CoStudy

HomeCertificationsCPA ISC › Data management

Data management — CPA ISC practice questions

77 multiple-choice questions and 79 flashcards on Data management, about 20% of the CPA ISC bank. Every one carries a written rationale.

Written and maintained by Nick Burton · last updated 2026-08-22 · how we write and review questions

What this chapter covers

Data management is one of 5 chapters in CoStudy's CPA — Information Systems & Controls (ISC) [Discipline] bank, and it holds 77 of the bank's 378 multiple-choice questions — roughly 20% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.

Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.

Free Data management practice questions

10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.

Mobile Device Management (MDM) solutions in a BYOD (Bring Your Own Device) environment are primarily used to:

  1. Enforce security policies (e.g., encryption, passcode requirements, remote wipe capability) on devices accessing corporate resources, while typically separating corporate and personal data
  2. Physically confiscate all employee-owned devices used for work purposes
  3. Eliminate the need for any data classification policy
  4. Guarantee that employees will never lose their personal devices

Answer: A — Enforce security policies (e.g., encryption, passcode requirements, remote wipe capability) on devices accessing corporate resources, while typically separating corporate and personal data

B) MDM manages devices remotely through policy enforcement; it doesn't involve physically confiscating employee-owned devices. A) Correct — MDM enforces security policies (encryption, passcode/biometric requirements, remote wipe if lost/stolen) on devices accessing corporate data, often using containerization to separate corporate and personal data on the same device. C) MDM enforces policies but doesn't replace the need for an underlying data classification scheme informing what data warrants protection. D) MDM mitigates the IMPACT of device loss (via remote wipe, encryption) but cannot prevent the physical loss of a device from occurring in the first place.

Combining NIST CSF and ISO 22301, an organization mapping its cybersecurity Recover function activities to its ISO 22301-aligned BCMS would MOST reasonably:

  1. Treat these as entirely separate, non-overlapping programs with no coordination whatsoever
  2. Recognize meaningful overlap and coordinate them, since both address restoring operations after a disruptive event, with NIST CSF's Recover function activities often directly supporting or aligning with the organization's broader ISO 22301 business continuity and disaster recovery plans
  3. Assume ISO 22301 addresses only marketing recovery, unrelated to any technical restoration process
  4. Conclude that NIST CSF's Recover function has no relationship whatsoever to business continuity planning

Answer: B — Recognize meaningful overlap and coordinate them, since both address restoring operations after a disruptive event, with NIST CSF's Recover function activities often directly supporting or aligning with the organization's broader ISO 22301 business continuity and disaster recovery plans

A) Treating these as fully separate ignores their natural overlap in addressing post-disruption recovery, a shared underlying objective. B) Correct — both frameworks address restoring operations after disruption; NIST CSF's Recover function (recovery planning, improvements, communications) naturally aligns with and can support the broader ISO 22301 BCMS's recovery/continuity plans, and organizations commonly coordinate the two rather than running them in silos. C) ISO 22301 addresses organizational business continuity broadly, including but not limited to technical system recovery, not marketing recovery specifically. D) NIST CSF's Recover function is directly and substantively related to business continuity/disaster recovery planning, the core subject of ISO 22301.

GDPR's extraterritorial reach means that:

  1. GDPR applies exclusively to companies physically headquartered within EU member state borders
  2. GDPR can apply to organizations outside the EU that offer goods/services to, or monitor the behavior of, individuals within the EU, regardless of where the organization itself is located
  3. GDPR has no applicability whatsoever to any organization outside the EU under any circumstances
  4. GDPR applies only to organizations with fewer than ten employees

Answer: B — GDPR can apply to organizations outside the EU that offer goods/services to, or monitor the behavior of, individuals within the EU, regardless of where the organization itself is located

A) Limiting GDPR strictly to EU-headquartered companies ignores its well-known extraterritorial reach, a defining and frequently tested feature of the regulation. B) Correct — GDPR's extraterritorial scope means it can apply to organizations located anywhere in the world if they offer goods/services to, or monitor the behavior of, individuals within the EU, regardless of the organization's own physical location. C) This directly contradicts GDPR's deliberately broad extraterritorial applicability, a central and well-known aspect of the regulation. D) GDPR's applicability isn't determined by employee headcount thresholds in this manner; it depends on the nature of data processing activities and their connection to EU individuals.

