CISA Data Management and Privacy Controls 2 — Questions and Answers
Question 1: Which US regulation primarily governs the privacy and security of health information held by covered entities and their business associates?
- SOX (Sarbanes-Oxley Act)
- GLBA (Gramm-Leach-Bliley Act)
- HIPAA (Health Insurance Portability and Accountability Act) (Correct answer)
- FERPA (Family Educational Rights and Privacy Act)
Correct answer: HIPAA (Health Insurance Portability and Accountability Act)
HIPAA's Privacy and Security Rules set standards for protecting individually identifiable health information (PHI) in the US.
Question 2: An IS auditor reviewing data backup controls should PRIMARILY verify that:
- Backups are performed only for financial data
- Backups are tested regularly to confirm successful restoration (Correct answer)
- All backups are stored in the same location as production data
- Backup frequency is determined by available storage space
Correct answer: Backups are tested regularly to confirm successful restoration
An untested backup provides no guarantee of recovery; regular restoration tests confirm data integrity and process reliability.
Question 3: Which of the following is the PRIMARY control to ensure data integrity in a database?
- Encrypting all database connections
- Implementing referential integrity constraints and input validation (Correct answer)
- Performing daily full database backups
- Restricting database access to read-only for all users
Correct answer: Implementing referential integrity constraints and input validation
Referential integrity constraints and input validation prevent invalid data from entering the database and maintain consistency between related tables.
Question 4: A data owner is BEST described as:
- The IT administrator responsible for database maintenance
- The business executive accountable for the data and its appropriate use (Correct answer)
- The CISO who defines information security policies
- The vendor who supplies the data management software
Correct answer: The business executive accountable for the data and its appropriate use
The data owner is a business-side role accountable for defining data classification, access requirements, and appropriate use policies.
Question 5: Which of the following BEST describes the purpose of a data loss prevention (DLP) solution?
- To back up sensitive data to an offsite location automatically
- To detect and prevent unauthorized transmission of sensitive data outside the organization (Correct answer)
- To encrypt data at rest in all storage systems
- To monitor network bandwidth consumed by data transfers
Correct answer: To detect and prevent unauthorized transmission of sensitive data outside the organization
DLP tools inspect content in motion, at rest, and in use to identify and block unauthorized exfiltration of sensitive information.
Question 6: During an audit of cloud data storage, an IS auditor should PRIMARILY confirm that:
- The cloud provider's headquarters is located in the US
- Data encryption, access controls, and contract-defined data handling terms are in place (Correct answer)
- The organization stores all data exclusively in a single cloud region
- Cloud storage costs are less than on-premises alternatives
Correct answer: Data encryption, access controls, and contract-defined data handling terms are in place
Encryption, access controls, and contractual data handling obligations are the core security requirements for cloud-stored data.
Which US regulation primarily governs the privacy and security of health information held by covered entities and their business associates?