Data Security
Data Minimization
Data Labelling
100

You’re working in a public cafe and need to step away for a moment. What should you do?

A) Ask a neighbor to watch your laptop while you're gone.

B) Lock your screen (Win + L) and take your laptop with you.

B) Lock your screen (Win + L) and take your laptop with you.

100

Q: What is the risk of keeping "ROT" (Redundant, Obsolete, or Trivial) data on our servers?

A) It increases our storage costs and security/legal risks.

B) There is no risk; digital storage is virtually unlimited.

A) It increases our storage costs and security/legal risks.

100

Content with this label can be shared on a confidential basis with appropriate external partners and vendors. Use appropriate safeguards such as encryption.

A) High Sensitivity
B) Medium Sensitivity 

B) Medium Sensitivity

200

A colleague sends you an unexpected Team message asking for your login credentials to "help fix a system error." What is the best response?

A) Never share your password; report the request to the Security team.

B) Share it only if you know the person well and trust them.

A) Never share your password; report the request to the Security team.

200

Q: Once a project is finished and you no longer need the physical documents containing sensitive info, what is the best practice?

A) Shred them in the office immediately.

B) Keep them in your desk drawer just in case you need to refer back next year

A) Shred them in the office immediately.

200

Vendor-facing TJX Policies and Standards should be marked as

A) LOW Sensitivity
B) MEDIUM Sensitivity



A) LOW Sensitivity

300

Q: If you accidentally click a suspicious link and think you might have "let something in," what should you do?

A) Immediately report it to IT, even if nothing seems to have happened yet.

B) Wait and see if your computer starts acting weird before telling anyone.

  • Correct Answer: A

A) Immediately report it to IT, even if nothing seems to have happened yet.

300

(Fill in the blanks)
In TJX Data Minimization means Limit the collection, use, and _____ of data only to what is strictly necessary.

A) Storage
B) Sharing
C) Retain
D) Delete


B) Retain

In accordance with TJX record retention schedules, 

data should be erased once eligible for deletion.

300

Are sensitivity labels only to be used for documents shared outside TJX?

A) YES
B) NO

B) NO
Sensitivity Labels must be applied to all Microsoft Word, Excel, PowerPoint, and Visio files regardless of whether they are shared externally or kept to an internal audience.

M
e
n
u