โ† All Cloud Engineer Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. A cloud engineer needs to implement data sovereignty for a government client. What does data sovereignty primarily require?

    Answer: Data must be stored and processed within a specific country's jurisdiction

    Data sovereignty means that data is subject to the laws of the country where it is stored, requiring that it physically reside within a specific jurisdiction.

  2. Which control from the CIS Controls framework specifically addresses the management of cloud-based assets?

    Answer: CIS Control 1: Inventory and Control of Enterprise Assets

    CIS Control 1 focuses on maintaining an accurate inventory of all enterprise assets, including cloud-based resources, as the foundation of security.

  3. Under PCI DSS v4.0, what is the requirement for protecting primary account numbers (PAN) when displayed on screens?

    Answer: PAN must be masked so only the last four digits are visible at most

    PCI DSS requires that PAN be masked when displayed, showing at most the first six and last four digits to minimize exposure of cardholder data.

  4. Which GDPR legal basis allows an organization to process personal data without explicit consent from the individual?

    Answer: Legitimate interests, where the organization's interests outweigh the individual's rights

    GDPR Article 6(1)(f) permits processing based on legitimate interests when those interests are not overridden by the data subject's rights and freedoms.

  5. A healthcare cloud provider is assessed using HITRUST CSF. What is the primary advantage of HITRUST over using individual frameworks separately?

    Answer: It harmonizes multiple frameworks (HIPAA, NIST, ISO) into one unified control set

    HITRUST CSF consolidates requirements from HIPAA, NIST, ISO 27001, PCI DSS, and others into a single, mappable control framework, reducing audit duplication.

  6. Under SOC 2, which Trust Service Criterion addresses system availability and performance?

    Answer: Availability

    The Availability criterion in SOC 2 addresses whether the system is available for operation and use as committed, covering uptime, performance, and disaster recovery.

  7. A cloud engineer is configuring logging for a PCI DSS-compliant environment. What is the minimum log retention period required?

    Answer: 3 months online, 1 year total

    PCI DSS Requirement 10.7 mandates that audit logs be retained for at least one year, with at least three months immediately available for analysis.