Cloud Engineer Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: A cloud engineer is designing a system for a bank. Which compliance framework specifically addresses IT controls for financial institutions in the US?
- HIPAA
- SOX (Sarbanes-Oxley Act) (Correct answer)
- FERPA
- COPPA
Correct answer: SOX (Sarbanes-Oxley Act)
SOX requires publicly traded companies, including banks, to implement strong IT controls around financial reporting and data integrity.
Question 2: Which NIST framework provides a risk-based approach to managing cybersecurity risk across an organization?
- NIST SP 800-53
- NIST Cybersecurity Framework (CSF) (Correct answer)
- NIST SP 800-171
- NIST SP 800-37
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST Cybersecurity Framework (CSF) provides five core functions—Identify, Protect, Detect, Respond, Recover—as a flexible, risk-based approach to cybersecurity.
Question 3: In cloud compliance, what is the primary purpose of a Business Associate Agreement (BAA)?
- To establish SLA terms for cloud uptime
- To define HIPAA responsibilities between a covered entity and cloud provider (Correct answer)
- To authorize cross-border data transfers under GDPR
- To certify PCI DSS compliance of a vendor
Correct answer: To define HIPAA responsibilities between a covered entity and cloud provider
A BAA is a HIPAA-required contract between a covered entity and a business associate that outlines each party's responsibilities for protecting PHI.
Question 4: Under GDPR, what is the maximum time frame for notifying supervisory authorities of a personal data breach?
- 24 hours
- 72 hours (Correct answer)
- 7 days
- 30 days
Correct answer: 72 hours
GDPR Article 33 requires that data controllers notify the relevant supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Question 5: Which cloud compliance concept refers to the division of compliance responsibilities between a cloud provider and its customer?
- Shared Fate Model
- Shared Responsibility Model (Correct answer)
- Dual Control Principle
- Segregation of Duties
Correct answer: Shared Responsibility Model
The Shared Responsibility Model defines which security and compliance obligations belong to the cloud provider versus the customer, varying by service type (IaaS, PaaS, SaaS).
Question 6: An organization processes data from children under 13 in the US. Which regulation governs their online data collection practices?
- FERPA
- CCPA
- COPPA (Correct answer)
- HIPAA
Correct answer: COPPA
COPPA (Children's Online Privacy Protection Act) requires parental consent before collecting personal information from children under 13 in the US.
Question 7: Which ISO standard is specifically focused on information security management systems (ISMS)?
- ISO 9001
- ISO 27001 (Correct answer)
- ISO 31000
- ISO 22301
Correct answer: ISO 27001
ISO 27001 is the internationally recognized standard for establishing, implementing, maintaining, and continually improving an ISMS.
A cloud engineer is designing a system for a bank.
Which compliance framework specifically addresses IT controls for financial institutions in the US?