โ† All ACL Flashcard Decks

Compliance & Regulatory Frameworks Flashcards

7 cards from real ACL practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance & Regulatory Frameworks flashcards as text
  1. A retail company must comply with PCI DSS and uses ACLs to segment their point-of-sale network. Which traffic flow would violate PCI DSS Requirement 1.3?

    Answer: Allowing direct inbound internet traffic to reach POS terminals without passing through a DMZ

    PCI DSS Requirement 1.3 prohibits direct inbound internet access to any component in the cardholder data environment; all internet traffic must traverse a DMZ.

  2. Under HIPAA's Security Rule, a covered entity implements role-based ACLs granting nurses access to patient records but not billing data. Which HIPAA principle does this demonstrate?

    Answer: Minimum Necessary standard limiting ePHI access to what is needed for job functions

    The Minimum Necessary standard requires covered entities to limit access to ePHI to only the information needed to perform a specific function, exactly as role-based ACLs enforce.

  3. An organization subject to CMMC (Cybersecurity Maturity Model Certification) Level 2 must implement AC.L2-3.1.3 (Control CUI Flow). Which ACL mechanism satisfies this requirement?

    Answer: Implementing ACL policies that restrict Controlled Unclassified Information to approved pathways and destinations

    CMMC AC.L2-3.1.3 requires controlling the flow of CUI, which is implemented through ACLs that restrict CUI to authorized network paths and destinations.

  4. During a FedRAMP assessment, an auditor evaluates SC-7 (Boundary Protection) for a cloud service provider. Which ACL finding would result in a deficiency?

    Answer: External boundary ACLs that permit unrestricted outbound connections from systems processing federal data

    FedRAMP SC-7 requires controlling both inbound and outbound traffic; unrestricted outbound connections from federal systems violate the boundary protection control.

  5. NIST SP 800-171 Requirement 3.13.1 requires monitoring, controlling, and protecting organizational communications at external boundaries. What ACL configuration directly implements this?

    Answer: Configuring perimeter ACLs that enforce allowed traffic protocols and deny all other flows at CUI system boundaries

    NIST SP 800-171 3.13.1 requires boundary protection controls including ACLs that define and enforce what traffic is permitted at system perimeters protecting CUI.

  6. A cloud environment must comply with CSA CCM (Cloud Controls Matrix). Which ACL-related practice addresses the IVS-09 (Network Security) control?

    Answer: Implementing virtual network ACLs and security groups to restrict traffic between cloud tenants and workloads

    CSA CCM IVS-09 requires implementing network security controls including ACLs and security groups to isolate cloud workloads and prevent unauthorized lateral movement.

  7. Under FERPA, a university uses ACLs to protect student education records. Which ACL rule set best aligns with FERPA requirements?

    Answer: Restrict student record system access to authenticated staff systems with documented educational need, blocking all other sources

    FERPA requires that education records be accessible only to school officials with a legitimate educational interest, which ACLs enforce by restricting network access to authorized systems.