitive subscriber datasets. Executive leadership assigns the Vice President of HR to define retention schedules, determine data classification tiers for personnel records, and approve access authorizations. A senior database administrator is then instructed to implement storage encryption, perform daily backups, and enforce access control lists based on those approved directives. Which of the following data governance roles describes the operational responsibilities of the senior database administrator?

Cevabı ve açıklamayı göster

Cevap: Data custodian

Cevap

Data custodian
The correct answer is the data custodian. In data governance frameworks, a data custodian (often a system engineer, database administrator, or IT administrator) is responsible for the technical safeguards, backup procedures, system hardening, and access enforcement required to protect data according to rules established by the data owner.

Adım Adım Çözüm

1
Identify the key responsibilities described for the senior database administrator in the scenario.
The senior database administrator is managing technical security controls, access control lists, storage encryption, and backup routines.
Technical operational duties differentiate database maintenance from policy definition.
2
Differentiate between governance accountability and technical maintenance roles.
The Vice President of HR acts as the business data owner who determines classification and approves access, whereas the database administrator executes those technical controls.
CompTIA Security+ distinguishes between the data owner (business accountability) and data custodian (operational execution).
3
Match the administrator's technical role to standard data governance terminology.
The role responsible for maintaining technical safeguards and operational compliance is the data custodian.
Data custodians preserve data integrity, security, and availability per the owner's policy specifications.

Anahtar Kavram

Distinction between Data Owner and Data Custodian roles
ÖncekiSayfa 112 / 112
Tüm alıştırma soruları — CompTIA Security+ | Examkin