Home › Certifications › CPA ISC › Data management
77 multiple-choice questions and 79 flashcards on Data management, about 20% of the CPA ISC bank. Every one carries a written rationale.
Data management is one of 5 chapters in CoStudy's CPA — Information Systems & Controls (ISC) [Discipline] bank, and it holds 77 of the bank's 378 multiple-choice questions — roughly 20% of the total. That proportion is not arbitrary: chapters follow the certifying body's published exam outline, and the number of questions in each is set by that domain's published weight, so the share of your practice time this chapter takes matches the share of the real exam it accounts for.
Studying by chapter is worth doing once you have a diagnostic score. A single overall percentage tells you whether you are close; it does not tell you which domain is dragging. Working a weak chapter in isolation, and re-testing it in isolation, is the fastest way to move a score that has stalled — and it is why the mock exams in CoStudy report by domain rather than as one number.
10 questions drawn from this chapter, with the full rationale shown — the controlling principle behind the right answer, and why each wrong option tempts and fails.
Mobile Device Management (MDM) solutions in a BYOD (Bring Your Own Device) environment are primarily used to:
Answer: A — Enforce security policies (e.g., encryption, passcode requirements, remote wipe capability) on devices accessing corporate resources, while typically separating corporate and personal data
B) MDM manages devices remotely through policy enforcement; it doesn't involve physically confiscating employee-owned devices. A) Correct — MDM enforces security policies (encryption, passcode/biometric requirements, remote wipe if lost/stolen) on devices accessing corporate data, often using containerization to separate corporate and personal data on the same device. C) MDM enforces policies but doesn't replace the need for an underlying data classification scheme informing what data warrants protection. D) MDM mitigates the IMPACT of device loss (via remote wipe, encryption) but cannot prevent the physical loss of a device from occurring in the first place.
Combining NIST CSF and ISO 22301, an organization mapping its cybersecurity Recover function activities to its ISO 22301-aligned BCMS would MOST reasonably:
Answer: B — Recognize meaningful overlap and coordinate them, since both address restoring operations after a disruptive event, with NIST CSF's Recover function activities often directly supporting or aligning with the organization's broader ISO 22301 business continuity and disaster recovery plans
A) Treating these as fully separate ignores their natural overlap in addressing post-disruption recovery, a shared underlying objective. B) Correct — both frameworks address restoring operations after disruption; NIST CSF's Recover function (recovery planning, improvements, communications) naturally aligns with and can support the broader ISO 22301 BCMS's recovery/continuity plans, and organizations commonly coordinate the two rather than running them in silos. C) ISO 22301 addresses organizational business continuity broadly, including but not limited to technical system recovery, not marketing recovery specifically. D) NIST CSF's Recover function is directly and substantively related to business continuity/disaster recovery planning, the core subject of ISO 22301.
GDPR's extraterritorial reach means that:
Answer: B — GDPR can apply to organizations outside the EU that offer goods/services to, or monitor the behavior of, individuals within the EU, regardless of where the organization itself is located
A) Limiting GDPR strictly to EU-headquartered companies ignores its well-known extraterritorial reach, a defining and frequently tested feature of the regulation. B) Correct — GDPR's extraterritorial scope means it can apply to organizations located anywhere in the world if they offer goods/services to, or monitor the behavior of, individuals within the EU, regardless of the organization's own physical location. C) This directly contradicts GDPR's deliberately broad extraterritorial applicability, a central and well-known aspect of the regulation. D) GDPR's applicability isn't determined by employee headcount thresholds in this manner; it depends on the nature of data processing activities and their connection to EU individuals.
Within ISO 22301, a Business Continuity Plan (BCP) is developed based primarily on findings from:
Answer: B — The Business Impact Analysis (BIA) and risk assessment, which identify critical processes, impact severity, and recovery priorities/objectives (RTO/RPO/MTD)
A) Marketing campaign performance is unrelated to business continuity planning inputs. B) Correct — ISO 22301-aligned BCPs are built on BIA and risk assessment findings, which identify which processes are most critical, the severity of potential disruption impacts, and the recovery objectives (RTO, RPO, MTD) that should drive continuity planning and resourcing decisions. C) Employee satisfaction survey data doesn't drive BCP development, though workforce continuity may be A consideration within the broader BIA. D) BCP development is a deliberate, analytically grounded process based on BIA/risk assessment findings, not a random selection exercise.
