CIPT TEST PAPER EXAMS 2026/2027 QUESTIONS AND
SOLUTIONS RATED A+
✔✔ILC - Disclosure - ✔✔-Internal disclosure of data should be documented by a data
flow diagram, data sharing restrictions, and request for data should be passed on tot he
original collectors of the data.
-External disclosure should be covered by contracts that govern use, retention, and
destruction of data.
✔✔ILC - Destruction - ✔✔-Need proper formatting to delete data; best way to destroy a
disk is by formatting the disk using /P:count flag command to zero the disk
-Digital Rights Management capabilities to make data inaccessible with encryption after
a certain time period.
-WORM (write once read many) media (ROMS, CDs, and DVDs) have to be destroyed
to rid data.
-Printers, copiers, and fax machines have hard drives that should be wiped clean or
destroyed.
Data should be assigned a minimum and maximum retention period.
✔✔Identity Management - ✔✔The processes involved in verifying the identity of an
individual, group, process, or device.
Various methods:
-Authentication = act of validating a person's identity with an identity management
service before access to resources is permitted. Can be ID/password, RFID card, key
fob, USB, biometrics (fingerprint/retinal), or user location
-Multifactor authentication - more than 1 type of authentication used to validate; could
be single or dual factor
-Authorization - confirming authenticated person has legitimate access to a resource or
permission to execute a command.
-Access control list - indicates types of permission for which identities are authorized.
(e.g. Alice and Bob have write access to file, but Carlos only has read access).
✔✔Discretionary Access Control (DAC) - ✔✔Allows users who own resource to manage
access control lists.
Easier to manage, but permits employees to act against organizational policy.
✔✔Mandatory Access Control (MAC) - ✔✔Only system administrators are permitted to
modify a resource's access control list.
More secure, but puts burden on IT department to manage access control lists for all
resources.
, ✔✔Cross-enterprise authentication and authorization models - ✔✔-single sign on
(SSO): users only have to remember one ID and password that will be used across
multiple sites. With SSO user can reset password for all sites at once.
-Open ID Federation: provides a mechanism that allows users to be authenticated to a
relying party using a 3rd party authentication service.
*E.g. Klout.com uses Twitter/FB to authenticate.
-Liberty Alliance: defines standards, guidelines, and best practices for identity
management.
*Kantara initiative (4 assurance levels)
-Identity metasystem architecture: privacy enhancing, security-enhancing identity
solution for the Internet developed by Windows.
*More private solution; does not permit tracking of users by the relying party or identity
provider.
-Social networks: Facebook, Google+ users can sign in with a single ID.
*Must understand what data is exchanged and how data is used.
✔✔Payment Card Industry Data Security Standard (PCI DSS) - ✔✔-Managed by PCI
Security Standards Council (SCC)
-PCI DSS 12 requirements:
(1) Build and maintain a secure network;
(2) Protect cardholder data (name, CC #, expiration date, and security code);
(3) Maintain a vulnerability management program;
(4) Implement strong access control measures;
(5) Regularly monitor/test networks;
(6) Maintain an information security policy;
-PCI DSS 12 requirements are fulfilled by 3 steps: assess remediate, and report.
✔✔PCI Payment Application Data Security Standard (PCI PA DSS) - ✔✔Vendors who
create payment application software need to be PA-DSS compliant if the software
stores, processes, or transmits cardholder data.
✔✔Encryption Regulation - ✔✔Basel III, HIPAA, PCI DSS (requires encrypted
transmission of cardholder data across open, public networks), Financial instruments
and change laws of Japan
✔✔Linux Unified Key Setup (LUKS) - ✔✔Disk encryption specification for encrypting an
entire disk; key file for a LUKS-encrypted drive can be stored on a USB key. Protects in
case computer is stolen/confiscated.
