CIPT 試験問題 66
Which Organization for Economic Co-operation and Development (OECD) privacy protection principle encourages an organization to obtain an individual s consent before transferring personal information?
CIPT 試験問題 67
SCENARIO - Please use the following to answer the next question:
It should be the most secure location housing data in all of Europe, if not the world. The Global Finance Data Collective (GFDC) stores financial information and other types of client data from large banks, insurance companies, multinational corporations and governmental agencies. After a long climb on a mountain road that leads only to the facility, you arrive at the security booth. Your credentials are checked and checked again by the guard to visually verify that you are the person pictured on your passport and national identification card.
You are led down a long corridor with server rooms on each side, secured by combination locks built into the doors. You climb a flight of stairs and are led into an office that is lighted brilliantly by skylights where the GFDC Director of Security, Dr. Monique Batch, greets you. On the far wall you notice a bank of video screens showing different rooms in the facility. At the far end, several screens show different sections of the road up the mountain.
Dr. Batch explains once again your mission. As a data security auditor and consultant, it is a dream assignment: The GFDC does not want simply adequate controls, but the best and most effective security that current technologies allow.
!'We were hacked twice last year," Dr. Batch says, :'and although only a small number of records were stolen, the bad press impacted our business. Our clients count on us to provide security that is nothing short of impenetrable and to do so quietly. We hope to never make the news again." She notes that it is also essential that the facility is in compliance with all relevant security regulations and standards.
You have been asked to verify compliance as well as to evaluate all current security controls and security measures, including data encryption methods, authentication controls and the safest methods for transferring data into and out of the facility. As you prepare to begin your analysis, you find yourself considering an intriguing question: Can these people be sure that I am who I say I am?
You are shown to the office made available to you and are provided with system login information, including the name of the wireless network and a wireless key. Still pondering, you attempt to pull up the facility s wireless network, but no networks appear in the wireless list. When you search for the wireless network by name, however it is readily found What measures can protect client information stored at GFDC?
It should be the most secure location housing data in all of Europe, if not the world. The Global Finance Data Collective (GFDC) stores financial information and other types of client data from large banks, insurance companies, multinational corporations and governmental agencies. After a long climb on a mountain road that leads only to the facility, you arrive at the security booth. Your credentials are checked and checked again by the guard to visually verify that you are the person pictured on your passport and national identification card.
You are led down a long corridor with server rooms on each side, secured by combination locks built into the doors. You climb a flight of stairs and are led into an office that is lighted brilliantly by skylights where the GFDC Director of Security, Dr. Monique Batch, greets you. On the far wall you notice a bank of video screens showing different rooms in the facility. At the far end, several screens show different sections of the road up the mountain.
Dr. Batch explains once again your mission. As a data security auditor and consultant, it is a dream assignment: The GFDC does not want simply adequate controls, but the best and most effective security that current technologies allow.
!'We were hacked twice last year," Dr. Batch says, :'and although only a small number of records were stolen, the bad press impacted our business. Our clients count on us to provide security that is nothing short of impenetrable and to do so quietly. We hope to never make the news again." She notes that it is also essential that the facility is in compliance with all relevant security regulations and standards.
You have been asked to verify compliance as well as to evaluate all current security controls and security measures, including data encryption methods, authentication controls and the safest methods for transferring data into and out of the facility. As you prepare to begin your analysis, you find yourself considering an intriguing question: Can these people be sure that I am who I say I am?
You are shown to the office made available to you and are provided with system login information, including the name of the wireless network and a wireless key. Still pondering, you attempt to pull up the facility s wireless network, but no networks appear in the wireless list. When you search for the wireless network by name, however it is readily found What measures can protect client information stored at GFDC?
CIPT 試験問題 68
シナリオ
Wesley Energy has finally made its move, acquiring the venerable oil and gas exploration firm Lancelot from its long-time owner David Wilson. As a member of the transition team, you have come to realize that Wilson's quirky nature affected even Lancelot's data practices, which are maddeningly inconsistent. "The old man hired and fired IT people like he was changing his necktie," one of Wilson's seasoned lieutenants tells you, as you identify the traces of initiatives left half complete.
たとえば、一部の専有データと顧客と従業員の個人情報は暗号化されていますが、従業員の有毒物質への曝露に関する監視検査からの健康情報など、他の機密情報は、特に機密性の低いデータを含む長い記録に含まれる場合、暗号化されないままです。また、一見するとほぼランダムに見える方法で、データがアプリケーション、サーバー、施設に分散していることもわかります。
Lancelot のデータの状態に関する予備的な調査結果には次のようなものがあります。
クラウド テクノロジーは、聞いたことのない企業も含め、世界中のベンダーによって提供されています。元 Lancelot 従業員から、これらのベンダーは異なるセキュリティ要件とプロトコルで運用されていると聞きました。
同社独自のシェールオイル回収プロセスは、機密性の低いさまざまな情報とともにサーバーに保存されており、科学者だけでなく、ほとんどの企業拠点のあらゆる職種の担当者がアクセスできます。
DES は、現在あらゆるファイルに使用されている最も強力な暗号化アルゴリズムです。
いくつかの企業施設には、訪問者のチェックイン以外の物理的なセキュリティ管理が欠如しており、よく知られたベンダーがそれを回避していることがよくあります。
これらすべてを修正するには時間がかかりますが、まず混乱の範囲を把握し、それに対処するための行動計画を策定する必要があります。
ランスロットが使用する暗号化の種類に関して正しいのはどれですか?
Wesley Energy has finally made its move, acquiring the venerable oil and gas exploration firm Lancelot from its long-time owner David Wilson. As a member of the transition team, you have come to realize that Wilson's quirky nature affected even Lancelot's data practices, which are maddeningly inconsistent. "The old man hired and fired IT people like he was changing his necktie," one of Wilson's seasoned lieutenants tells you, as you identify the traces of initiatives left half complete.
たとえば、一部の専有データと顧客と従業員の個人情報は暗号化されていますが、従業員の有毒物質への曝露に関する監視検査からの健康情報など、他の機密情報は、特に機密性の低いデータを含む長い記録に含まれる場合、暗号化されないままです。また、一見するとほぼランダムに見える方法で、データがアプリケーション、サーバー、施設に分散していることもわかります。
Lancelot のデータの状態に関する予備的な調査結果には次のようなものがあります。
クラウド テクノロジーは、聞いたことのない企業も含め、世界中のベンダーによって提供されています。元 Lancelot 従業員から、これらのベンダーは異なるセキュリティ要件とプロトコルで運用されていると聞きました。
同社独自のシェールオイル回収プロセスは、機密性の低いさまざまな情報とともにサーバーに保存されており、科学者だけでなく、ほとんどの企業拠点のあらゆる職種の担当者がアクセスできます。
DES は、現在あらゆるファイルに使用されている最も強力な暗号化アルゴリズムです。
いくつかの企業施設には、訪問者のチェックイン以外の物理的なセキュリティ管理が欠如しており、よく知られたベンダーがそれを回避していることがよくあります。
これらすべてを修正するには時間がかかりますが、まず混乱の範囲を把握し、それに対処するための行動計画を策定する必要があります。
ランスロットが使用する暗号化の種類に関して正しいのはどれですか?
CIPT 試験問題 69
What is the goal of privacy enhancing technologies (PETS) like multiparty computation and differential privacy?
CIPT 試験問題 70
Which of the following is NOT a step in the methodology of a privacy risk framework?