Within ISO 22301, a Business Continuity Plan (BCP) is developed based primarily on findings from:

  1. The organization's marketing campaign performance data
  2. The Business Impact Analysis (BIA) and risk assessment, which identify critical processes, impact severity, and recovery priorities/objectives (RTO/RPO/MTD)
  3. The organization's annual employee satisfaction survey results exclusively
  4. A random selection process with no analytical basis

Answer: B — The Business Impact Analysis (BIA) and risk assessment, which identify critical processes, impact severity, and recovery priorities/objectives (RTO/RPO/MTD)

A) Marketing campaign performance is unrelated to business continuity planning inputs. B) Correct — ISO 22301-aligned BCPs are built on BIA and risk assessment findings, which identify which processes are most critical, the severity of potential disruption impacts, and the recovery objectives (RTO, RPO, MTD) that should drive continuity planning and resourcing decisions. C) Employee satisfaction survey data doesn't drive BCP development, though workforce continuity may be A consideration within the broader BIA. D) BCP development is a deliberate, analytically grounded process based on BIA/risk assessment findings, not a random selection exercise.

Robotic Process Automation (RPA) is best described as software that:

  1. Trains neural networks to make novel predictions from unstructured data
  2. Provisions cloud servers automatically through infrastructure-as-code
  3. Mimics user actions across UIs to automate rule-based repetitive tasks
  4. Detects security incidents at endpoints using behavior-based analysis

Answer: C — Mimics user actions across UIs to automate rule-based repetitive tasks

A) That describes machine learning, not RPA. C) Correct — RPA automates rule-based UI-level tasks like a virtual user. B) That describes IaC tools like Terraform, not RPA. D) That describes EDR, not RPA.

A comprehensive ISC synthesis scenario asks a candidate to evaluate an organization's overall risk posture using SDLC/Agile control maturity, BIA/BCP readiness, key management practices, API security, MDM/BYOD policy, and physical security together. The BEST approach is to:

  1. Evaluate each area in isolation with no attempt to connect findings into an overall risk conclusion
  2. Synthesize findings across all six areas — for example, recognizing that weak SDLC controls on a high-BIA-criticality application, combined with unmanaged API rate limiting and inconsistent MDM enforcement, compound into an elevated overall risk profile requiring prioritized remediation
  3. Focus only on physical security, since it is listed last, and ignore the other five areas
  4. Conclude the six areas are entirely unrelated and cannot inform one overall assessment

Answer: B — Synthesize findings across all six areas — for example, recognizing that weak SDLC controls on a high-BIA-criticality application, combined with unmanaged API rate limiting and inconsistent MDM enforcement, compound into an elevated overall risk profile requiring prioritized remediation

A) Isolated single-area review misses the exam's clear intent to test integrated judgment across development, continuity, cryptographic, application, mobile, and physical security domains together. B) Correct — the ISC exam (and real-world risk assessment) rewards synthesizing findings across all relevant areas, recognizing how weaknesses compound (e.g., weak SDLC rigor on a critical app, missing API protections, and inconsistent MDM enforcement together elevate overall risk beyond what any single gap would suggest alone). C) Arbitrarily focusing on one area based on list position ignores the substantive risk contributions of the other five areas. D) These six areas are interconnected in a real technology risk environment, and a well-reasoned synthesis integrating all of them is both possible and expected.

