CIAM Governance and Compliance 2 — Questions and Answers
Question 1: Under GDPR, what is the maximum fine for a Tier 2 violation as a percentage of global annual turnover?
- 2%
- 4% (Correct answer)
- 6%
- 10%
Correct answer: 4%
GDPR Tier 2 violations (the most serious) carry fines up to 4% of global annual turnover or €20 million, whichever is higher.
Question 2: Which IAM governance framework artifact maps business roles to IT entitlements?
- Risk register
- Role catalog (Correct answer)
- Access certification report
- Policy exception log
Correct answer: Role catalog
A role catalog defines and maps business roles to their associated IT entitlements, forming the foundation of role-based access control governance.
Question 3: A SOC 2 Type II report differs from SOC 2 Type I primarily in that it:
- Covers additional trust service criteria
- Evaluates controls over a period of time rather than a point in time (Correct answer)
- Is intended for regulatory bodies rather than customers
- Requires third-party penetration testing
Correct answer: Evaluates controls over a period of time rather than a point in time
SOC 2 Type II evaluates the operational effectiveness of controls over a defined period (typically 6–12 months), while Type I assesses design at a single point in time.
Question 4: Which principle requires that access rights be reviewed and removed when no longer needed for a job function?
- Segregation of duties
- Need-to-know principle
- Least privilege (Correct answer)
- Discretionary access control
Correct answer: Least privilege
Least privilege mandates that users retain only the minimum access necessary for their current role, requiring revocation when access is no longer justified.
Question 5: Under HIPAA, which entity must sign a Business Associate Agreement (BAA) with a covered entity?
- Any vendor the covered entity pays
- Vendors who handle protected health information on behalf of the covered entity (Correct answer)
- Vendors located outside the United States
- Vendors providing cloud infrastructure only
Correct answer: Vendors who handle protected health information on behalf of the covered entity
A BAA is required for any business associate that creates, receives, maintains, or transmits PHI on behalf of a HIPAA covered entity.
Question 6: An organization discovers that a former employee's SSO account was not deprovisioned for 45 days after termination. Which governance control failure does this best represent?
- Inadequate access certification
- Missing joiner workflow
- Failed leaver workflow (Correct answer)
- Insufficient role mining
Correct answer: Failed leaver workflow
A leaver workflow governs the timely revocation of access upon employment termination; failure to execute it left the account active.
Question 7: Which PCI DSS requirement specifically mandates restricting access to system components and cardholder data to only those individuals whose job requires such access?
- Requirement 3
- Requirement 7 (Correct answer)
- Requirement 10
- Requirement 12
Correct answer: Requirement 7
PCI DSS Requirement 7 requires limiting access to system components and cardholder data to those with a legitimate business need.
Under GDPR, what is the maximum fine for a Tier 2 violation as a percentage of global annual turnover?