Limited-Time Offer: Enjoy 50% Savings! Ends in 00h 00m 00s Coupon code: 50OFF
Skip to content

Free CIPS Commercial Data Management L6M7 Exam Questions

Page: 1 / 9 Total 83 questions

Want more questions? Get Premium Access.

Question 1

Which of the following is a UK-specific law that deals with the rights of data, particularly data that is shared and gathered online?

Correct Answer: B. Data Protection Act 2018
Explanation:

The Data Protection Act 2018 is the UK-specific law that governs data protection and incorporates GDPR into UK legislation. GDPR itself is an EU regulation but is included in UK law under this act.


Question 2

At Consultancy X, employees create a range of documents daily, from presentation slides to spreadsheets. Consultancy X was concerned that important data could easily be lost, so it implemented a system where data entered during the day is saved overnight on a backup server. This way, if any individual computer or device should fail, the employee can still access their dat

a. What is the risk approach taken by Consultancy X?

Correct Answer: B. Reduce
Explanation:

The company reduced the risk of data loss by using a backup system, though it did not eliminate the risk entirely. Transferring risk would involve making another party responsible, and accepting risk would mean doing nothing. (P.109)


Question 3

Fluffy Pillows Ltd has recently expanded its operations and has hired more staff. These staff will work remotely and because of this Fluffy Pillows Ltd is in need of buying and upgrading their IT systems. The CEO of Fluffy Pillows is examining the security of currently held data in preparation for the expansion and has recently completed a document which looks into what data is stored where and what the consequences would be if this data were to be stolen or corrupted. In his research he has found multiple data entries for the same information, which he believes could lead to inaccuracies in data reporting. He is also concerned that the data isn't being stored securely and is unsure whether he should retain some of the confidential personal details on employees who have left the business. He has decided that along with the introduction of new systems it is important that all members of staff at Fluffy Pillows are aware of the responsibilities of storing data correctly and the risks of cyber attacks.

What is the main concern with regards to the quality of data currently held?

Correct Answer: A. Commission
Explanation:

This is commission---data has been created (commissioned) by mistake, leading to multiple entries for the same thing.


Question 4

Which of the following is an International Standard in Security Management Systems?

Correct Answer: C. ISO 28000
Explanation:

ISO 28000 is an international standard that focuses on supply chain security management, based on the Deming Cycle (Plan, Do, Check, Act). Familiarity with ISO 27001 and ISO 27002 is also recommended. (P.130)


Question 5

Which of the following is a type of firewall?

Correct Answer: A. Proxy
Explanation:

A proxy is a type of firewall. It works at the IT application level rather than on a whole network. A firewall is a security measure that prevents unauthorized access to a system. P.184

Domain: 3.2


Question 6

Henry is the Head of IT at Purple Rain Ltd and is presenting a case to the Senior Leadership Team to ask for more investment in the company's IT strategy. Henry believes the company has an issue with data resilience and is asking for more money to be invested in this. He has completed a Business Impact Assessment (BIA) to better understand what data the company holds. Jon is the Head of Procurement and has listened intently to Henry's presentation. He has decided to go back to his department and complete a thorough risk assessment, as he is aware his team holds a lot of data on suppliers and contracts. The CEO of Purple Rain, Roger Nelson, has asked Henry about next steps in order to protect the company from further risks associated with the IT strategy. Data is currently stored on servers located at Purple Rain's Headquarters. The server room is locked at all times of the day and is only accessible to staff members who have a key. The building itself is extremely secure with CCTV systems located both inside the server room and outside it. However, the server room is prone to overheating.

What would Henry's BIA show?

Correct Answer: B. What system the data is held on
Explanation:

A Business Impact Assessment (BIA) identifies the systems in which data is stored, its origin, whether it is transferred elsewhere, and the company's ability to recover data. It does not assess funding issues or non-IT risks like cyberbullying. (P.104)


Question 7

Jamila is the Head of Procurement at Big Smiles Ltd. A few years ago, e-procurement systems were introduced, which has led to huge efficiency and transparency gains for the organisation. The tools that Jamila's team use include a PO system and supplier KPI monitoring system, which are accessed through a web portal. Which of the following statements are true?

Correct Answer: A. The benefit of web-based portals is that all users have the same version, so items can be shared more easily
Explanation:

Web-based portals allow all users to work on the same version, reducing maintenance costs. There is no limit to the number of users, and piracy risk is lower because data is stored in the cloud. (P.53)


Question 8

In relation to cyber security, what would be the benefit of a public sector organisation joining a Group Purchasing Organisation (GPO)?

Correct Answer: C. The GPO takes on the burden of checking suppliers' security policies and procedures
Explanation:

A GPO is the same as a Buying Consortium---it's when multiple organisations pool resources and procure together. The GPO/Consortium does the legwork for procurement activities such as vetting suppliers. This is one advantage of using them---they have the expertise to weed out unsuitable suppliers. Option A is a true statement but doesn't relate to cyber security. P.167

Domain: 3.1


Question 9

Bob is the CEO of Big Leaf Company and has a lot of sensitive data on his phone. The IT department has advised Bob he should increase his security measures to protect unwanted people accessing his phone, which he often leaves on his desk when he goes to Board Meetings. Which of the following would be most useful to Bob?

Correct Answer: B. Multi-factor authentication
Explanation:

Multi-factor authentication would be the most useful to protect a mobile phone. Multi-factor authentication uses three things: something you know (password), something you have (a secret code or token), and something you are (biometric scan). This is more secure than biometrics alone. CCTV does not prevent someone from accessing Bob's phone. A firewall is better suited for an IT system or intranet. P.187

Domain: 3.2


Question 10

Jumping Cucumbers Ltd is a food manufacturing organisation that uses Internet of Things (IoT) devices in production processes. Mohammed is the head of IT at the company and is considering ways of reducing the risks of technology security breaches. Which of the following would reduce the risks for his devices?

Correct Answer: B. Installing encryption software
Explanation:

Encryption software enhances the security of IoT devices by protecting data from unauthorized access. While secure passwords (Option A) and backups (Option C) are good cybersecurity practices, they do not specifically address IoT device security. A physical security guard (Option D) would not prevent remote cyber attacks. (P.176)