200-201 exam dumps

200-201 practice question 387 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 387

Select 3

During a network security audit, you are tasked with identifying protected data being transmitted over the network. Which of the following types of data would typically require protection to meet compliance or regulatory requirements?

  1. A

    Social Security Numbers (SSNs) transmitted in plaintext

  2. B

    Publicly available information such as a company's website URL

  3. C

    Credit card numbers transmitted over an encrypted connection

  4. D

    Employee email addresses shared in an internal company document

  5. E

    Patient health records sent via an unencrypted email

  6. F

    System logs containing non-sensitive server performance metrics

Show answer and explanation

Correct answers: A, C, E

Explanation

Protected data refers to information that requires safeguarding due to its sensitive nature or regulatory requirements, such as Social Security Numbers, credit card details, or patient health records. Identifying such data ensures compliance with cybersecurity policies and prevents unauthorized access or data breaches. Non-sensitive or publicly available data typically does not require the same level of protection.

  • A. Correct.

    Social Security Numbers (SSNs) are considered sensitive personal information and must be protected during transmission. If transmitted in plaintext, they are at risk of interception and misuse.

  • B. Incorrect.

    Publicly available information, such as a company's website URL, does not require protection as it is not sensitive or private information.

  • C. Correct.

    Credit card numbers are classified as sensitive data under compliance regulations like PCI DSS. Even though they are transmitted over an encrypted connection, they are still considered protected data.

  • D. Incorrect.

    Employee email addresses shared in an internal company document are typically not classified as protected data unless combined with other sensitive information.

  • E. Correct.

    Patient health records fall under regulations like HIPAA and require protection. Sending them via unencrypted email poses a significant security and compliance risk.

  • F. Incorrect.

    System logs containing non-sensitive server performance metrics do not generally contain protected data and therefore do not require special handling.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam