โ† All CCP Flashcard Decks

Compliance, Legal, & Ethical Issues Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance, Legal, & Ethical Issues flashcards as text
  1. Under the Computer Fraud and Abuse Act (CFAA), which activity is explicitly prohibited?

    Answer: Accessing a protected computer without authorization

    The CFAA prohibits unauthorized access to protected computers, including federal and financial systems and those used in interstate commerce.

  2. A company operating in California must comply with CCPA. Which right does CCPA grant consumers that HIPAA does NOT specifically provide?

    Answer: Right to opt out of the sale of their personal information

    CCPA grants California consumers the right to opt out of the sale of their personal information, which is a consumer-focused right not mirrored in HIPAA's healthcare-centric framework.

  3. Which ethical principle requires a cybersecurity professional to avoid conflicts of interest and remain objective in assessments?

    Answer: Objectivity

    Objectivity requires professionals to provide unbiased assessments free from personal or financial conflicts of interest.

  4. An organization subject to SOX must maintain internal controls over financial reporting. Which IT control directly supports SOX compliance?

    Answer: Access control logs showing who modified financial data

    SOX Section 404 requires controls ensuring the integrity of financial data; audit logs of financial system access directly demonstrate those controls.

  5. A security researcher discovers a zero-day vulnerability in a vendor's product. According to responsible disclosure ethics, what should they do FIRST?

    Answer: Notify the vendor privately and allow time to patch

    Responsible disclosure requires notifying the vendor first and providing reasonable time to develop and release a patch before any public disclosure.

  6. Which law requires US federal agencies to implement information security programs and report security incidents to Congress?

    Answer: FISMA

    The Federal Information Security Modernization Act (FISMA) mandates that federal agencies develop, document, and implement information security programs.

  7. A penetration tester is asked to test systems owned by a client but hosted by a third-party cloud provider. What document is MOST critical before testing begins?

    Answer: Written authorization from both the client and the cloud provider

    Cloud providers own the underlying infrastructure; testing without their permission may violate their terms of service and laws even with client consent.