CGRC Regulatory Requirements 3 — Questions and Answers
Question 1: Under the California Consumer Privacy Act (CCPA), consumers have the right to opt out of which specific activity?
- Collection of their personal information
- Sale of their personal information (Correct answer)
- Processing of their sensitive data
- Sharing of data with government agencies
Correct answer: Sale of their personal information
CCPA grants California consumers the right to opt out of the sale of their personal information to third parties by notifying the business.
Question 2: The Basel III framework primarily applies to which type of organization?
- Insurance companies
- Healthcare organizations
- Banks and financial institutions (Correct answer)
- Government agencies
Correct answer: Banks and financial institutions
Basel III is an international regulatory framework developed by the Basel Committee on Banking Supervision to strengthen regulation, supervision, and risk management of banks.
Question 3: Which regulation requires broker-dealers and investment advisers to maintain books and records and make them available to regulators for inspection?
- SOX Section 802
- SEC Rule 17a-4 (Correct answer)
- FINRA Rule 4370
- Regulation S-P
Correct answer: SEC Rule 17a-4
SEC Rule 17a-4 specifies the record retention requirements for broker-dealers, including the media, format, and accessibility of electronic records.
Question 4: Under NERC CIP standards, what is the primary purpose of the BES Cyber System categorization (High, Medium, Low)?
- Determining penalty amounts for violations
- Identifying the applicable security requirements for each system (Correct answer)
- Establishing incident response priorities
- Setting backup frequency requirements
Correct answer: Identifying the applicable security requirements for each system
NERC CIP categorizes BES Cyber Systems as High, Medium, or Low impact to determine which security requirements apply, with stricter controls for higher-impact systems.
Question 5: The EU AI Act's risk-based approach classifies AI systems into tiers. Which category faces an outright ban?
- High-risk AI systems
- General-purpose AI systems
- Unacceptable risk AI systems (Correct answer)
- Limited-risk AI systems
Correct answer: Unacceptable risk AI systems
The EU AI Act prohibits AI systems classified as posing unacceptable risk, such as social scoring systems or real-time biometric surveillance in public spaces.
Question 6: Which provision of the Bank Secrecy Act (BSA) requires financial institutions to file a report when a cash transaction exceeds $10,000?
- Suspicious Activity Report (SAR)
- Currency Transaction Report (CTR) (Correct answer)
- Foreign Bank Account Report (FBAR)
- FinCEN Form 112
Correct answer: Currency Transaction Report (CTR)
The BSA requires financial institutions to file a Currency Transaction Report (CTR) for cash transactions exceeding $10,000 to help detect money laundering.
Question 7: Under SOC 2 reporting, which Trust Services Criteria category addresses the availability of systems and data?
- Security
- Availability (Correct answer)
- Confidentiality
- Processing Integrity
Correct answer: Availability
The Availability Trust Services Criterion in SOC 2 addresses whether systems and information are available for operation and use as committed or agreed upon.
Under the California Consumer Privacy Act (CCPA), consumers have the right to opt out of which specific activity?