IIBA-CBDA · IIBA · Secure, Manage and Document Data · Bank updated 2026-07-02
IIBA-CBDA practice questions: Secure, Manage and Document Data
5 free questions from 49 on this area · answer and explanation for each · no sign-up
These 5 questions come from the Secure, Manage and Document Data section of our IIBA-CBDA bank (49 questions on this area). Every question is original, with the correct answer explained and linked to the source it is drawn from.
1/5 · Secure, Manage and Document Data · easy
While documenting an analytics dataset, an analyst records the field names, data types, allowed value ranges, the source system, and the date each record was last refreshed. A new team member needs this information to understand and trust the dataset before using it. What is the analyst documenting?
ATransactional data
BMaster data
CMetadata
DReference data
Show answer & explanation
C is correct. Field names, data types, allowed ranges, source system, and refresh dates are classic examples of metadata—'data about data'—which supports discoverability, understanding, and trust. Master, transactional, and reference data refer to categories of business content rather than the descriptive layer.
↗ IIBA Business Data Analytics Guide — Secure, Manage and Document Data
2/5 · Secure, Manage and Document Data
A security review of an analytics platform confirms that all client connections to the reporting portal use TLS, so data is protected while moving over the network. However, the review flags that the underlying database files and nightly backup archives are stored as plain, readable files on disk. An attacker who obtained a copy of a backup file could read all of it directly. Which additional protection most directly addresses this gap?
AEncryption at rest for the database files and backup archives
BStronger TLS cipher suites on the reporting portal
CA web application firewall in front of the portal
DMore frequent backups to reduce the recovery point objective
Show answer & explanation
A is correct. Encryption in transit (TLS) and encryption at rest protect data in different states. TLS protects data while it moves across the network; it does nothing once data is written to disk. The flagged risk — readable database files and backup archives — is a data-at-rest exposure, so encryption at rest is the direct mitigation, ensuring stolen files or backups are useless without the decryption keys. Tuning TLS, increasing backup frequency, or adding a WAF addresses other concerns but leaves the stored, readable files exposed.
↗ IIBA Business Data Analytics Guide — Secure, Manage and Document Data
3/5 · Secure, Manage and Document Data
Two analysts argue over what 'active customer' means: one applies a 90-day rule, the other a 12-month rule, and the term is defined differently in three reports. Leadership wants a single agreed, plain-language definition of each business term — independent of any physical table or column — so that everyone interprets metrics the same way. Which artifact is purpose-built to hold these shared, technology-agnostic term definitions?
AAn entity-relationship diagram
BA data lineage diagram
CA business glossary
DA data dictionary
Show answer & explanation
C is correct. A business glossary holds agreed, plain-language, technology-agnostic definitions of business terms so that metrics are interpreted consistently. It is distinct from a data dictionary (technical/physical structure of fields), lineage (flow/transformation traceability), and an ERD (structural relationships). When the problem is disagreement over the meaning of a term rather than its storage, the glossary is the correct artifact.
↗ IIBA Business Data Analytics Guide — Secure, Manage and Document Data
4/5 · Secure, Manage and Document Data
An analyst inherits a critical reporting pipeline whose original author has left. The code runs, but nobody can explain why certain currency conversions, exclusion filters, and deduplication steps exist, what assumptions they encode, or which downstream reports depend on them. A new regulation now requires changes, and the team is afraid to touch anything. What documentation practice would most directly have prevented this situation?
AStoring more frequent database backups of the output tables
BEncrypting the source datasets the pipeline reads from
CDocumenting each transformation step with its purpose, business rules, assumptions, and downstream dependencies so the pipeline's logic is understandable independent of any individual
DAdding stricter role-based access controls to the pipeline code
Show answer & explanation
C is correct. The failure is undocumented logic: the team cannot explain the purpose, business rules, assumptions, or downstream impact of each transformation, creating fear of change-induced breakage. The directly preventive practice is thorough transformation/pipeline documentation that captures the why and the dependencies so the logic survives staff turnover and supports safe, auditable change. Backups, access controls, and encryption address loss, permissions, and confidentiality respectively—none preserves the missing knowledge.
↗ IIBA Business Data Analytics Guide — Secure, Manage and Document Data
5/5 · Secure, Manage and Document Data · hard
In a finance analytics group, one analyst currently writes the transformation logic that adjusts revenue figures, runs it in production, and also approves the resulting numbers for the board report. An auditor flags this arrangement as a control weakness. Which principle should be applied to address the auditor's concern?
AData minimization — reduce the number of revenue fields the analyst can access
BSeparation of duties — split the conflicting responsibilities so the person who builds or changes the logic is not the same person who approves or releases its output
CEncryption in transit — protect the revenue figures as they move to the board report
DData retention scheduling — define how long the revenue adjustments are kept
Show answer & explanation
B is correct. Securing data and processes includes governance controls such as separation of duties, which ensures that no single individual controls all steps of a sensitive process. Splitting who authors transformation logic, who runs it, and who approves the output reduces the opportunity for undetected error or fraud. Minimization, encryption, and retention address different concerns and leave the conflicting combination of responsibilities intact.
↗ IIBA Business Data Analytics Guide — Secure, Manage and Document Data
Other IIBA-CBDA areas
The same kind of free sample for every other section of the IIBA-CBDA bank:
Study Secure, Manage and Document Data with instant feedback
6 free questions · filter study mode by area and difficulty · error log with spaced repetition · no card, no dumps, no ads.
Create your free account →
Read next
ECBA vs CCBA vs CBAP: Which IIBA Certification Fits Your Experience Level? (2026)
ECBA, CCBA or CBAP? The eligibility gate that picks for you, what the 2026 ECBA rewrite changed, and each credential's three-year cost, verified against IIBA.
PMI-PBA vs CBAP: The Business Analysis Certification Decision, Settled with Data
PMI-PBA ($405-555, 36 months of experience) vs CBAP ($495-650 all-in, 7,500 hours plus references): eligibility, exam mechanics, three-year cost, salary data.
ExamDeck is an independent study tool, not affiliated with IIBA®. IIBA-CBDA and BABOK® are trademarks of the International Institute of Business Analysis. Exam facts checked against official IIBA materials (as of August 2026); confirm current details on iiba.org.