Privacy by design, a principle embedded in GDPR and modern privacy frameworks, means that:

  1. Privacy considerations are addressed only after a system has been fully built and deployed
  2. Privacy is solely the legal department's responsibility with no input from engineering
  3. Privacy protections are proactively embedded into the design and architecture of systems and business practices from the outset
  4. Privacy by design applies only to mobile applications, not web or backend systems

Answer: C — Privacy protections are proactively embedded into the design and architecture of systems and business practices from the outset

A) Addressing privacy only after deployment is the opposite of the 'by design' principle. C) Correct — privacy by design requires proactively building privacy protections into systems and processes from the earliest design stages, not bolting them on afterward. B) Privacy by design is a cross-functional discipline involving engineering, product, and legal together, not legal alone. D) The principle applies broadly across all systems and platforms, not just mobile apps.

Cross-border data transfer mechanisms, such as Standard Contractual Clauses (SCCs), are used primarily to:

  1. Apply only to transfers of physical paper documents, never to electronic data
  2. Eliminate the need for any data protection safeguards during international transfers
  3. Provide a legally recognized framework for transferring personal data internationally (e.g., from the EU to a country without an adequacy decision) while maintaining required data protection safeguards
  4. Guarantee unlimited government access to the transferred data

Answer: C — Provide a legally recognized framework for transferring personal data internationally (e.g., from the EU to a country without an adequacy decision) while maintaining required data protection safeguards

C) Correct — SCCs are pre-approved contractual clauses that provide a recognized legal mechanism for transferring personal data across borders (e.g., outside the EU/EEA to jurisdictions lacking an adequacy determination) while contractually obligating the parties to maintain adequate data protection safeguards. B) SCCs specifically EXIST to impose and maintain data protection safeguards during international transfers, not eliminate them. A) SCCs apply to personal data transfers generally, predominantly electronic data in modern contexts, not just physical paper documents. D) SCCs are designed to protect data and limit inappropriate access, not to guarantee government access; unrestricted government access would undermine their entire purpose.

A key control weakness in backup programs that auditors frequently identify is:

  1. Encryption of backup media that prevents the tapes from being read by unauthorized users
  2. Automatic replication of backups to a geographically separated secondary storage location
  3. Failure to periodically test that backups can actually be restored to a usable state
  4. Rotation of backup media on a defined schedule to a secure offsite storage facility

Answer: C — Failure to periodically test that backups can actually be restored to a usable state

A) Encryption is a control strength, not weakness. B) Replication is a strength, not weakness. C) Correct — untested backups often fail when finally needed. D) Rotation is a strength, not weakness.

A resilient enterprise database backup strategy typically follows the 3-2-1 rule of:

  1. Three full backups per week on two disks stored in one office cabinet
  2. Three restore tests annually, two auditors, and one signed attestation
  3. Three encryption keys, two administrators, and one physical safe copy
  4. Three copies of data on two different media with one copy off-site

Answer: D — Three copies of data on two different media with one copy off-site

A) That misstates the rule — it's about copies, not frequency alone. D) Correct — the 3-2-1 rule: 3 copies, 2 media types, 1 off-site. C) That confuses backup with key management. B) That is a testing schedule, not the 3-2-1 rule.

Data management flashcards

4 cards from the 79 in this chapter.

Normalization purpose?

Reduce data redundancy and prevent update anomalies by splitting data across related tables.

Adequacy decision (GDPR)?

European Commission determination that a non-EU country provides adequate data protection, allowing transfers without extra safeguards like SCCs.

What drives Business Continuity Plan (BCP) development under ISO 22301?

The BIA and risk assessment, identifying critical processes, impact severity, and recovery objectives (RTO/RPO/MTD).

Recovery Point Objective (RPO)?

Maximum acceptable data loss, expressed as the point in time to which data must be recoverable after an incident.

Practise the full chapter

These are a sample. The full Data management chapter runs 156 items with per-chapter progress tracking, on the web and in the iOS app.

Open CPA ISC in CoStudy →

Other CPA ISC chapters

All CPA ISC practice questions →