Robotic Process Automation (RPA) is best described as software that:
Answer: C — Mimics user actions across UIs to automate rule-based repetitive tasks
A) That describes machine learning, not RPA. C) Correct — RPA automates rule-based UI-level tasks like a virtual user. B) That describes IaC tools like Terraform, not RPA. D) That describes EDR, not RPA.
A comprehensive ISC synthesis scenario asks a candidate to evaluate an organization's overall risk posture using SDLC/Agile control maturity, BIA/BCP readiness, key management practices, API security, MDM/BYOD policy, and physical security together. The BEST approach is to:
Answer: B — Synthesize findings across all six areas — for example, recognizing that weak SDLC controls on a high-BIA-criticality application, combined with unmanaged API rate limiting and inconsistent MDM enforcement, compound into an elevated overall risk profile requiring prioritized remediation
A) Isolated single-area review misses the exam's clear intent to test integrated judgment across development, continuity, cryptographic, application, mobile, and physical security domains together. B) Correct — the ISC exam (and real-world risk assessment) rewards synthesizing findings across all relevant areas, recognizing how weaknesses compound (e.g., weak SDLC rigor on a critical app, missing API protections, and inconsistent MDM enforcement together elevate overall risk beyond what any single gap would suggest alone). C) Arbitrarily focusing on one area based on list position ignores the substantive risk contributions of the other five areas. D) These six areas are interconnected in a real technology risk environment, and a well-reasoned synthesis integrating all of them is both possible and expected.
Privacy by design, a principle embedded in GDPR and modern privacy frameworks, means that:
Answer: C — Privacy protections are proactively embedded into the design and architecture of systems and business practices from the outset
A) Addressing privacy only after deployment is the opposite of the 'by design' principle. C) Correct — privacy by design requires proactively building privacy protections into systems and processes from the earliest design stages, not bolting them on afterward. B) Privacy by design is a cross-functional discipline involving engineering, product, and legal together, not legal alone. D) The principle applies broadly across all systems and platforms, not just mobile apps.
Cross-border data transfer mechanisms, such as Standard Contractual Clauses (SCCs), are used primarily to:
Answer: C — Provide a legally recognized framework for transferring personal data internationally (e.g., from the EU to a country without an adequacy decision) while maintaining required data protection safeguards
C) Correct — SCCs are pre-approved contractual clauses that provide a recognized legal mechanism for transferring personal data across borders (e.g., outside the EU/EEA to jurisdictions lacking an adequacy determination) while contractually obligating the parties to maintain adequate data protection safeguards. B) SCCs specifically EXIST to impose and maintain data protection safeguards during international transfers, not eliminate them. A) SCCs apply to personal data transfers generally, predominantly electronic data in modern contexts, not just physical paper documents. D) SCCs are designed to protect data and limit inappropriate access, not to guarantee government access; unrestricted government access would undermine their entire purpose.
A key control weakness in backup programs that auditors frequently identify is:
Answer: C — Failure to periodically test that backups can actually be restored to a usable state
A) Encryption is a control strength, not weakness. B) Replication is a strength, not weakness. C) Correct — untested backups often fail when finally needed. D) Rotation is a strength, not weakness.
A resilient enterprise database backup strategy typically follows the 3-2-1 rule of:
Answer: D — Three copies of data on two different media with one copy off-site
A) That misstates the rule — it's about copies, not frequency alone. D) Correct — the 3-2-1 rule: 3 copies, 2 media types, 1 off-site. C) That confuses backup with key management. B) That is a testing schedule, not the 3-2-1 rule.
4 cards from the 79 in this chapter.
Normalization purpose?
Reduce data redundancy and prevent update anomalies by splitting data across related tables.
Adequacy decision (GDPR)?
European Commission determination that a non-EU country provides adequate data protection, allowing transfers without extra safeguards like SCCs.
What drives Business Continuity Plan (BCP) development under ISO 22301?
The BIA and risk assessment, identifying critical processes, impact severity, and recovery objectives (RTO/RPO/MTD).
Recovery Point Objective (RPO)?
Maximum acceptable data loss, expressed as the point in time to which data must be recoverable after an incident.
These are a sample. The full Data management chapter runs 156 items with per-chapter progress tracking, on the web and in the iOS app.