CCP CCP IT Governance, Risk & Compliance 2 — Questions and Answers
Question 1: ISO/IEC 27001 is an international standard for:
- Information security management systems (ISMS) (Correct answer)
- Software quality assurance
- Network equipment certification
- Cloud service provider auditing
Correct answer: Information security management systems (ISMS)
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an information security management system.
Question 2: Which compliance regulation specifically protects the privacy of US patients' health information?
- HIPAA (Correct answer)
- PCI DSS
- SOX
- GDPR
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes national standards for protecting sensitive patient health information in the US.
Question 3: A security audit trail is primarily used to:
- Record user activities and system events for accountability and forensic review (Correct answer)
- Monitor real-time network bandwidth utilization
- Automatically patch software vulnerabilities
- Manage user access provisioning workflows
Correct answer: Record user activities and system events for accountability and forensic review
Audit trails create a chronological record of system activities enabling detection of unauthorized actions and supporting incident investigation and compliance.
Question 4: The principle of least privilege means:
- Users should be granted only the minimum access rights necessary to perform their job (Correct answer)
- Administrators should use unprivileged accounts for daily tasks
- System services should run as root only when required
- Network ports should be opened only for active connections
Correct answer: Users should be granted only the minimum access rights necessary to perform their job
The principle of least privilege limits user and system access rights to the bare minimum required for their role, reducing the attack surface.
Question 5: PCI DSS compliance is required for organizations that:
- Store, process, or transmit payment card data (Correct answer)
- Employ more than 500 IT staff
- Operate in more than one US state
- Use open-source software in production
Correct answer: Store, process, or transmit payment card data
PCI DSS (Payment Card Industry Data Security Standard) applies to any entity that handles cardholder data to protect against payment fraud.
Question 6: Which IT governance framework uses a balanced scorecard approach to measure IT performance across four perspectives?
- COBIT (Correct answer)
- ITIL
- TOGAF
- PMBOK
Correct answer: COBIT
COBIT incorporates balanced scorecard concepts, measuring IT performance from financial, customer, internal process, and learning/growth perspectives.
ISO/IEC 27001 is an international standard for: