CGRC Regulatory Requirements 4 — Questions and Answers
Question 1: Which GDPR principle requires that personal data be collected for specified, explicit, and legitimate purposes and not further processed in incompatible ways?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
The GDPR's purpose limitation principle requires that personal data be collected only for specified, explicit, and legitimate purposes and not processed beyond those purposes.
Question 2: Under the Children's Online Privacy Protection Act (COPPA), what is the age threshold below which parental consent is required before collecting personal information?
- 13 years old (Correct answer)
- 16 years old
- 17 years old
- 18 years old
Correct answer: 13 years old
COPPA requires operators of websites and online services to obtain verifiable parental consent before collecting personal information from children under 13.
Question 3: A healthcare organization shares patient data with a billing company that processes claims on its behalf. Under HIPAA, the billing company is classified as a:
- Covered entity
- Business associate (Correct answer)
- Hybrid entity
- Data processor
Correct answer: Business associate
Under HIPAA, a business associate is a person or entity that performs functions involving the use or disclosure of PHI on behalf of a covered entity.
Question 4: Which regulation requires publicly traded companies to maintain internal controls and procedures for financial reporting and have executives certify their accuracy?
- GLBA
- SOX (Correct answer)
- Dodd-Frank
- SEC Regulation FD
Correct answer: SOX
The Sarbanes-Oxley Act (SOX) requires executives of publicly traded companies to certify the accuracy of financial reports and maintain adequate internal controls.
Question 5: Under FedRAMP, what is the purpose of the Provisional Authority to Operate (P-ATO)?
- Allows agencies to operate systems without full authorization
- Grants authorization from the Joint Authorization Board for cloud services used by multiple agencies (Correct answer)
- Provides a temporary waiver for non-compliant systems
- Authorizes penetration testing on federal systems
Correct answer: Grants authorization from the Joint Authorization Board for cloud services used by multiple agencies
A FedRAMP P-ATO is granted by the Joint Authorization Board (JAB) and allows cloud service providers to offer services to multiple federal agencies under one authorization.
Question 6: The Dodd-Frank Wall Street Reform and Consumer Protection Act created which new federal agency to protect consumers in the financial sector?
- Financial Industry Regulatory Authority (FINRA)
- Consumer Financial Protection Bureau (CFPB) (Correct answer)
- Office of Financial Research (OFR)
- Financial Stability Oversight Council (FSOC)
Correct answer: Consumer Financial Protection Bureau (CFPB)
Dodd-Frank created the Consumer Financial Protection Bureau (CFPB) to regulate consumer financial products and services and protect consumers from unfair, deceptive, or abusive practices.
Question 7: Under PCI DSS, what must an organization do if it cannot immediately remediate a discovered vulnerability?
- Suspend all cardholder data processing
- Implement compensating controls (Correct answer)
- Notify the card brands immediately
- Submit a formal exception request to the PCI SSC
Correct answer: Implement compensating controls
When a requirement cannot be met due to legitimate technical or business constraints, PCI DSS allows the use of compensating controls that provide equivalent security.
Which GDPR principle requires that personal data be collected for specified, explicit, and legitimate purposes and not further processed in incompatible ways?