answers rated A+ passed
Which of the following are considered the Essential Information and Network Security
Objectives?
- Authenticity and Accountability
- Confidentiality, Integrity, and Availability
- Accountability, Authenticity, Availability, Confidentiality, and Integrity
- Accountability, Authenticity, and Authorization - correct answer ✔✔ Accountability,
Authenticity, Availability, Confidentiality, and Integrity
Passive Attacks involve some modification of stored or transmitted data or the creation of false
data.
True or False - correct answer ✔✔ False
The five components of privacy engineering are:
- Privacy Impact Assessment, Security Assessment, Privacy Engineering, Security Objectives, and
Risk Assessment
- Security Risk Assessments; Risk Management; Privacy Impact Assessment; Privacy Engineering;
Vulnerability Assessment
- Security Risk Assessment; Risk Management; Business Impact Assessment; Privacy
Requirements, Privacy Engineering and Security Objectives
- Security Risk Assessment; Risk Management; Privacy Impact Assessment; Privacy
Requirements, Privacy Engineering and Security Objectives - correct answer ✔✔ Security Risk
Assessment; Risk Management; Privacy Impact Assessment; Privacy Requirements, Privacy
Engineering and Security Objectives
The Objectives of Privacy Engineering are Manageability, Predictability, and Accountability.
, True or False - correct answer ✔✔ False
Which U.S. Privacy Act expands the definition of PII to include "any information that identifies,
relates to, describes, is capable of being associated with, or could reasonably be linked, directly
or indirectly, with a particular consumer or household"?
PCI
HIPAA
CCPA
GDPR - correct answer ✔✔ CCPA
Which of the following is NOT an example of NON-Sensitive PII:
Work Email Address
Criminal History
Attendees of a public meeting
Non-Profit Board Attendees - correct answer ✔✔ Criminal History
Which of the following is considered the minimum standards for the protection of individual
privacy?
NIST SP188
HEW's FIPPs from 1973
OESCD80's 8 principles
GDPR - correct answer ✔✔ NOT
HEW's FIPPs from 1973
Which NIST publication focuses on security and privacy controls for information systems?
NIST 8062
NIST 800-161