Written by students who passed Immediately available after payment Read online or as PDF Wrong document? Swap it for free 4.6 TrustPilot
logo-home
Document preview thumbnail
Preview 2 out of 13 pages
Exam (elaborations)

CIPT TEST PAPER EXAMS 2026.pdf 1. Document information

Document preview thumbnail
Preview 2 out of 13 pages

CIPT TEST PAPER EXAMS 1. Document information

Content preview

CIPT TEST PAPER EXAMS 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔ILC - Disclosure - ✔✔-Internal disclosure of data should be documented by a data
flow diagram, data sharing restrictions, and request for data should be passed on tot he
original collectors of the data.
-External disclosure should be covered by contracts that govern use, retention, and
destruction of data.

✔✔ILC - Destruction - ✔✔-Need proper formatting to delete data; best way to destroy a
disk is by formatting the disk using /P:count flag command to zero the disk
-Digital Rights Management capabilities to make data inaccessible with encryption after
a certain time period.
-WORM (write once read many) media (ROMS, CDs, and DVDs) have to be destroyed
to rid data.
-Printers, copiers, and fax machines have hard drives that should be wiped clean or
destroyed.

Data should be assigned a minimum and maximum retention period.

✔✔Identity Management - ✔✔The processes involved in verifying the identity of an
individual, group, process, or device.

Various methods:
-Authentication = act of validating a person's identity with an identity management
service before access to resources is permitted. Can be ID/password, RFID card, key
fob, USB, biometrics (fingerprint/retinal), or user location
-Multifactor authentication - more than 1 type of authentication used to validate; could
be single or dual factor
-Authorization - confirming authenticated person has legitimate access to a resource or
permission to execute a command.
-Access control list - indicates types of permission for which identities are authorized.
(e.g. Alice and Bob have write access to file, but Carlos only has read access).

✔✔Discretionary Access Control (DAC) - ✔✔Allows users who own resource to manage
access control lists.

Easier to manage, but permits employees to act against organizational policy.

✔✔Mandatory Access Control (MAC) - ✔✔Only system administrators are permitted to
modify a resource's access control list.

More secure, but puts burden on IT department to manage access control lists for all
resources.

, ✔✔Cross-enterprise authentication and authorization models - ✔✔-single sign on
(SSO): users only have to remember one ID and password that will be used across
multiple sites. With SSO user can reset password for all sites at once.
-Open ID Federation: provides a mechanism that allows users to be authenticated to a
relying party using a 3rd party authentication service.
*E.g. Klout.com uses Twitter/FB to authenticate.
-Liberty Alliance: defines standards, guidelines, and best practices for identity
management.
*Kantara initiative (4 assurance levels)
-Identity metasystem architecture: privacy enhancing, security-enhancing identity
solution for the Internet developed by Windows.
*More private solution; does not permit tracking of users by the relying party or identity
provider.
-Social networks: Facebook, Google+ users can sign in with a single ID.
*Must understand what data is exchanged and how data is used.

✔✔Payment Card Industry Data Security Standard (PCI DSS) - ✔✔-Managed by PCI
Security Standards Council (SCC)

-PCI DSS 12 requirements:
(1) Build and maintain a secure network;
(2) Protect cardholder data (name, CC #, expiration date, and security code);
(3) Maintain a vulnerability management program;
(4) Implement strong access control measures;
(5) Regularly monitor/test networks;
(6) Maintain an information security policy;

-PCI DSS 12 requirements are fulfilled by 3 steps: assess remediate, and report.

✔✔PCI Payment Application Data Security Standard (PCI PA DSS) - ✔✔Vendors who
create payment application software need to be PA-DSS compliant if the software
stores, processes, or transmits cardholder data.

✔✔Encryption Regulation - ✔✔Basel III, HIPAA, PCI DSS (requires encrypted
transmission of cardholder data across open, public networks), Financial instruments
and change laws of Japan

✔✔Linux Unified Key Setup (LUKS) - ✔✔Disk encryption specification for encrypting an
entire disk; key file for a LUKS-encrypted drive can be stored on a USB key. Protects in
case computer is stolen/confiscated.

✔✔Privacy Enhancing Technologies (PET) - ✔✔-automated data retrieval
-automated system audits: limit viewing of personal data to one record at a time and tie
record access to a work order/task that validates the employees' need to access a
record

Document information

Uploaded on
July 19, 2026
Number of pages
13
Written in
2025/2026
Type
Exam (elaborations)
Contains
Questions & answers
$17.99

Wrong document? Swap it for free Within 14 days of purchase and before downloading, you can choose a different document. You can simply spend the amount again.
Written by students who passed
Immediately available after payment
Read online or as PDF

Seller avatar
Reputation scores are based on the amount of documents a seller has sold for a fee and the reviews they have received for those documents. There are three levels: Bronze, Silver and Gold. The better the reputation, the more your can rely on the quality of the sellers work.
BOARDWALK
3.5
(40)
Sold
278
Followers
8
Items
32861
Last sold
1 day ago


Why students choose Stuvia

Created by fellow students, verified by reviews

Quality you can trust: written by students who passed their tests and reviewed by others who've used these notes.

Didn't get what you expected? Choose another document

No worries! You can instantly pick a different document that better fits what you're looking for.

Pay as you like, start learning right away

No subscription, no commitments. Pay the way you're used to via credit card and download your PDF document instantly.

Student with book image

“Bought, downloaded, and aced it. It really can be that simple.”

Alisha Student

Working on your references?

Create accurate citations in APA, MLA and Harvard with our free citation generator.

Working on your references?

Frequently asked questions