exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 170 discussion

Actual exam question from Cisco's 200-201
Question #: 170
Topic #: 1
[All 200-201 Questions]

Which category relates to improper use or disclosure of PII data?

  • A. legal
  • B. compliance
  • C. regulated
  • D. contractual
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
addpro7
Highly Voted 1 year, 7 months ago
Selected Answer: C
Many regulations as well as the United States government require organizations to identify personally identifiable information (PII) and protected health information (PHI) and handle them in a secure manner. Unauthorized release or loss of such data could result in severe fines and penalties for the organization. Given the importance of PII and PHI, regulators and the government want to oversee the usage more efficiently. This section explains what PII and PHI are. based on page 158, section PERSONALLY IDENTIFIABLE INFORMATION AND PROTECTED HEALTH INFORMATION of: Cisco CyberOps Associate CBROPS 200-201 Official Cert Guide by Omar Santos
upvoted 5 times
...
drdecker100
Most Recent 9 months, 2 weeks ago
Selected Answer: B
The category that relates to improper use or disclosure of personally identifiable information (PII) data is the compliance category. Compliance refers to adhering to legal and regulatory requirements, as well as internal policies and procedures, to protect sensitive data and ensure the confidentiality, integrity, and availability of information. Compliance requirements often include data protection regulations that mandate how PII data should be collected, stored, and processed, and require organizations to take measures to prevent unauthorized access or disclosure of PII.
upvoted 3 times
...
Interrogantis
10 months ago
Selected Answer: C
The improper use or disclosure of Personally Identifiable Information (PII) data is a regulated issue. NIST SP 800-53 and SP 800-171 provide specific guidelines for protecting PII data, including security requirements for non-federal information systems and organizations that process, store, or transmit Controlled Unclassified Information (CUI), which includes PII data. These guidelines address areas such as access control, incident response, and media protection, and aim to ensure the confidentiality, integrity, and availability of PII data. Organizations are expected to comply with these regulations and guidelines, and failure to do so may result in legal consequences.
upvoted 2 times
...
CiscoTerminator
2 years ago
What are question: I would flag this in a Cisco exam. Key word here is "improper" and still PII data is "regulated" if you dont "comply" then "legal" ramifications will follow the organisation.
upvoted 3 times
...
Alannn
2 years, 2 months ago
I think legal is the correct answer aswell: An organization that is subject to any obligations to protect PII should consider such obligations when determining the PII confidentiality impact level. Many organizations are subject to laws, regulations, or other mandates36 governing the obligation to protect personal information,37 such as the Privacy Act of 1974, OMB memoranda, and the Health Insurance Portability and Accountability Act of 1996 (HIPAA). Additionally, some Federal agencies, such as the Census Bureau and the Internal Revenue Service (IRS), are subject to additional specific legal obligations to protect certain types of PII.
upvoted 1 times
...
anonymous1966
2 years, 3 months ago
"A" should be correct. With GDPR (General Data Protection Regulation) I believe is Legal. The other alternative are mere consequences. But.... For certification exam, I believe "C" is the right alternative, because inside the companies this information is Regulated.
upvoted 4 times
...
qz999
2 years, 3 months ago
Seems to me that the correct answer is 'compliance', as compliance must be maintained for all applicable laws, regulations, and contracts.
upvoted 3 times
...
beowolf
2 years, 8 months ago
PII is related to compliance requirement. This question is not clear. When it comes to PII, its about collection minimization and storing the collected data securely such as encryption or use tokenization therefore this is a compliance requirement.
upvoted 3 times
beowolf
2 years, 7 months ago
I am not sure about the correct answer, improper use of PII is perhaps related to law or regulated.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...