Regulatory Frameworks & Compliance Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Frameworks & Compliance flashcards as text
Which AWS service is specifically designed to help customers demonstrate compliance by providing on-demand access to AWS security and compliance reports?
Answer: AWS Artifact
AWS Artifact provides on-demand access to AWS compliance reports (e.g., SOC, PCI, ISO) and agreements, helping customers meet their own compliance needs.
A company must comply with ITAR (International Traffic in Arms Regulations). What does this primarily restrict in cloud environments?
Answer: Access to defense-related technical data by foreign nationals or non-US cloud regions
ITAR restricts the export of defense-related technical data, meaning it must only be accessible to US persons and stored in US-controlled cloud environments.
Under the EU-US Data Privacy Framework, which principle requires organizations to provide individuals the ability to correct inaccurate personal data?
Answer: Access
The Access principle requires that individuals be able to access personal data held about them and correct, amend, or delete inaccurate information.
A cloud engineer implements network segmentation to isolate cardholder data environments (CDE). Which PCI DSS benefit does this provide?
Answer: Reduces the scope of the PCI DSS assessment
Network segmentation that isolates the CDE from other networks reduces the number of systems and processes in scope for PCI DSS assessment, simplifying compliance.
Which NIST Special Publication provides security controls specifically for protecting Controlled Unclassified Information (CUI) in non-federal systems?
Answer: NIST SP 800-171
NIST SP 800-171 defines security requirements for protecting CUI in non-federal information systems, and compliance is required for DoD contractors.
In a multi-tenant cloud environment, what compliance challenge does 'noisy neighbor' resource contention primarily create?
Answer: Availability and processing integrity issues affecting SLA compliance
Noisy neighbor effects, where one tenant's workload impacts another's performance, can violate availability SLAs and undermine SOC 2 Availability and Processing Integrity criteria.
A GDPR Data Protection Impact Assessment (DPIA) is mandatory when processing activities are likely to result in which outcome?
Answer: High risk to the rights and freedoms of natural persons
Under GDPR Article 35, a DPIA is required prior to processing that is likely to result in a high risk to individuals' rights and freedoms, such as large-scale profiling or systematic monitoring.