← All Cloud Engineer Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. Under HIPAA, which cloud storage configuration violates the minimum necessary standard?

    Answer: Allowing all employees to access the full patient database for any reason

    HIPAA's minimum necessary standard requires that access to PHI be limited to only what is needed for a specific job function.

  2. A cloud engineer must ensure EU citizen data processed in the US complies with GDPR. Which mechanism is most commonly used for this cross-border transfer?

    Answer: Standard Contractual Clauses (SCCs)

    Standard Contractual Clauses (SCCs) are the primary legal mechanism approved by the EU for transferring personal data to third countries.

  3. Which PCI DSS requirement specifically addresses the protection of stored cardholder data?

    Answer: Requirement 3

    PCI DSS Requirement 3 covers protection of stored cardholder data, including encryption and data retention policies.

  4. SOC 2 Type II differs from SOC 2 Type I primarily because it:

    Answer: Tests controls over a period of time rather than a single point

    SOC 2 Type II evaluates the operational effectiveness of controls over a review period (typically 6–12 months), while Type I is a point-in-time assessment.

  5. An organization subject to FedRAMP must use a cloud service that has achieved which authorization before storing federal data?

    Answer: FedRAMP Authorization to Operate (ATO)

    FedRAMP requires cloud services to obtain an Authorization to Operate (ATO) before federal agencies can use them to process, store, or transmit federal information.

  6. Which GDPR principle requires that personal data not be kept longer than necessary for its original purpose?

    Answer: Storage limitation

    The storage limitation principle under GDPR mandates that personal data be retained only as long as necessary for the specified purpose.

  7. Under the California Consumer Privacy Act (CCPA), what right allows consumers to request deletion of their personal information?

    Answer: Right to erasure

    CCPA grants consumers the right to request that a business delete personal information it has collected about them, subject to certain exceptions.