Cloud Engineer Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: Which AWS service is specifically designed to help customers demonstrate compliance by providing on-demand access to AWS security and compliance reports?
- AWS Config
- AWS Artifact (Correct answer)
- AWS Security Hub
- AWS Trusted Advisor
Correct answer: AWS Artifact
AWS Artifact provides on-demand access to AWS compliance reports (e.g., SOC, PCI, ISO) and agreements, helping customers meet their own compliance needs.
Question 2: A company must comply with ITAR (International Traffic in Arms Regulations). What does this primarily restrict in cloud environments?
- Use of open-source software in defense applications
- Access to defense-related technical data by foreign nationals or non-US cloud regions (Correct answer)
- Encryption strength of data at rest in government clouds
- Transfer of financial data to countries with trade sanctions
Correct answer: Access to defense-related technical data by foreign nationals or non-US cloud regions
ITAR restricts the export of defense-related technical data, meaning it must only be accessible to US persons and stored in US-controlled cloud environments.
Question 3: Under the EU-US Data Privacy Framework, which principle requires organizations to provide individuals the ability to correct inaccurate personal data?
- Notice
- Data Integrity and Purpose Limitation
- Access (Correct answer)
- Recourse, Enforcement, and Liability
Correct answer: Access
The Access principle requires that individuals be able to access personal data held about them and correct, amend, or delete inaccurate information.
Question 4: A cloud engineer implements network segmentation to isolate cardholder data environments (CDE). Which PCI DSS benefit does this provide?
- Eliminates the need for encryption within the CDE
- Reduces the scope of the PCI DSS assessment (Correct answer)
- Automatically achieves Level 1 PCI compliance
- Removes the requirement for access logging in the CDE
Correct answer: Reduces the scope of the PCI DSS assessment
Network segmentation that isolates the CDE from other networks reduces the number of systems and processes in scope for PCI DSS assessment, simplifying compliance.
Question 5: Which NIST Special Publication provides security controls specifically for protecting Controlled Unclassified Information (CUI) in non-federal systems?
- NIST SP 800-53
- NIST SP 800-171 (Correct answer)
- NIST SP 800-37
- NIST SP 800-61
Correct answer: NIST SP 800-171
NIST SP 800-171 defines security requirements for protecting CUI in non-federal information systems, and compliance is required for DoD contractors.
Question 6: In a multi-tenant cloud environment, what compliance challenge does 'noisy neighbor' resource contention primarily create?
- Data residency violations
- Availability and processing integrity issues affecting SLA compliance (Correct answer)
- GDPR consent management failures
- PCI DSS cardholder data exposure
Correct answer: Availability and processing integrity issues affecting SLA compliance
Noisy neighbor effects, where one tenant's workload impacts another's performance, can violate availability SLAs and undermine SOC 2 Availability and Processing Integrity criteria.
Question 7: A GDPR Data Protection Impact Assessment (DPIA) is mandatory when processing activities are likely to result in which outcome?
- Processing data of more than 1,000 individuals
- High risk to the rights and freedoms of natural persons (Correct answer)
- Cross-border data transfers to any non-EU country
- Storage of data beyond 90 days
Correct answer: High risk to the rights and freedoms of natural persons
Under GDPR Article 35, a DPIA is required prior to processing that is likely to result in a high risk to individuals' rights and freedoms, such as large-scale profiling or systematic monitoring.
Which AWS service is specifically designed to help customers demonstrate compliance by providing on-demand access to AWS security and compliance reports?