CCB CCB Data Privacy & Information Security Compliance 1 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), what right allows consumers to request deletion of their personal information?
- Right to erasure (Correct answer)
- Right to opt-out
- Right to portability
- Right to access
Correct answer: Right to erasure
The CCPA grants consumers the right to request deletion (erasure) of personal information collected by a business, subject to certain exceptions.
Question 2: Which U.S. federal law establishes minimum data security standards for financial institutions, including safeguard rules for customer information?
- HIPAA
- Gramm-Leach-Bliley Act (GLBA) (Correct answer)
- Sarbanes-Oxley Act
- FISMA
Correct answer: Gramm-Leach-Bliley Act (GLBA)
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to implement safeguards to protect customers' nonpublic personal information.
Question 3: A data breach notification requirement typically mandates reporting within how many hours under U.S. federal banking regulations?
- 24 hours
- 36 hours (Correct answer)
- 72 hours
- 96 hours
Correct answer: 36 hours
The FFIEC/OCC Computer-Security Incident Notification Rule requires banking organizations to notify their primary federal regulator within 36 hours of discovering a significant cybersecurity incident.
Question 4: Which of the following best describes 'data minimization' as a privacy compliance principle?
- Encrypting all collected data
- Collecting only data necessary for a specific purpose (Correct answer)
- Storing data in the smallest possible file format
- Limiting data access to senior management only
Correct answer: Collecting only data necessary for a specific purpose
Data minimization requires organizations to collect only the personal data that is adequate, relevant, and limited to what is necessary for the stated purpose.
Question 5: In the context of information security compliance, what does a 'data inventory' primarily help an organization accomplish?
- Track employee productivity
- Map where personal data is collected, stored, and shared (Correct answer)
- Calculate the monetary value of company data
- Automate data deletion schedules
Correct answer: Map where personal data is collected, stored, and shared
A data inventory (or data map) identifies what personal data an organization holds, where it resides, how it flows, and who has access — foundational to privacy compliance.
Question 6: Which framework is most commonly used by U.S. organizations to assess and improve cybersecurity risk management practices?
- ISO 27001
- NIST Cybersecurity Framework (CSF) (Correct answer)
- SOC 2 Type II
- PCI DSS
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides a voluntary, risk-based approach to managing cybersecurity risk and is widely adopted by U.S. organizations across industries.
Under the California Consumer Privacy Act (CCPA), what right allows consumers to request deletion of their personal information?