Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 3 out of 16 pages
Exam (elaborations)

CIPT LATEST EXAM ALL 2026.pdf 1. Document information

Document preview thumbnail
Preview 3 out of 16 pages

CIPT LATEST EXAM ALL 1. Document information

Content preview

CIPT LATEST EXAM ALL 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔Ways to mitigate network risks - ✔✔(1) Keep computers clear of malware - run latest
anti-malware software;
(2) Apply smartphone policies - phone passwords, auto-device lock/remote wiping
mechanism enforced for smartphones connecting to network resources;
(3) Validate network devices - each device must come from reputable vendor and have
proper configuration/most recent updates;
(4) Write secure code - developers should follow guidelines on how to write software
that avoids the risk of exposing data over network ("Writing Secure Code" and "The
Open Web Application Security Project");
(5) Validate applications - all apps running on computers/smartphones should be
restricted from accessing network services unless they are on a safe list set up by IT
dept.
(6) Network encryption - use encryption on wireless/wired networks at transportation
level to mitigate threat of thieves accessing unprotected data.

✔✔Network Monitoring - ✔✔Malware can infect company's network and travel from
computer to computer. Network monitoring software can look for known virus signatures
or use other means to find and cleanse network infestations.

Network monitoring can also prevent private data from leaving company / look for
signatureless advanced malware and take targeted actions.

✔✔Data Storage - ✔✔(1) Files - can be protected outside of their storage system using
password-based encryption or digital rights management;
(2) Websites - Employee access should be limited, and each website should have a
policy link for employees/access control list/organized by category to protect sensitive
content.
(3) Databases - good place to store sensitive data because general access control, role-
based access control, encryption, data categorization, retention management, and
auditing.
(4) Cloud storage - provides better access to data for customers, lower operational
costs, and limits regulatory risks for cross-border transfer of customer data. Contracts
should ensure that the hosting company follows org's data storage policy.
---RISK: Sharing a data center - companies hosting data for other companies increases
data breach risks
(5) Applications - need strong role-based access controls.
(6) Backup tapes - easy source of data leakage - no access control list and can be
easily read by anyone. To mitigate, ensure backups are encrypted and stored in safe
place.
(7) Hardware - need hardware disposal procedure; data should be wiped before
disposing of old hardware.

,✔✔Privacy Notice - ✔✔Privacy notice should be modeled upon company's privacy
policy, and should include:
-what data is collected
-how data is used
-how collected data is shared
-user control over collected data
-controlling marketing contact
-use of cookies and other tracking mechanisms
-gaining access to data
-resolving privacy issues
-date of notice
-any changes to privacy notice

✔✔Privacy Policy - ✔✔A privacy policy is a statement or a legal document (in privacy
law) that discloses some or all of the ways a party gathers, uses, discloses, and
manages a customer or client's data. It fulfills a legal requirement to protect a customer
or client's privacy.

Key things to include in privacy policy:
-Data classification
-Data retention period associated with each type of data classification
-Data deletion upon expiration of retention period
-Guidelines for creating a meaningful data inventory, including rules on where data can
be placed, minimizing offline storage, contracts to govern third parties' use of data,
classifying data, creating data flow.

✔✔Access Control - ✔✔Access control list consists of access control entries, which
contain the name of entity (by user, group, device or service) and type of access the
entity has to a particular resource.
---Should be validated on a regular basis to ensure that the entries are still appropriate.

Various types of access control:
(1) Discretionary access control - user has complete control over all resources she
owns; user has ability to determine permission other users have tot he resource.
(2) Mandatory access control - only the administrator can assign access rights.
(3) Role-based access control - access granted based on organizational role.
(4) Attribute-based access control - extension of role-based access control; attributes
can be time, location, age, or nationality. The extensible access control markup
language (XACML) is a standard that can be used to implement ABAC systems.

✔✔Encryption - ✔✔Protecting data transmission: Secure sockets layer (SSL) protocol
and transport layer security (TLS) help protect data that is transmitted from client server
machines and server to server machines.
-SSL commonly protects communications between a browser and a web server; TLS
for emails between email servers.

, Protecting data at rest: Symmetric and asymmetric encryption.
-Symmetric encryption - single cryptographic key for encryption and decryption;
efficient for protecting data accessed by multiple people. (Ex. = Data encryption
standard (DES))
-Asymmetric encryption - set of cryptographic keys, one for encryption and one for
decryption - slow and complicated for sharing beyond 2 people. (Ex. = RSA and
ElGamal)

✔✔Hashing - ✔✔Uses cryptographic key to encrypt data but does not allow data to be
later decrypted - permits use of sensitive data while protecting original value.

Used for credit card numbers or SSN. The downside is that the information can never
be decrypted.

✔✔Password control - ✔✔Single Sign On (SSO) can permit access to multiple
resources from a single account, with ability to centrally lock a person to multiple
resources.

✔✔Machine access restriction - ✔✔Limit access to a computer based on computer
identifier or IP address.

Example: Access to payroll database only limited to set of computers in payroll
department.

✔✔Enterprise Architecture (EA) - ✔✔EA involves managing data flow across an
organization to reduce risk and support business growth.
---Data flow diagram can show origin of data, indicating whether origin was an
individual, external entity, internal group or process.

✔✔Privacy and security regulations with specific IT requirements - ✔✔-Canada:
Personal Information Protection and Electronic Documents Act (PIPEDA) - company
doing business in Canada must obtain OPT-OUT consent from data subjects in order to
collect, use, or disclose personal information.
-EU: Data Protection Directive - anyone transferring data from EU citizens; applies to
processing of all online and offline data, and to all organizations holding personal data.
-Hong Kong: Personal Data (Privacy) Ordinance (PDPO) applies to companies doing
business in Hong Kong. Data subjects must be provided the right to access, correct, or
delete their personal data.
-Mexico: Law on the Protection of Personal Data Held by Private Parties applies to
Mexican companies doing business in Mexico; need OPT-IN (prior) consent before
gathering and processing data.
-US: Children's Online Privacy Protection Act (COPPA) applies to commercial/online
services directed at children under 13; must get OPT-IN consent from parent.

✔✔Information Lice Cycle (ILC) - ✔✔Collection, Use, Disclosure, Retention, Destruction

Document information

Uploaded on
July 19, 2026
Number of pages
16
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.49

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BOARDWALK
3.5
(41)
Sold
284
Followers
11
Items
36005
Last sold
1 week ago



Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions