Cloud Engineer Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under HIPAA, which cloud storage configuration violates the minimum necessary standard?
- Granting read-only access to audit logs for the security team
- Allowing all employees to access the full patient database for any reason (Correct answer)
- Encrypting PHI at rest using AES-256
- Logging all access attempts to PHI containers
Correct answer: Allowing all employees to access the full patient database for any reason
HIPAA's minimum necessary standard requires that access to PHI be limited to only what is needed for a specific job function.
Question 2: A cloud engineer must ensure EU citizen data processed in the US complies with GDPR. Which mechanism is most commonly used for this cross-border transfer?
- Data residency agreements
- Standard Contractual Clauses (SCCs) (Correct answer)
- ISO 27001 certification
- NIST 800-53 controls
Correct answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are the primary legal mechanism approved by the EU for transferring personal data to third countries.
Question 3: Which PCI DSS requirement specifically addresses the protection of stored cardholder data?
- Requirement 1
- Requirement 3 (Correct answer)
- Requirement 6
- Requirement 10
Correct answer: Requirement 3
PCI DSS Requirement 3 covers protection of stored cardholder data, including encryption and data retention policies.
Question 4: SOC 2 Type II differs from SOC 2 Type I primarily because it:
- Covers more Trust Service Criteria
- Tests controls over a period of time rather than a single point (Correct answer)
- Is required by law for cloud providers
- Applies only to financial data
Correct answer: Tests controls over a period of time rather than a single point
SOC 2 Type II evaluates the operational effectiveness of controls over a review period (typically 6–12 months), while Type I is a point-in-time assessment.
Question 5: An organization subject to FedRAMP must use a cloud service that has achieved which authorization before storing federal data?
- ISO 27001 certification
- FedRAMP Authorization to Operate (ATO) (Correct answer)
- PCI DSS Level 1 compliance
- FIPS 140-2 validation only
Correct answer: FedRAMP Authorization to Operate (ATO)
FedRAMP requires cloud services to obtain an Authorization to Operate (ATO) before federal agencies can use them to process, store, or transmit federal information.
Question 6: Which GDPR principle requires that personal data not be kept longer than necessary for its original purpose?
- Data minimization
- Storage limitation (Correct answer)
- Purpose limitation
- Integrity and confidentiality
Correct answer: Storage limitation
The storage limitation principle under GDPR mandates that personal data be retained only as long as necessary for the specified purpose.
Question 7: Under the California Consumer Privacy Act (CCPA), what right allows consumers to request deletion of their personal information?
- Right to access
- Right to erasure (Correct answer)
- Right to opt-out
- Right to non-discrimination
Correct answer: Right to erasure
CCPA grants consumers the right to request that a business delete personal information it has collected about them, subject to certain exceptions.
Under HIPAA, which cloud storage configuration violates the minimum necessary standard?