✔✔Privacy Enhancing Technologies (PET) - ✔✔-automated data retrieval
-automated system audits: limit viewing of personal data to one record at a time and tie
record access to a work order/task that validates the employees' need to access a
record
SOLUTIONS RATED A+
✔✔ILC - Disclosure - ✔✔-Internal disclosure of data should be documented by a data
flow diagram, data sharing restrictions, and request for data should be passed on tot he
original collectors of the data.
-External disclosure should be covered by contracts that govern use, retention, and
destruction of data.
✔✔ILC - Destruction - ✔✔-Need proper formatting to delete data; best way to destroy a
disk is by formatting the disk using /P:count flag command to zero the disk
-Digital Rights Management capabilities to make data inaccessible with encryption after
a certain time period.
-WORM (write once read many) media (ROMS, CDs, and DVDs) have to be destroyed
to rid data.
-Printers, copiers, and fax machines have hard drives that should be wiped clean or
destroyed.
Data should be assigned a minimum and maximum retention period.
✔✔Identity Management - ✔✔The processes involved in verifying the identity of an
individual, group, process, or device.
Various methods:
-Authentication = act of validating a person's identity with an identity management
service before access to resources is permitted. Can be ID/password, RFID card, key
fob, USB, biometrics (fingerprint/retinal), or user location
-Multifactor authentication - more than 1 type of authentication used to validate; could
be single or dual factor
-Authorization - confirming authenticated person has legitimate access to a resource or
permission to execute a command.
-Access control list - indicates types of permission for which identities are authorized.
(e.g. Alice and Bob have write access to file, but Carlos only has read access).
✔✔Discretionary Access Control (DAC) - ✔✔Allows users who own resource to manage
access control lists.
Easier to manage, but permits employees to act against organizational policy.
✔✔Mandatory Access Control (MAC) - ✔✔Only system administrators are permitted to
modify a resource's access control list.
More secure, but puts burden on IT department to manage access control lists for all
resources.
, ✔✔Cross-enterprise authentication and authorization models - ✔✔-single sign on
(SSO): users only have to remember one ID and password that will be used across
multiple sites. With SSO user can reset password for all sites at once.
-Open ID Federation: provides a mechanism that allows users to be authenticated to a
relying party using a 3rd party authentication service.
*E.g. Klout.com uses Twitter/FB to authenticate.
-Liberty Alliance: defines standards, guidelines, and best practices for identity
management.
*Kantara initiative (4 assurance levels)
-Identity metasystem architecture: privacy enhancing, security-enhancing identity
solution for the Internet developed by Windows.
*More private solution; does not permit tracking of users by the relying party or identity
provider.
-Social networks: Facebook, Google+ users can sign in with a single ID.
*Must understand what data is exchanged and how data is used.
✔✔Payment Card Industry Data Security Standard (PCI DSS) - ✔✔-Managed by PCI
Security Standards Council (SCC)
-PCI DSS 12 requirements:
(1) Build and maintain a secure network;
(2) Protect cardholder data (name, CC #, expiration date, and security code);
(3) Maintain a vulnerability management program;
(4) Implement strong access control measures;
(5) Regularly monitor/test networks;
(6) Maintain an information security policy;
-PCI DSS 12 requirements are fulfilled by 3 steps: assess remediate, and report.
✔✔PCI Payment Application Data Security Standard (PCI PA DSS) - ✔✔Vendors who
create payment application software need to be PA-DSS compliant if the software
stores, processes, or transmits cardholder data.
✔✔Encryption Regulation - ✔✔Basel III, HIPAA, PCI DSS (requires encrypted
transmission of cardholder data across open, public networks), Financial instruments
and change laws of Japan
✔✔Linux Unified Key Setup (LUKS) - ✔✔Disk encryption specification for encrypting an
entire disk; key file for a LUKS-encrypted drive can be stored on a USB key. Protects in
case computer is stolen/confiscated.
✔✔Privacy Enhancing Technologies (PET) - ✔✔-automated data retrieval
-automated system audits: limit viewing of personal data to one record at a time and tie
record access to a work order/task that validates the employees' need to access a
record