โ† All ACE Flashcard Decks

Industry Regulations & Compliance Flashcards

7 cards from real ACE practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Industry Regulations & Compliance flashcards as text
  1. The Sarbanes-Oxley Act (SOX) Section 802 makes it a federal crime to destroy, alter, or falsify records in what context?

    Answer: Federal investigations and bankruptcy proceedings

    SOX Section 802 criminalizes destruction or falsification of records in connection with federal investigations and bankruptcy proceedings, with penalties up to 20 years imprisonment.

  2. When a forensic examiner works on a case involving a publicly traded company, which obligation does SOX impose regarding electronic records retention?

    Answer: Audit work papers must be retained for 7 years

    SOX requires auditors to retain audit work papers and related records for 7 years after completing the audit.

  3. Under the Federal Rules of Civil Procedure (FRCP) Rule 37(e), what sanction may a court impose if a party fails to preserve electronically stored information (ESI) due to a failure to take reasonable steps?

    Answer: Adverse inference instructions to the jury

    FRCP Rule 37(e) allows courts to instruct the jury to draw an adverse inference against a party that failed to preserve ESI through culpable conduct.

  4. Which NIST publication provides the primary framework for computer security incident handling and is commonly referenced in forensic compliance procedures?

    Answer: NIST SP 800-61

    NIST SP 800-61, 'Computer Security Incident Handling Guide,' is the foundational reference for establishing incident response procedures in compliance frameworks.

  5. A forensic investigator is examining a healthcare organization's systems. Under HIPAA's Security Rule, which category of safeguards requires workforce training and security policies?

    Answer: Administrative safeguards

    HIPAA's Administrative Safeguards include workforce security training, security management processes, and written policies โ€” the organizational rather than technical controls.

  6. What is the primary legal concern when a forensic examiner acquires a forensic image of an employee's personal smartphone that was used for both business and personal purposes?

    Answer: Fourth Amendment and employee privacy rights under state law

    BYOD investigations raise Fourth Amendment issues and state privacy law concerns because employees retain a reasonable expectation of privacy in personal data on their devices.

  7. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to implement a comprehensive information security program primarily to protect what type of information?

    Answer: Nonpublic personal information (NPI) of customers

    GLBA's Safeguards Rule mandates that financial institutions protect nonpublic personal information (NPI) of their customers through a written, comprehensive security program.

Industry Regulations & Compliance Flashcards โ€” ACE Study Cards with Answers