CCCP Technology & Data Compliance 3 — Questions and Answers
Question 1: A financial institution must comply with the Gramm-Leach-Bliley Act (GLBA). Which rule specifically requires the institution to implement an information security program?
- Privacy Rule
- Pretexting Rule
- Safeguards Rule (Correct answer)
- Financial Rule
Correct answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer financial data.
Question 2: Under SOC 2 auditing standards, which Trust Services Criteria category addresses whether the system is available for operation and use as committed?
- Security
- Availability (Correct answer)
- Processing Integrity
- Confidentiality
Correct answer: Availability
The Availability criteria in SOC 2 evaluates whether systems and information are accessible for operation and use as promised in service level agreements.
Question 3: Which technique renders personal data permanently anonymous by removing all identifiers so that re-identification is no longer possible?
- Pseudonymization
- Tokenization
- Anonymization (Correct answer)
- Encryption
Correct answer: Anonymization
Anonymization irreversibly removes all identifying information so data can no longer be linked to an individual, distinguishing it from pseudonymization which is reversible.
Question 4: A company's AI algorithm is found to systematically deny loans to applicants from certain zip codes that correlate with racial demographics. This scenario raises concerns under which compliance area?
- Export control regulations
- Algorithmic bias and fair lending laws (Correct answer)
- HIPAA technical safeguards
- SEC disclosure requirements
Correct answer: Algorithmic bias and fair lending laws
Algorithmic decision-making that produces disparate impact based on protected characteristics violates fair lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act.
Question 5: What is the standard maximum fine for a GDPR violation categorized as a Tier 2 infringement (most serious)?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 5% of global annual turnover
- €100 million or 10% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR Tier 2 violations, such as breaching core principles or data subject rights, carry fines up to €20 million or 4% of total worldwide annual turnover, whichever is higher.
Question 6: An organization stores credit card numbers and wants to reduce PCI DSS scope. Which method replaces card data with a randomly generated surrogate value that retains no exploitable value?
- Hashing
- Tokenization (Correct answer)
- Masking
- Truncation
Correct answer: Tokenization
Tokenization substitutes sensitive card data with a non-sensitive token that has no exploitable value, effectively reducing the systems that fall within PCI DSS scope.
Question 7: Under the FTC Act Section 5, what type of data security practice can constitute an unfair or deceptive act?
- Implementing multi-factor authentication
- Failing to implement reasonable data security measures after promising consumers their data is secure (Correct answer)
- Conducting annual penetration tests
- Encrypting data in transit using TLS 1.2 or higher
Correct answer: Failing to implement reasonable data security measures after promising consumers their data is secure
The FTC has authority to take action against companies that fail to implement reasonable data security, particularly when their practices contradict privacy policy promises made to consumers.
A financial institution must comply with the Gramm-Leach-Bliley Act (GLBA).
Which rule specifically requires the institution to implement an information security program?