Skip to content
CY-703 (B) · Cyber Security Policies & Standards/Important Questions

Cyber Security Policies & Standards (CY-703 (B)) - Important Questions

  1. Unit 414 Marks High Priority

    Explain privacy policies and their specifications. Describe the essential components of a privacy policy, including roles (data subject, data controller, data processor), purposes, obligations, consent, enforcement mechanisms, audit trails, and accountability. Discuss how specifications capture access control, retention, purpose limitation and obligations for third-party sharing.

    Core topic from Unit 4; highly recurrent in analytics (privacy policies and their specifications).

  2. Unit 410 Marks Medium Priority

    Discuss privacy policy languages such as P3P, EPAL and XACML. Compare their expressive power, typical syntax/semantics, enforcement architectures, and suitability for web, enterprise and cross-organisational deployments. Provide examples of simple policy rules in at least one language.

    Directly addresses policy languages referenced in analytics; compares major specification approaches.

  3. Unit 47 Marks Medium Priority

    Explain how privacy policies can be specified for the medical domain. Cover patient consent models, purpose limitation (treatment, research, billing), minimum disclosure, emergency access (break-the-glass), retention, auditability and how policies map to enforcement mechanisms (role-based access control, purpose-based access).

    Specified in analytics as an important applied topic: domain-specific privacy policy specification (medical).

  4. Unit 47 Marks Medium Priority

    Explain how privacy policies can be specified for the financial domain. Discuss consent, transaction data handling, anti-fraud sharing, regulatory compliance requirements, third-party disclosure rules, retention, and technical enforcement (logging, strong access controls, encryption).

    Domain-specific policy formulation for finance: recurring applied question in Unit 4 context.

  5. Unit 414 Marks High Priority

    Describe Data Privacy Attacks with emphasis on data linking and profiling. Explain attack strategies (record linkage, attribute linkage, inferential profiling), give real-world examples of re-identification via linking datasets, and discuss mitigation techniques including anonymization approaches (k-anonymity, l-diversity, t-closeness), generalization and suppression, pseudonymization, access controls and policy-based disclosure limits. Analyse limitations and utility trade-offs of these techniques.

    Core Unit 4 topic per analytics: data privacy attacks, datalinking and profiling with mitigation techniques.

  6. Unit 410 Marks Low Priority

    Explain differential privacy. State the formal definition of $\epsilon$-differential privacy and describe the Laplace mechanism. Include the standard probabilistic guarantee: $$\Pr\left[\mathcal{M}\left(D\right)\in S\right] \le e^{\epsilon} \Pr\left[\mathcal{M}\left(D'\right)\in S\right]$$ for neighbouring databases $D$ and $D'$, and the Laplace noise scale $b = \frac{\Delta f}{\epsilon}$ where $\Delta f$ is the global sensitivity of the query $f$. Discuss composition and the privacy-utility trade-off.

    Foundational privacy-preserving mechanism often expected in advanced answers for Unit 4 topics.

Go to where you left off?

Quick Add to Notes

Save questions, your own notes and screenshots into notes filed by unit. It takes a free account.

Create free account

Have an account? Log in