CCSP Legal, Risk, and Compliance 2 — Questions and Answers
Question 1: Which regulation requires organizations that handle payment card data to comply with a set of security standards?
- HIPAA
- SOX
- PCI DSS (Correct answer)
- FERPA
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for all organizations that store, process, or transmit cardholder data.
Question 2: What is vendor lock-in risk in cloud computing and how does it affect compliance?
- The risk of a vendor going bankrupt
- Dependency on a single cloud provider's proprietary technology making migration difficult, which can affect data portability rights under regulations like GDPR (Correct answer)
- The risk of a vendor increasing prices
- A compliance requirement to use only approved vendors
Correct answer: Dependency on a single cloud provider's proprietary technology making migration difficult, which can affect data portability rights under regulations like GDPR
Vendor lock-in can conflict with GDPR's right to data portability and make it difficult for organizations to switch providers or comply with data residency requirements.
Question 3: What is the purpose of a cloud service level agreement (SLA) from a risk and compliance perspective?
- To define the cloud provider's marketing commitments
- To contractually define performance, availability, and security obligations, establishing accountability and remedies for non-compliance (Correct answer)
- To set employee performance targets
- To specify the price per GB of cloud storage
Correct answer: To contractually define performance, availability, and security obligations, establishing accountability and remedies for non-compliance
An SLA establishes measurable service commitments and financial penalties, giving customers contractual recourse if the provider fails to meet security, availability, or compliance obligations.
Question 4: In the context of cloud eDiscovery, what is the primary challenge compared to on-premises environments?
- Cloud providers have too much storage
- Data may be distributed across multiple jurisdictions and commingled with other tenants' data, complicating legal hold and collection (Correct answer)
- Cloud systems cannot produce logs
- eDiscovery tools do not work on cloud data
Correct answer: Data may be distributed across multiple jurisdictions and commingled with other tenants' data, complicating legal hold and collection
Cloud eDiscovery challenges include multi-jurisdictional data storage, commingling of data across tenants, and limited customer access to enforce legal holds on provider-managed infrastructure.
Question 5: Which risk treatment option involves transferring the financial impact of a risk to a third party?
- Risk acceptance
- Risk avoidance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial consequences of a risk to a third party, most commonly through cyber liability insurance or contractual indemnification clauses.
Question 6: What does the FedRAMP program require cloud service providers to do before selling to US federal agencies?
- Obtain PCI DSS certification
- Achieve a standardized security authorization based on NIST 800-53 controls through third-party assessment (Correct answer)
- Complete an ISO 27001 audit
- Register with the FBI Cyber Division
Correct answer: Achieve a standardized security authorization based on NIST 800-53 controls through third-party assessment
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach to security assessment and authorization for cloud services sold to US federal agencies.
Which regulation requires organizations that handle payment card data to comply with a set of security standards?