Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 6 Question 3 Discussion

Cybersecurity regulations typically require that enterprises demonstrate that they can protect:
C) personal data of customers and employees.
A) applications and technology systems.
B) trade secrets and other intellectual property.
D) business continuity and disaster recovery.

IIBA-CCA Exam - Topic 6 Question 3 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 3
Topic #: 6
[All IIBA-CCA Questions]

Cybersecurity regulations typically require that enterprises demonstrate that they can protect:

Show Suggested Answer Hide Answer
Suggested Answer: C

Cybersecurity regulations most commonly focus on the protection of personal data, because misuse or exposure can directly harm individuals through identity theft, fraud, discrimination, or loss of privacy. Privacy and data-protection laws typically require organizations to implement appropriate safeguards to protect personal information across its lifecycle, including collection, storage, processing, sharing, and disposal. In cybersecurity governance documentation, this obligation is often expressed through requirements to maintain confidentiality and integrity of personal data, limit access based on business need, and ensure accountability through logging, monitoring, and audits.

Demonstrating protection of personal data generally includes having a documented data classification scheme, clearly defined lawful purposes for processing, retention limits, and secure handling procedures. Technical controls commonly expected include strong authentication, least privilege and role-based access control, encryption for data at rest and in transit, secure key management, endpoint and server hardening, vulnerability management, and continuous monitoring for suspicious activity. Operational capabilities such as incident response, breach detection, and timely notification processes are also emphasized because regulators expect organizations to manage and report material data exposures appropriately.

While protecting applications, intellectual property, and ensuring continuity are important security objectives, they are not the primary focus of many cybersecurity regulations in the same consistent way as personal data protection. Therefore, the best answer is personal data of customers and employees.


Contribute your Thoughts:

0/2000 characters
Pansy
4 days ago
I agree, but A is also important. If apps are compromised, everything else is at risk.
upvoted 0 times
...
Ruthann
9 days ago
I think C is the most critical. Protecting personal data is essential.
upvoted 0 times
...
Vashti
14 days ago
D matters for overall resilience. But C should be the priority.
upvoted 0 times
...
Ricki
19 days ago
B is key too. Losing trade secrets can ruin a business.
upvoted 0 times
...
Stephanie
24 days ago
I agree, but A is also important. If apps are compromised, data is at risk.
upvoted 0 times
...
Ciara
29 days ago
I think C is the most critical. Protecting personal data is essential.
upvoted 0 times
...
Wilburn
1 month ago
I thought it was all about applications and systems!
upvoted 0 times
...
Jessenia
1 month ago
Business continuity? Seems like a stretch for cybersecurity.
upvoted 0 times
...
Mari
3 months ago
Wait, are we really required to protect trade secrets?
upvoted 0 times
...
Ashton
3 months ago
A and B are super important too!
upvoted 0 times
...
Lyndia
3 months ago
Definitely C, personal data is a big deal!
upvoted 0 times
...
Macy
3 months ago
Not sure if all companies actually follow these regulations...
upvoted 0 times
...
Owen
4 months ago
Totally agree with D, business continuity is crucial!
upvoted 0 times
...
Lilli
4 months ago
Wait, are we really required to protect trade secrets too?
upvoted 0 times
...
Audrie
4 months ago
I think A is just as important, though.
upvoted 0 times
...
Mirta
4 months ago
Definitely C, personal data is a big deal!
upvoted 0 times
...
Raul
4 months ago
This seems similar to a case study we did on compliance, where protecting intellectual property was highlighted as a key area.
upvoted 0 times
...
Herminia
4 months ago
I’m leaning towards option C, but I vaguely recall discussions about business continuity being important too.
upvoted 0 times
...
Justine
5 months ago
I remember a practice question that emphasized trade secrets, but I feel like applications and systems are also crucial.
upvoted 0 times
...
Tanja
5 months ago
I think the focus is mostly on protecting personal data, but I’m not entirely sure if that’s the only requirement.
upvoted 0 times
...

Save Cancel