CIAM Compliance Standards 3 — Questions and Answers
Question 1: Which NIST SP 800-53 control family directly governs identification and authentication requirements?
- AC – Access Control
- IA – Identification and Authentication (Correct answer)
- AU – Audit and Accountability
- CM – Configuration Management
Correct answer: IA – Identification and Authentication
The IA control family in NIST SP 800-53 covers organizational identification and authentication policies, including multi-factor authentication.
Question 2: Under CCPA, which right allows California consumers to request that a business delete their personal information?
- Right to Know
- Right to Opt-Out
- Right to Delete (Correct answer)
- Right to Non-Discrimination
Correct answer: Right to Delete
CCPA's Right to Delete allows consumers to request deletion of their personal information collected by a business, subject to certain exceptions.
Question 3: ISO 27001 Annex A control A.9.2 specifically addresses which IAM process?
- Network access control
- User access management (provisioning and deprovisioning) (Correct answer)
- Cryptographic key management
- Physical access to server rooms
Correct answer: User access management (provisioning and deprovisioning)
ISO 27001 Annex A.9.2 covers user access management, including registration, deregistration, and review of access rights.
Question 4: A quarterly access review where managers certify their team's entitlements is best described as which compliance control?
- Privileged access management audit
- User access recertification (UAR) (Correct answer)
- Role-based access control implementation
- Separation of duties enforcement
Correct answer: User access recertification (UAR)
User Access Recertification (UAR) is a periodic review process where data owners or managers certify that access rights remain appropriate.
Question 5: Which regulation requires financial institutions to implement a comprehensive information security program and is enforced by the FTC?
- SOX
- GLBA Safeguards Rule (Correct answer)
- PCI DSS
- FERPA
Correct answer: GLBA Safeguards Rule
The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to protect customer financial information through a written security program.
Question 6: In a GDPR context, what is the maximum timeframe for notifying supervisory authorities after discovering a personal data breach?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 7: Which CIS Control directly maps to managing access based on the principle of least privilege?
- CIS Control 1 – Inventory of Enterprise Assets
- CIS Control 5 – Account Management
- CIS Control 6 – Access Control Management (Correct answer)
- CIS Control 12 – Network Infrastructure Management
Correct answer: CIS Control 6 – Access Control Management
CIS Control 6 focuses on Access Control Management, including least privilege, limiting administrative rights, and centralizing access management.
Which NIST SP 800-53 control family directly governs identification and authentication requirements?