Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 4 out of 31 pages
Exam (elaborations)

NYC Document Control Specialist Exam Practice Questions And Correct Answers (Verified Answers) Plus Rationales | I

Document preview thumbnail
Preview 4 out of 31 pages

NYC Document Control Specialist Exam Practice Questions And Correct Answers (Verified Answers) Plus Rationales | I

Content preview

NYC Document Control Specialist Exam Practice
Questions And Correct Answers (Verified Answers)
Plus Rationales | I


1. A city agency receives a FOIL request for emails between two senior officials discussing a
pending procurement. The agency's general counsel claims the emails are exempt as intra-agency
materials that are deliberative. However, the requester argues that the emails contain factual data
and final agency policy. Under the New York Freedom of Information Law and relevant case law,
which factor is MOST critical in determining whether the deliberative process exemption applies?

A. Whether the emails were sent from personal or government email accounts
B. Whether the emails were created before or after the final procurement decision
C. Whether the emails were shared with any external parties
D. Whether the emails contain opinions that are part of the agency's decision-making process, not merely factual
information

Answer: D
Rationale: The deliberative process exemption under FOIL protects opinions and recommendations that
are part of the agency's decision-making process, but not purely factual data. The key factor is the
content and purpose of the communication, not the timing or medium. Options A, B, and C are
secondary considerations and not determinative.


2. An NYC agency is implementing a new electronic document management system (EDMS) to
replace its paper-based records. As the document control specialist, you are tasked with ensuring
that the system meets legal and regulatory requirements for admissibility of electronic records in
court. Which combination of controls is ESSENTIAL to establish the authenticity and reliability of
the electronic records under the business records exception to the hearsay rule?

A. Encryption at rest, audit trails, and user authentication
B. Version control, full-text indexing, and metadata preservation
C. Audit trails, regular backups, and a written policy on record creation and maintenance
D. Digital signatures, checksums, and anti-malware software

Answer: C
Rationale: To satisfy the business records exception (CPLR 4518), the proponent must show that the
record was made in the regular course of business, at or near the time of the event, and that it was the
regular practice to make such records. Audit trails demonstrate the chain of custody, backups ensure
records are not altered, and a written policy establishes the regularity of the practice. While encryption,
authentication, and version control are important for security, they are not the core legal requirements
for admissibility.




Page 1

,3. During a routine audit of your agency's records management program, you discover that several
departments are retaining emails beyond the approved retention schedule because managers find
them 'useful for reference.' Under the NYC Records Retention and Disposition Schedule, what is
the CORRECT course of action?


A. Immediately delete all emails that have exceeded the retention period, regardless of manager objections
B. Request an exception from the NYC Department of Records and Information Services (DORIS) to extend the
retention schedule for those emails
C. Reclassify the emails as permanent records because they are frequently referenced
D. Ignore the issue because the emails are not yet subject to a litigation hold

Answer: B
Rationale: The NYC Records Retention and Disposition Schedule is mandatory, but agencies may request
exceptions or revisions from DORIS for records that have ongoing administrative, legal, or historical
value. Simply retaining records beyond schedule without approval violates policy. Option A is too
drastic without proper authorization; option C is incorrect because frequency of reference does not
automatically make a record permanent; option D ignores the compliance requirement.


4. Your agency is involved in federal litigation, and a discovery request seeks all documents related
to a specific project. The project files include drafts, notes, and emails that contain both privileged
attorney-client communications and non-privileged business discussions. You are responsible for
preparing the privilege log. According to the Federal Rules of Civil Procedure and best practices,
which of the following is the MOST appropriate way to describe a withheld document that contains
both privileged and non-privileged content?

A. Withhold the entire document and describe it generically as 'Privileged communication'
B. Redact the privileged portions, produce the non-privileged portions, and describe the redacted material in the
privilege log
C. Withhold the entire document and provide a detailed description of the privileged content only
D. Produce the entire document without redaction but mark it as 'Confidential - Attorney-Client Privilege'

Answer: B
Rationale: FRCP 26(b)(5) requires that when a party withholds information on privilege grounds, they
must describe the nature of the withheld information in a manner that enables the other party to assess
the claim. For documents containing both privileged and non-privileged content, the proper practice is
to redact only the privileged portions and produce the rest, with the privilege log describing the redacted
information. Option A is too vague; option C fails to describe non-privileged content; option D waives
privilege.


5. An NYC agency is transitioning to a cloud-based records management system. The contract with
the vendor includes a clause that the vendor may access records for 'system maintenance and
improvement.' As the document control specialist, you are concerned about compliance with the
NYC Records Management Law and data privacy regulations. Which of the following actions is
MOST critical to include in the contract or service level agreement to protect the agency's records?

