CCP Compliance, Legal, & Ethical Issues 2 — Questions and Answers
Question 1: Under the Computer Fraud and Abuse Act (CFAA), which activity is explicitly prohibited?
- Performing authorized penetration tests
- Accessing a protected computer without authorization (Correct answer)
- Encrypting data on your own systems
- Monitoring your own network traffic
Correct answer: Accessing a protected computer without authorization
The CFAA prohibits unauthorized access to protected computers, including federal and financial systems and those used in interstate commerce.
Question 2: A company operating in California must comply with CCPA. Which right does CCPA grant consumers that HIPAA does NOT specifically provide?
- Right to access their data
- Right to correct inaccurate data
- Right to opt out of the sale of their personal information (Correct answer)
- Right to data security protections
Correct answer: Right to opt out of the sale of their personal information
CCPA grants California consumers the right to opt out of the sale of their personal information, which is a consumer-focused right not mirrored in HIPAA's healthcare-centric framework.
Question 3: Which ethical principle requires a cybersecurity professional to avoid conflicts of interest and remain objective in assessments?
- Confidentiality
- Integrity
- Non-maleficence
- Objectivity (Correct answer)
Correct answer: Objectivity
Objectivity requires professionals to provide unbiased assessments free from personal or financial conflicts of interest.
Question 4: An organization subject to SOX must maintain internal controls over financial reporting. Which IT control directly supports SOX compliance?
- Network segmentation for DMZ zones
- Access control logs showing who modified financial data (Correct answer)
- Antivirus signature update schedules
- Wireless encryption standards
Correct answer: Access control logs showing who modified financial data
SOX Section 404 requires controls ensuring the integrity of financial data; audit logs of financial system access directly demonstrate those controls.
Question 5: A security researcher discovers a zero-day vulnerability in a vendor's product. According to responsible disclosure ethics, what should they do FIRST?
- Publish full exploit details immediately to warn the public
- Notify the vendor privately and allow time to patch (Correct answer)
- Sell the exploit to the highest bidder
- Report it directly to law enforcement
Correct answer: Notify the vendor privately and allow time to patch
Responsible disclosure requires notifying the vendor first and providing reasonable time to develop and release a patch before any public disclosure.
Question 6: Which law requires US federal agencies to implement information security programs and report security incidents to Congress?
- FERPA
- FISMA (Correct answer)
- GLBA
- ECPA
Correct answer: FISMA
The Federal Information Security Modernization Act (FISMA) mandates that federal agencies develop, document, and implement information security programs.
Question 7: A penetration tester is asked to test systems owned by a client but hosted by a third-party cloud provider. What document is MOST critical before testing begins?
- A non-disclosure agreement with the client
- Written authorization from both the client and the cloud provider (Correct answer)
- A statement of work from the client only
- An insurance certificate covering the tester
Correct answer: Written authorization from both the client and the cloud provider
Cloud providers own the underlying infrastructure; testing without their permission may violate their terms of service and laws even with client consent.
Under the Computer Fraud and Abuse Act (CFAA), which activity is explicitly prohibited?