โ† All ACT Flashcard Decks

Industry Regulations & Compliance Flashcards

7 cards from real ACT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Industry Regulations & Compliance flashcards as text
  1. An Apple Certified Trainer configures a Supervised iPhone for a financial firm. Which iOS feature, when disabled via MDM, helps the firm comply with insider-trading communication policies?

    Answer: AirDrop and personal hotspot restrictions

    Restricting AirDrop and hotspot prevents unmonitored data transfers, helping firms comply with financial communication oversight regulations like FINRA rules.

  2. Under Sarbanes-Oxley (SOX), which aspect of Apple device management is most relevant to IT general controls (ITGCs)?

    Answer: Access controls and audit logging for financial systems accessed from Apple devices

    SOX ITGCs require access controls, change management, and audit logging for systems that process financial data, including Apple devices accessing those systems.

  3. Which Apple configuraton profile payload is most directly used to enforce email archiving for regulatory retention requirements in an enterprise?

    Answer: Exchange ActiveSync or Mail payload with managed S/MIME settings

    The Exchange ActiveSync or Mail payload enables managed mail accounts with S/MIME signing, supporting email archiving solutions required by regulations like SEC Rule 17a-4.

  4. A trainer is asked about Apple's approach to law enforcement data requests. Which document publicly describes how Apple handles government requests for user data?

    Answer: Apple Transparency Report

    Apple publishes a Transparency Report that details government and private party requests for user data and how Apple responds to them.

  5. When configuring Apple devices for a publicly traded company, which log should be preserved to meet SEC electronic records retention rules?

    Answer: Business communication records including email and messaging through managed apps

    SEC rules require broker-dealers and public companies to retain business communications, which includes emails and messages sent through managed corporate apps.

  6. What is the significance of 'Managed Open In' restrictions in an MDM profile for a HIPAA-regulated organization?

    Answer: It prevents PHI from being transferred to unmanaged apps or personal storage

    Managed Open In ensures that documents opened in managed apps can only be shared with other managed apps, preventing PHI from leaking into personal apps.

  7. Which Apple security feature provides hardware-level attestation that a device has not been tampered with, relevant to compliance frameworks requiring device integrity verification?

    Answer: Secure Enclave and Apple's device attestation (DeviceCheck/App Attest)

    Apple's Secure Enclave and DeviceCheck/App Attest APIs provide cryptographic attestation of device integrity, supporting zero-trust and compliance frameworks that require verified device state.