CFS136 · Principles of Information Security

Chapter 10 Review: Data Protection and Privacy

A hands-on review station for data classification, data states, protection techniques, data loss prevention, secure destruction, and the privacy roles and regulations from Chapter 10.

Start Here

Six review stations, each a different way to practice Chapter 10. Work through them in any order. Nothing here is graded or stored, so use it as many times as you like before the quiz or the exam.

What this chapter asked you to be able to do

  • Classify data by sensitivity level (public, internal, confidential, critical/restricted) and choose handling controls that match the risk.
  • Explain the security challenges and controls for the three data states: at rest, in transit, and in use.
  • Differentiate the data protection techniques (encryption, tokenization, masking, anonymization, pseudonymization) and apply each to the right scenario.
  • Describe how data loss prevention (DLP) protects data across endpoints, networks, and cloud services.
  • Explain data retention and secure destruction, including degaussing, shredding, and cryptographic erasure.
  • Identify the privacy roles (controller, processor, steward, data protection officer) and the obligations set by GDPR, CCPA/CPRA, and HIPAA.

Your progress this session

These counters update as you check answers on each station. They reset when you reload the page.

0/20Terms viewed
0/6Data states correct
0/5Classifications correct
0/6Techniques matched
0/7Roles matched
0/10Quiz correct
How to use each station Make a choice, then select Check to see whether it holds up and why. Every answer includes the reasoning, so a wrong pick is a chance to reread the logic rather than just the label. Keyboard users can move between tabs with the arrow keys.