โ† All ACL Flashcard Decks

Compliance & Regulatory Frameworks Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance & Regulatory Frameworks flashcards as text
  1. Under HIPAA, which ACL configuration best protects electronic Protected Health Information (ePHI) at the network perimeter?

    Answer: Deny all traffic by default and permit only specific authorized connections to ePHI systems

    HIPAA requires a 'deny all, permit by exception' ACL posture to ensure only explicitly authorized traffic can reach systems holding ePHI.

  2. PCI DSS Requirement 1 mandates that cardholder data environments (CDE) be protected by firewalls. Which ACL practice specifically satisfies the requirement to restrict inbound and outbound traffic?

    Answer: Permitting only traffic with a documented business justification and blocking all other flows

    PCI DSS Requirement 1.2 demands that ACL rules permitting traffic into or out of the CDE must be documented with a specific business need.

  3. NIST SP 800-53 control AC-4 addresses Information Flow Enforcement. Which ACL scenario correctly implements this control?

    Answer: Restricting data transfers between systems classified at different sensitivity levels using ACL policies

    AC-4 requires organizations to enforce approved authorizations for controlling the flow of information between interconnected systems, typically implemented via ACLs.

  4. Under SOX IT controls, which ACL-related practice helps ensure the integrity of financial reporting systems?

    Answer: Segregating duties by using ACLs to prevent developers from accessing production financial systems

    SOX requires separation of duties, and ACLs are used to enforce that developers, test teams, and finance systems are network-isolated to prevent unauthorized changes.

  5. GDPR Article 32 requires appropriate technical measures to protect personal data. How do ACLs contribute to GDPR compliance?

    Answer: ACLs enforce network-level access restrictions that limit who can reach systems storing EU personal data

    GDPR Article 32 includes network security controls like ACLs as part of 'appropriate technical measures' to protect personal data from unauthorized access.

  6. A healthcare organization subject to HIPAA discovers that an ACL rule permits any host on the internal network to query their patient database server on port 1433. What is the compliance risk?

    Answer: The rule violates the Minimum Necessary standard by granting overly broad access to ePHI

    HIPAA's Minimum Necessary standard requires limiting access to ePHI to only those with a need to know, making a broad 'any internal host' rule non-compliant.

  7. Which compliance framework explicitly requires network segmentation enforced by ACLs or firewalls to isolate systems storing payment card data?

    Answer: PCI DSS

    PCI DSS Requirement 1 specifically mandates network segmentation to isolate the cardholder data environment using firewalls and ACLs.