Legal, Risk, and Compliance Flashcards
6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 6 Legal, Risk, and Compliance flashcards as text
Which framework provides a set of controls specifically designed to assess the security of cloud service providers?
Answer: Cloud Security Alliance (CSA) Cloud Controls Matrix (CCM)
The CSA Cloud Controls Matrix (CCM) is a cybersecurity control framework specifically designed for cloud computing, mapping controls to regulatory standards and cloud service models.
What is the primary purpose of a Business Associate Agreement (BAA) in the context of HIPAA compliance in the cloud?
Answer: To legally obligate a cloud vendor handling PHI to comply with HIPAA security and privacy requirements
A BAA is a legally binding contract required by HIPAA whenever a covered entity shares protected health information (PHI) with a third-party service provider.
What type of audit report provides a detailed description of a service organization's controls but is intended for restricted distribution?
Answer: SOC 2 Type II
SOC 2 Type II reports provide detailed descriptions and evidence of controls over a period of time and are restricted to customers and stakeholders under NDA.
What is the primary focus of the EU General Data Protection Regulation (GDPR) as it applies to cloud computing?
Answer: Protection of EU residents' personal data and enforcement of privacy rights including consent, access, and erasure
GDPR mandates how organizations collect, process, store, and delete EU residents' personal data, imposing strict consent requirements, data subject rights, and breach notification obligations.
In cloud risk management, what does quantitative risk analysis produce that qualitative analysis does not?
Answer: Numerical estimates of risk in monetary terms (e.g., Annual Loss Expectancy)
Quantitative risk analysis calculates numerical values such as ALE (Annual Loss Expectancy) = ARO × SLE, enabling cost-benefit comparison of security controls.
What is the role of the Data Protection Officer (DPO) under GDPR?
Answer: To ensure the organization complies with GDPR, advise on data protection obligations, and act as a contact for supervisory authorities
The DPO is an independent role required by GDPR for certain organizations to oversee data protection strategy, ensure compliance, and liaise with data protection authorities.