Data Protection
Secure Sharing
Data Retention
Information Classification
Information Security Policies
200

Which security principle prevents unauthorized people from viewing sensitive data?
A. Availability

B. Confidentiality

C. Performance

D. Portability

B. Confidentiality

200

Which action best protects sensitive information?
A. Saving copies in multiple personal accounts as backups  

B. Sharing files with anyone who asks  

C. Using approved storage locations and access controls  

D. Downloading files for offline use whenever possible

C. Using approved storage locations and access controls  

200

What is the primary purpose of a data retention policy?
A. To keep all data indefinitely 

B. To define how long information should be retained and when it should be securely disposed

C. To increase data storage capacity 

D. To prevent backups from occurring

B. To define how long information should be retained and when it should be securely disposed

200

Which of the following is an example of Protected Information?
A. Employee Social Security Number

B. Company logo on the website 

C. Public news article 

D. Published annual report

A. Employee Social Security Number

200

What principle ensures users receive only the access required to perform their job
A. Open Access 

B. Least Privilege

C. Unlimited Access 

D. Shared Access

B. Least Privilege

400

Who is typically accountable for determining a dataset’s classification?

A. Data owner

B. Data custodian 

C. System administrator 

D. End user

A. Data owner

400

Why do organizations require employees to use approved storage locations?
A. To make documents look more professional  

B. To support security controls, monitoring, and data protection requirements  

C. To reduce the number of folders employees create D. To prevent employees from working remotely

B. To support security controls, monitoring, and data protection requirements  

400

Which of the following is a likely consequence of retaining sensitive information beyond its approved retention period?
A. Reduced breach impact 

B. Reduced compliance obligations 

C. Increased exposure during litigation, audits, or security incidents

D. Improved access controls

C. Increased exposure during litigation, audits, or security incidents

400

Who is responsible for helping protect company information?
A. Managers only 

B. IT Team only 

C. Security Team only 

D. Everyone

D. Everyone

400

Why should employees avoid installing unauthorized software?
A. It may introduce security, legal, or operational risks

B. It uses battery power  

C. It changes desktop icons 

D. It increases printing costs

A. It may introduce security, legal, or operational risks

600

Which is the most appropriate statement about hashing and encryption?
A. Hashing and encryption can both be reversed with the correct key 

B. Hashing is generally one-way, while encryption is reversible with the correct key

C. Encryption verifies data integrity, while hashing protects data confidentiality 

D. Hashing protects data in transit, while encryption protects only data at rest

B. Hashing is generally one-way, while encryption is reversible with the correct key

600

An employee emails a sensitive report to their personal email account so they can work on it at home. Why is this risky?
A. Personal email may not provide the organization's required security protections and monitoring  

B. The email may arrive too slowly  

C. Personal email accounts cannot store attachments D. The report formatting could change

A. Personal email may not provide the organization's required security protections and monitoring  

600

During a cybersecurity breach, why could excessive data retention increase organizational impact?
A. More historical data may be exposed or stolen

B. Recovery becomes unnecessary 

C. Compliance requirements disappear 

D. Security controls automatically improve

A. More historical data may be exposed or stolen

600

Which classification level typically requires the highest level of protection?
A. Public 

B. Confidential 

C. Protected 

D. Archived

 C. Protected

600

You notice a company device in your area that has no owner label and nobody seems to know who it belongs to. What is the BEST action?

A. Use the device until someone claims it  

B. Store it in a cabinet  

C. Report it through the RCO team

D. Give it to a new employee

C. Report it through the RCO team

800

A healthcare dataset replaces patient names with unique codes, while the re-identification key is stored separately. Which technique is being used?
A. Anonymization, because the names are no longer visible 

B. Pseudonymization, because patients can still be re-identified using the key

C. Encryption, because the original values are permanently unreadable 

D. Data masking, because the patient records cannot be restored

B. Pseudonymization, because patients can still be re-identified using the key

800

Which scenario represents the most significant violation of secure information-handling practices?

A. Sharing a document through an approved platform with properly assigned permissions  

B. Storing project files in an approved company repository  

C. Downloading sensitive information to a personal cloud account to facilitate collaboration  

D. Restricting access based on business need

C. Downloading sensitive information to a personal cloud account to facilitate collaboration  

800

Which statement best reflects the relationship between data retention and information security?

A. Information security focuses only on protecting retained data indefinitely 

B. Proper retention management reduces the volume of data exposed to cyber threats

C. Retention has no impact on cybersecurity risk 

D. Longer retention periods always improve security

B. Proper retention management reduces the volume of data exposed to cyber threats

800

An employee accidentally shares Protected information using an unapproved method. What is the best action?
A. Ignore the incident 

B. Delete evidence of the sharing 

C. Report the incident immediately and follow company procedures

D. Wait for someone else to report it

C. Report the incident immediately and follow company procedures

800

You recently moved to a new role within the organization. You notice that you still have access to applications from your previous role. What should you do?
A. Continue using the access if it still works 

B. Share the access with your replacement 

C. Notify your manager so access can be reviewed and adjusted 

D. Wait until the system removes access automatically

C. Notify your manager so access can be reviewed and adjusted

1000

A research dataset uses coded patient IDs, but a separate file can reconnect the codes to individuals. How should the dataset be treated?
A. As anonymous data with no privacy risk 

B. As public data because names were removed 

C. As personal data requiring continued protection

D. As deleted data because identifiers were replaced

C. As personal data requiring continued protection

1000

Which combination of actions best protects sensitive information throughout its lifecycle?

A. Downloading files locally, sharing through personal apps, and deleting them afterward  

B. Storing information in approved locations, restricting access based on business need, and using approved transmission methods  

C. Saving copies in multiple personal storage locations for redundancy  

D. Sharing information broadly to ensure accessibility

B. Storing information in approved locations, restricting access based on business need, and using approved transmission methods  

1000

A healthcare organization retains millions of records beyond their required retention periods. Which risk presents the most significant concern?
A. Increased cybersecurity exposure, legal discovery obligations, storage costs, and privacy risk

B. Improved compliance posture 

C. Reduced obligations during investigations 

D. Elimination of insider threats

A. Increased cybersecurity exposure, legal discovery obligations, storage costs, and privacy risk

1000

Before sharing data externally, employees should:
A. Share immediately if requested 

B. Verify the information classification and approved sharing method

C. Remove the classification label 

D. Send it through personal email

B. Verify the information classification and approved sharing method

1000

What factors should be considered for granting Access
A. User role, location, Manager Approval 

B. Manager Approval 

C. User Preference 

D. User role, location, data classification, risk level

D. User role, location, data classification, risk level