← All CCP Flashcard Decks

Compliance, Legal, & Ethical Issues Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance, Legal, & Ethical Issues flashcards as text
  1. A cybersecurity professional is asked by their employer to exploit a competitor's systems to gather intelligence. What should they do?

    Answer: Refuse, as this constitutes unauthorized access and is illegal

    Accessing competitor systems without authorization violates the CFAA and cybersecurity ethics codes regardless of employer directives.

  2. Which concept requires that digital evidence be documented and secured from collection through court presentation to maintain its admissibility?

    Answer: Chain of custody

    Chain of custody documents every person who handled evidence and every action taken with it, ensuring the court can trust the evidence has not been tampered with.

  3. A US company receives a subpoena for data stored on servers in Germany. Which legal framework governs this cross-border data request?

    Answer: US-EU CLOUD Act agreements and GDPR transfer restrictions

    Cross-border data requests involve both the US CLOUD Act framework and GDPR transfer restrictions, requiring coordination between both legal regimes.

  4. Which NIST document provides a framework for improving critical infrastructure cybersecurity using a risk-based approach?

    Answer: NIST Cybersecurity Framework (CSF)

    The NIST Cybersecurity Framework (CSF) provides a risk-based approach organized around five core functions: Identify, Protect, Detect, Respond, and Recover.

  5. Under the ISC² Code of Ethics, which canon takes the HIGHEST priority when canons conflict?

    Answer: Protect society, the common good, necessary public trust and confidence, and the infrastructure

    The ISC² Code of Ethics prioritizes protecting society and the public good above all other professional obligations when conflicts arise.

  6. A healthcare organization implements de-identification to share patient data for research. Under HIPAA, which method involves removing 18 specific identifiers?

    Answer: Safe Harbor method

    HIPAA's Safe Harbor de-identification method requires removal of 18 specific categories of identifiers, after which data is no longer considered PHI.

  7. Which legal doctrine protects security researchers from CFAA liability when testing systems they are explicitly authorized to test?

    Answer: Authorization as a complete defense

    Explicit written authorization from the system owner is the primary legal defense against CFAA claims, as the law's core prohibition requires lack of authorization.