A. Require the vendor to obtain written consent from each individual whose records are stored
B. Prohibit the vendor from accessing records except as necessary to fulfill the contract, with a detailed logging
requirement




Page 2

,C. Allow vendor access but require that all records be encrypted in transit and at rest
D. Require the vendor to indemnify the agency for any data breach

Answer: B
Rationale: Under the NYC Records Management Law, records remain the property of the city, and
vendors must have strict limitations on access. The most critical protection is to contractually limit
access to what is necessary for the service and to require logging of all access. Consent of individuals
(A) is impractical and not required; encryption (C) is important but does not control access;
indemnification (D) is a remedy, not a preventative control.


6. A document control specialist is reviewing a proposed disposition of records that have been
scheduled for destruction. The records include personnel files that are 7 years old, project files that
are 10 years old, and financial audit records that are 6 years old. According to the NYC Municipal
Archives retention schedules, which of the following statements is CORRECT?

A. All three categories may be destroyed because they have exceeded the minimum retention periods
B. The personnel files and project files may be destroyed, but the financial audit records must be retained for 7
years
C. None of the records may be destroyed without a records disposition authorization from DORIS
D. The personnel files may be destroyed, but the project files and financial audit records must be retained for 20
years

Answer: C
Rationale: All records scheduled for destruction must be reviewed and authorized by the NYC
Department of Records and Information Services (DORIS) through a Records Disposition Authorization
(RDA). Even if a record has passed its minimum retention period, it cannot be destroyed without this
authorization. Options A and B assume automatic destruction, which is incorrect. Option D states
incorrect retention periods.


7. During the implementation of an enterprise content management (ECM) system, the IT
department proposes to use a 'single instance storage' (deduplication) technique to save disk space.
However, the legal department is concerned that this may affect the ability to preserve records in
their original format for litigation hold purposes. Which of the following is the MOST appropriate
approach to address this concern?

A. Implement single instance storage only for non-records and temporary files, not for records that may be
subject to hold
B. Use single instance storage but disable deduplication for any file that is placed on hold
C. Reject single instance storage entirely because it is incompatible with legal hold requirements
D. Implement single instance storage and rely on the system's ability to reconstruct the original file from the
deduplicated store

Answer: B
Rationale: Single instance storage can be used as long as the system can preserve the original metadata
and content of a record when placed on hold. The best practice is to disable deduplication for held
records to ensure they remain in their original state. Option A is overly restrictive; option C is
unnecessary; option D may not guarantee preservation of the exact original format.




Page 3

, 8. An NYC agency receives a subpoena duces tecum for records related to a construction project.
The subpoena demands production within 10 days. The project files are voluminous and stored
both on-premises and in a cloud service. As the document control specialist, what is your FIRST
step in responding to the subpoena?


A. Immediately begin collecting all potentially responsive documents from all sources
B. Notify the agency's general counsel and the cloud vendor to initiate a legal hold
C. Assess the scope of the subpoena, identify potential burdens, and determine if the subpoena is reasonably
particular
D. Request an extension from the issuing party due to the volume of records

Answer: C
Rationale: Before taking any action, the specialist must assess the subpoena for scope and particularity
to ensure it is not overly broad or unduly burdensome. This assessment guides the collection effort and
may lead to a motion to quash or modify. Option A is premature; option B is important but secondary;
option D may be necessary but is not the first step.


9. Which of the following scenarios would constitute a violation of the NYC Health Insurance
Portability and Accountability Act (HIPAA) Privacy Rule regarding the use of protected health
information (PHI) in a city agency?

A. A social worker discloses PHI to a colleague during a case consultation without the patient's authorization
B. An agency uses PHI to conduct a quality improvement study without obtaining individual authorization
C. A data analyst accesses PHI to verify the accuracy of a report without a specific authorization for that
purpose
D. An agency discloses PHI to a law enforcement official in response to a court order without patient
authorization

Answer: C
Rationale: Under HIPAA, accessing PHI without a legitimate purpose—such as for quality improvement
or treatment-is a violation unless specifically authorized. Option A is permitted for treatment or
consultation; option B is allowed for health care operations; option D is permitted pursuant to a court
order. Option C involves accessing PHI for a non-operational purpose without authorization.


10. An agency's records management policy states that all records must be stored in a manner that
prevents unauthorized access, alteration, or destruction. The agency uses a combination of physical
locks, access card systems, and network firewalls. To ensure compliance with the policy, which
additional control is MOST necessary for electronic records?

A. Implement a data loss prevention (DLP) system that monitors and blocks unauthorized data transfers
B. Require all employees to use strong passwords and change them every 90 days
C. Conduct quarterly audits of user access rights and review audit logs for suspicious activity
D. Encrypt all records at rest and in transit using industry-standard algorithms

Answer: C
Rationale: While encryption, DLP, and passwords are important, the most critical control for ensuring
integrity and preventing unauthorized alteration is regular auditing of access and activity. Audit logs
allow detection of unauthorized changes or access. Without review, other controls may be bypassed.
Option C directly addresses the policy requirement of preventing unauthorized access and alteration.



Page 4

Document information

Uploaded on
July 6, 2026
Number of pages
31
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$21.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Sold
1
Followers
2
Items
412
Last sold
2 weeks ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions