Chapter 14 Compliance Frameworks Flashcards

1
Q

What must a government agency consider when planning to store sensitive data with a global CSP?

A. Data sovereignty
B. Data ownership
C. Data classification
D. Data retention

A

A. Data sovereignty

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Who is accountable for the storage and protection of customer data?
They must ensure that they implement controls to meet legal and regulatory requirements

A. Data controller
B. Data protection officer
D. Data processor
D. Supervisory Authority

A

A. Data controller

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

A CISO is assessing regulatory requirements for hospital employees and patient data (within Europe). What typer of information will need to be protected and which regulation will be most important?

A. GDPR
B. Financial records
C. Intellectual property
D. PII
E. COPPA

A

A. GDPR
E. COPPA

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

A multinational company wants the assurance that data will not be accessible when their contract with a CSP expires. What technology may be application?

A. Crypto erase
B. Pulping
C. Shredding
D. Degaussing

A

A. Crypto erase

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

A global automobile manufacturer must ensure that its products are compatible with its worldwide customer base. What regulations or standards will be most important?

A. Export control regulations
B. General Data Protection Regulation (GDPR)
C. International Organization for Standardization (ISO)
D. National Institute of Standards and Technology (NIST)

A

C. International Organization for Standardization (ISO)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

A SaaS provider has several products designed to attach a young audience, while revenue is generated by advertising and subscriptions with the US. What regulations will be the most important for the provider?

A. Capability Maturity Model Integration (CMMI)
B. National Institute of Standards and Technology (NIST)
C. Children’s Online Privacy Protection Act (COPPA)
D. Cloud Security Alliance (CSA) Security Trust Assurance and Risk (STAR)

A

C. Children’s Online Privacy Protection Act (COPPA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

A SaaS provider has several commercial products to assist with an automobile manufacturer. They must assure potential customers that the cloud provider is secure and trustworthy. What accreditation can the SaaS provider attain to appeal to its customers?

A. International Organization for Standardization (ISO)
B. Capability Maturity Model Integration (CMMI)
C. National Institute of Standards and Technology (NIST)
D. Cloud Security Alliance (CSA) Security Trust Assurance and Risk (STAR)

A

D. Cloud Security Alliance (CSA) Security Trust Assurance and Risk (STAR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

A software development company is trying to win a contract for a US Federal Government Agency. They must assure the customer that they have a robust security framework for the delivery of software and services. What is the most relevant?

A. International Organizattion for Standardization (ISO)
B. Capability Maturity Model Integration (CMMI)
C. National Institute of Standards and Technology (NIST)
D. Cloud Security Alliance (CSA) Security Trust Assurance and Risk (STAR)

A

B. Capability Maturity Model Integration (CMMI)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

What compliance will be most important to a US based e-commerce retailer with respect to thee storage of cardholder data and electronic transactions?

A. Payment Card Industry Data Security Standard (PCI DSS)
B. International Organization for Standardization
C. Interconnection security Agreement (ISA)
D. Non disclosure agreement (NDA)

A

A. Payment Card Industry Data Security Standard (PCI DSS)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

A smartcard manufacturer needs to sell product to a global market. They need to show compliance using internationally agreed upon protocols. What would be a useful accreditation or assurance that their products have been evaluated and will meet the security requirements of their customers?

A. Internal Organization for Standardization (ISO)
B. Capability Maturity Model Integration (CMMI)
C. National Institute of Standards and Technology (NIST)
D. Common Criteria

A

D. Common Criteria

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

What regulatory body is intended to protect the personal data of EU citizens?

A. General Data Protection Regulation (GDPR)
B. National Institute of Standards and Technology (NIST)
C. International Organization for Standardization (ISO)
D. Common Criteria (CC)

A

A. General Data Protection Regulation (GDPR)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
12
Q

A US Smartcard manufacturer needs to sell its products in a global market. The y need to ensure that the technology is not sold to countries or governments hostile to the US. What guidance or regulations should they consult?

A. Due care
B. Export controls
C. Legal holds
D. E Discovery

A

B. Export controls

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
13
Q

A governement department has data privacy requirements and they need to have employees and service providers sign this agreement. They should be made aware of the strict terms of this agreement and the penalties that may be forthcoming. What type of agreement will be important?

A. Service Level Agreement (SLA)
B. Master Service Agreement (MSA)
C. Non-disclosure agreement (NDA)
D. Memorandum of understanding (MOU)

A

C. Non-disclosure agreement (NDA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
14
Q

A large multinational company intends to purchase multiple products on a rolling contract from a CSP. They need to document payment terms, dispute resolution, intellectual property ownership and geographic operational locations within the scope of the contract. What type of contract would be most suitable?

A. Service level agreement (SLA)
B. Master Service Agreement (MSA)
C. Memorandum of understanding (MOU)
D. Operational level agreement (OLA)

A

B. Master Service Agreement (MSA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
15
Q

An organization would like to build resiliency into its network connections. They are working with an ISP that proposes a highly available MPLS solution. To ensure the vendor is able to deliver the service with 99.999% uptime, what documentation will be important?

A. Service level agreement (SLA)
B. Memorandum of understanding (MOU)
C. Interconnection security agreement (ISA)
D. Operational Level Agreement (OLA)

A

A. Service level agreement (SLA)

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
16
Q

What agreement should be used when business partners need to share data? This agreement may stipulate a timeline for the information exchange to be supported, security requirements, data types that will be exchanged and the actual sites that will be part of the data interchange.

A. Service level agreement (SLA)
B. Master service agreement (MSA)
C. Memorandum of understanding (MOU)
D. Interconnection security agreement (ISA)

A

D. Interconnection security agreement (ISA)

17
Q

What agreement ensures that the customer data will be protected by the service provider and that agree upon steps are in place if data breaches or any adverse action were to occur?

A. Non disclosure agreement (NDA)
B. Memorandum of understanding (MOU)
C. Interconnection security agreement (ISA)
D. Operational level agreement (OLA)
E. Privacy Level Agreement (PLA)

A

E. Privacy Level Agreement (PLA)

18
Q

An investigation is to be performed on an employee suspected of stealing company Intellectual Property (IP). What must be done first to ensure that the data is not deleted?

A. Due care
B. Export controls
C. Legal holds
D. E-discovery

A

C. Legal holds

19
Q

An investigation is to be performed on an employee suspected of stealing company Intellectual Property (IP). There are over 10GB of data stored across several information systems. What must be done to ensure that the relevant data is collected?

A. Due care
B. Export controls
C. Legal holds
D. E-discovery

A

D. E-discovery

20
Q

What document may be used when business partners need to document responsibilities? This document will not be written by lawyers is intended to formalize a verbal agreement or a handshake

A. Service level agreement (SLA)
B. Master service agreement (MSA)
C. Memorandum of understanding (MOU)
D. Interconnection security agreement (ISA)

A

C. Memorandum of understanding (MOU)