โ† All Cloud Engineer Flashcard Decks

Regulatory Frameworks & Compliance Flashcards

7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Frameworks & Compliance flashcards as text
  1. Which AWS service is specifically designed to help customers demonstrate compliance by providing on-demand access to AWS security and compliance reports?

    Answer: AWS Artifact

    AWS Artifact provides on-demand access to AWS compliance reports (e.g., SOC, PCI, ISO) and agreements, helping customers meet their own compliance needs.

  2. A company must comply with ITAR (International Traffic in Arms Regulations). What does this primarily restrict in cloud environments?

    Answer: Access to defense-related technical data by foreign nationals or non-US cloud regions

    ITAR restricts the export of defense-related technical data, meaning it must only be accessible to US persons and stored in US-controlled cloud environments.

  3. Under the EU-US Data Privacy Framework, which principle requires organizations to provide individuals the ability to correct inaccurate personal data?

    Answer: Access

    The Access principle requires that individuals be able to access personal data held about them and correct, amend, or delete inaccurate information.

  4. A cloud engineer implements network segmentation to isolate cardholder data environments (CDE). Which PCI DSS benefit does this provide?

    Answer: Reduces the scope of the PCI DSS assessment

    Network segmentation that isolates the CDE from other networks reduces the number of systems and processes in scope for PCI DSS assessment, simplifying compliance.

  5. Which NIST Special Publication provides security controls specifically for protecting Controlled Unclassified Information (CUI) in non-federal systems?

    Answer: NIST SP 800-171

    NIST SP 800-171 defines security requirements for protecting CUI in non-federal information systems, and compliance is required for DoD contractors.

  6. In a multi-tenant cloud environment, what compliance challenge does 'noisy neighbor' resource contention primarily create?

    Answer: Availability and processing integrity issues affecting SLA compliance

    Noisy neighbor effects, where one tenant's workload impacts another's performance, can violate availability SLAs and undermine SOC 2 Availability and Processing Integrity criteria.

  7. A GDPR Data Protection Impact Assessment (DPIA) is mandatory when processing activities are likely to result in which outcome?

    Answer: High risk to the rights and freedoms of natural persons

    Under GDPR Article 35, a DPIA is required prior to processing that is likely to result in a high risk to individuals' rights and freedoms, such as large-scale profiling or systematic monitoring.