ACT Industry Regulations & Compliance 2 — Questions and Answers
Question 1: Under FERPA, which entity has primary responsibility for protecting student education records at a K-12 school using Apple devices?
- Apple Inc.
- The educational institution (Correct answer)
- The student's parents only
- The device manufacturer
Correct answer: The educational institution
FERPA places responsibility on the educational institution to safeguard student education records, regardless of the technology platform used.
Question 2: An Apple Certified Trainer is deploying iPads in a healthcare clinic. Which regulation primarily governs the protection of patient health information on those devices?
- FERPA
- COPPA
- HIPAA (Correct answer)
- GDPR
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) governs the protection of protected health information (PHI) in US healthcare settings.
Question 3: A trainer is setting up Apple School Manager for a district. Which MDM configuration helps enforce CIPA compliance for student internet access?
- Enabling AirDrop for all users
- Configuring content filtering restrictions via MDM profile (Correct answer)
- Disabling iCloud backup
- Enabling developer mode on student devices
Correct answer: Configuring content filtering restrictions via MDM profile
CIPA requires schools to implement internet filtering, which can be enforced through MDM content restriction profiles in Apple School Manager.
Question 4: Which Apple platform feature allows an organization to enforce a passcode policy to meet SOC 2 compliance requirements?
- Screen Time
- MDM configuration profile with passcode payload (Correct answer)
- iCloud Keychain
- Apple Business Chat
Correct answer: MDM configuration profile with passcode payload
MDM configuration profiles with a passcode payload enforce minimum passcode length, complexity, and expiration across managed devices to satisfy SOC 2 controls.
Question 5: When deploying Macs in a US federal agency, which security framework do Apple devices need to align with for government use?
- ISO 27001
- NIST SP 800-53 / FedRAMP (Correct answer)
- PCI DSS
- SOX
Correct answer: NIST SP 800-53 / FedRAMP
US federal agencies use NIST SP 800-53 controls and FedRAMP authorization as the standard security framework for IT systems including Apple devices.
Question 6: A company collects biometric data via an iOS app for employee authentication. Which US state law most directly regulates the collection of biometric identifiers?
- California Consumer Privacy Act (CCPA)
- Illinois Biometric Information Privacy Act (BIPA) (Correct answer)
- New York SHIELD Act
- Virginia Consumer Data Protection Act
Correct answer: Illinois Biometric Information Privacy Act (BIPA)
Illinois BIPA specifically regulates the collection, storage, and use of biometric identifiers such as fingerprints and facial geometry.
Question 7: What is the primary purpose of Apple's 'Activation Lock' feature in the context of regulatory compliance for device asset management?
- It encrypts all data on the device
- It prevents unauthorized reactivation, supporting chain-of-custody and theft-deterrence compliance requirements (Correct answer)
- It enforces app purchase policies
- It blocks access to non-approved App Store apps
Correct answer: It prevents unauthorized reactivation, supporting chain-of-custody and theft-deterrence compliance requirements
Activation Lock ties the device to an Apple ID, preventing unauthorized reuse and supporting asset tracking and loss-prevention compliance obligations.
Under FERPA, which entity has primary responsibility for protecting student education records at a K-12 school using Apple devices?