Cloud Engineer Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: A cloud engineer needs to implement data sovereignty for a government client. What does data sovereignty primarily require?
- Data must be encrypted using government-approved algorithms only
- Data must be stored and processed within a specific country's jurisdiction (Correct answer)
- Data must be backed up to at least three geographic regions
- Data must be accessible only by government employees
Correct answer: Data must be stored and processed within a specific country's jurisdiction
Data sovereignty means that data is subject to the laws of the country where it is stored, requiring that it physically reside within a specific jurisdiction.
Question 2: Which control from the CIS Controls framework specifically addresses the management of cloud-based assets?
- CIS Control 1: Inventory and Control of Enterprise Assets (Correct answer)
- CIS Control 4: Secure Configuration of Enterprise Assets
- CIS Control 16: Application Software Security
- CIS Control 17: Incident Response Management
Correct answer: CIS Control 1: Inventory and Control of Enterprise Assets
CIS Control 1 focuses on maintaining an accurate inventory of all enterprise assets, including cloud-based resources, as the foundation of security.
Question 3: Under PCI DSS v4.0, what is the requirement for protecting primary account numbers (PAN) when displayed on screens?
- PAN must never be displayed under any circumstances
- PAN must be masked so only the last four digits are visible at most (Correct answer)
- PAN must be encrypted before display
- PAN display requires two-factor authentication each time
Correct answer: PAN must be masked so only the last four digits are visible at most
PCI DSS requires that PAN be masked when displayed, showing at most the first six and last four digits to minimize exposure of cardholder data.
Question 4: Which GDPR legal basis allows an organization to process personal data without explicit consent from the individual?
- Legitimate interests, where the organization's interests outweigh the individual's rights (Correct answer)
- Anonymous data processing by certified third parties
- Pseudonymization of all data before processing
- Encryption of personal data before any processing occurs
Correct answer: Legitimate interests, where the organization's interests outweigh the individual's rights
GDPR Article 6(1)(f) permits processing based on legitimate interests when those interests are not overridden by the data subject's rights and freedoms.
Question 5: A healthcare cloud provider is assessed using HITRUST CSF. What is the primary advantage of HITRUST over using individual frameworks separately?
- It replaces all other compliance requirements with a single audit
- It harmonizes multiple frameworks (HIPAA, NIST, ISO) into one unified control set (Correct answer)
- It provides free annual audits for qualifying organizations
- It is mandated by the US federal government for all health IT
Correct answer: It harmonizes multiple frameworks (HIPAA, NIST, ISO) into one unified control set
HITRUST CSF consolidates requirements from HIPAA, NIST, ISO 27001, PCI DSS, and others into a single, mappable control framework, reducing audit duplication.
Question 6: Under SOC 2, which Trust Service Criterion addresses system availability and performance?
- Security
- Availability (Correct answer)
- Confidentiality
- Processing Integrity
Correct answer: Availability
The Availability criterion in SOC 2 addresses whether the system is available for operation and use as committed, covering uptime, performance, and disaster recovery.
Question 7: A cloud engineer is configuring logging for a PCI DSS-compliant environment. What is the minimum log retention period required?
- 30 days online, 6 months total
- 3 months online, 1 year total (Correct answer)
- 6 months online, 1 year total
- 1 year online, 3 years total
Correct answer: 3 months online, 1 year total
PCI DSS Requirement 10.7 mandates that audit logs be retained for at least one year, with at least three months immediately available for analysis.
A cloud engineer needs to implement data sovereignty for a government client.
What does data sovereignty primarily require?