C838 Exam 4 Questions with 100%
Correct Answers.
Organization risk knowledge items
An inventory of all assets
A valuation of each asset
A determination of critical paths, processes, and assets
A clear understanding of risk appetite
Secondary input etitities for P&PD
Data location allowed
Data breach constraints
Data retention constraints
Categories of users allowed
Security measures to be ensured
Status
Categories of personal data that can be processed
Sensitive data
Telephone or Internet data
Biometric data
Personal data
Categories of the processing to be performed
Data Discovery Issues
Hidden costs
Dashboard
Poor data quality
Data Retention Policy requirements
, Retention periods
Data formats
Data security
Data retrieval procedures for the enterprise
Features of IRM
Sets up a baseline for the default Information Protection Policy
Adds an extra layer of access controls on top of the data object or
document Protects sensitive organization content
Contains ACLs and is embedded into the original file, therefore IRM is agnostic to the
location of the data
Approches to data masking
Random substitution: Replaces the value with a random value
Algorithm substitution: Replaces the value with an algorithm-generated value
Shuffle: Shuffles different values from the data set
Masking: Hides certain parts of the data using specific characters
Deletion: Deletes the data or uses a null value
Challenges with Key Management
Backup and replication: The nature of the cloud can affect the ability for long- and short-term
key management.
Access to the keys: Permitting permission for accessing keys by CSP employees or personnel is
an important criteria.
Key storage: Secure keys' storage is essential for the security of data.
ISO/IEC 27043:2015
Information technology — Security techniques — Incident investigation principles and processes
ISO/IEC 27018:2014
Information technology — Security techniques — Code of practice for protection of personally
identifiable information (PII) in public clouds acting as PII processors
Correct Answers.
Organization risk knowledge items
An inventory of all assets
A valuation of each asset
A determination of critical paths, processes, and assets
A clear understanding of risk appetite
Secondary input etitities for P&PD
Data location allowed
Data breach constraints
Data retention constraints
Categories of users allowed
Security measures to be ensured
Status
Categories of personal data that can be processed
Sensitive data
Telephone or Internet data
Biometric data
Personal data
Categories of the processing to be performed
Data Discovery Issues
Hidden costs
Dashboard
Poor data quality
Data Retention Policy requirements
, Retention periods
Data formats
Data security
Data retrieval procedures for the enterprise
Features of IRM
Sets up a baseline for the default Information Protection Policy
Adds an extra layer of access controls on top of the data object or
document Protects sensitive organization content
Contains ACLs and is embedded into the original file, therefore IRM is agnostic to the
location of the data
Approches to data masking
Random substitution: Replaces the value with a random value
Algorithm substitution: Replaces the value with an algorithm-generated value
Shuffle: Shuffles different values from the data set
Masking: Hides certain parts of the data using specific characters
Deletion: Deletes the data or uses a null value
Challenges with Key Management
Backup and replication: The nature of the cloud can affect the ability for long- and short-term
key management.
Access to the keys: Permitting permission for accessing keys by CSP employees or personnel is
an important criteria.
Key storage: Secure keys' storage is essential for the security of data.
ISO/IEC 27043:2015
Information technology — Security techniques — Incident investigation principles and processes
ISO/IEC 27018:2014
Information technology — Security techniques — Code of practice for protection of personally
identifiable information (PII) in public clouds acting as PII processors