ACT Industry Regulations & Compliance 3 — Questions and Answers
Question 1: Under the Americans with Disabilities Act (ADA), what must an organization consider when deploying Apple devices for public-facing services?
- Devices must run the latest iOS version
- Accessibility features must be available and content must meet WCAG standards (Correct answer)
- All devices must have cellular connectivity
- Screen Time must be disabled
Correct answer: Accessibility features must be available and content must meet WCAG standards
ADA requirements include making digital services accessible; Apple's built-in accessibility features and WCAG-compliant content help satisfy these obligations.
Question 2: Which Apple configuration prevents users from disabling FileVault on a company Mac, supporting data-at-rest encryption mandates?
- Gatekeeper enforcement
- MDM FileVault management with deferred enablement and escrow (Correct answer)
- System Integrity Protection (SIP)
- iCloud Drive encryption
Correct answer: MDM FileVault management with deferred enablement and escrow
MDM can manage FileVault by enabling deferred enablement and escrowing the recovery key, ensuring encryption cannot be disabled by end users.
Question 3: A trainer deploys an app that processes credit card data on iPads at a retail store. Which compliance standard applies to cardholder data protection?
- HIPAA
- GLBA
- PCI DSS (Correct answer)
- FISMA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) governs how organizations handle, store, and transmit payment cardholder data.
Question 4: What role does Apple's 'App Transport Security' (ATS) play in regulatory compliance for iOS apps?
- It verifies app developer identities
- It enforces HTTPS connections, helping apps meet data-in-transit encryption requirements (Correct answer)
- It blocks sideloading of unauthorized apps
- It restricts background app refresh
Correct answer: It enforces HTTPS connections, helping apps meet data-in-transit encryption requirements
ATS enforces the use of HTTPS and strong TLS, helping iOS apps comply with regulations that mandate encryption of data in transit.
Question 5: When a school district in the US must comply with COPPA, what is the minimum age threshold below which parental consent is required for collecting children's personal data?
- 16
- 14
- 13 (Correct answer)
- 18
Correct answer: 13
COPPA (Children's Online Privacy Protection Act) requires verifiable parental consent before collecting personal data from children under 13.
Question 6: Which Apple Business Manager feature helps an organization comply with software license management audits?
- Managed Apple IDs
- Apps and Books (Volume Purchase Program) with license assignment tracking (Correct answer)
- iCloud storage allocation
- Configurator 2 blueprints
Correct answer: Apps and Books (Volume Purchase Program) with license assignment tracking
Apps and Books in Apple Business Manager tracks app license assignments, providing an auditable record to demonstrate software license compliance.
Question 7: In the context of the EU's GDPR applied to a US company with EU customers using an Apple app, what is the 'right to erasure' obligation?
- The company must delete the app from the App Store upon request
- The company must delete a user's personal data upon request within required timeframes (Correct answer)
- The company must erase all device data remotely
- The company must remove the user's Apple ID
Correct answer: The company must delete a user's personal data upon request within required timeframes
GDPR Article 17 grants individuals the right to request deletion of their personal data, and the organization must comply within 30 days.
Under the Americans with Disabilities Act (ADA), what must an organization consider when deploying Apple devices for public-facing services?