CNDA Risk Management and Compliance 2 — Questions and Answers
Question 1: What is the primary difference between a vulnerability assessment and a penetration test?
- Vulnerability assessments are only run on web apps; pen tests cover networks
- A vulnerability assessment identifies weaknesses; a pen test actively exploits them to determine real-world impact (Correct answer)
- Pen tests are automated; vulnerability assessments are manual
- They are identical in scope and methodology
Correct answer: A vulnerability assessment identifies weaknesses; a pen test actively exploits them to determine real-world impact
A vulnerability assessment discovers and reports weaknesses, while a penetration test attempts to exploit them to validate actual risk and business impact.
Question 2: Under HIPAA, what category of information must healthcare organizations protect?
- All employee email
- Protected Health Information (PHI) that identifies individuals (Correct answer)
- Financial transaction records
- Marketing contact lists
Correct answer: Protected Health Information (PHI) that identifies individuals
HIPAA protects PHI — any individually identifiable health information held or transmitted by a covered entity or its business associates.
Question 3: Which security framework uses the Cybersecurity Framework Core with five functions: Identify, Protect, Detect, Respond, and Recover?
- NIST SP 800-53
- NIST Cybersecurity Framework (CSF) (Correct answer)
- ISO 27001
- CIS Controls
Correct answer: NIST Cybersecurity Framework (CSF)
The NIST CSF organizes security activities into five core functions that map to the full lifecycle of managing cybersecurity risk.
Question 4: What is a 'security control baseline' as used in NIST SP 800-53?
- The minimum acceptable patch level for servers
- A predefined set of security controls tailored to a system's impact level (Low, Moderate, High) (Correct answer)
- A list of denied network addresses
- The default firewall rule set
Correct answer: A predefined set of security controls tailored to a system's impact level (Low, Moderate, High)
NIST SP 800-53 baselines group controls by system impact level, providing a starting point that organizations tailor to their specific environment.
Question 5: What does 'due diligence' mean in the context of cybersecurity governance?
- Running daily vulnerability scans
- Researching and understanding risks before implementing security controls and business decisions (Correct answer)
- Requiring all staff to take phishing training
- Documenting all software licenses
Correct answer: Researching and understanding risks before implementing security controls and business decisions
Due diligence requires organizations to actively investigate and understand security risks, not merely assume that existing controls are sufficient.
Question 6: Which regulation requires US public companies to maintain adequate internal controls over financial reporting and cybersecurity disclosures?
- GLBA
- SOX (Sarbanes-Oxley Act) (Correct answer)
- CCPA
- FERPA
Correct answer: SOX (Sarbanes-Oxley Act)
SOX Section 404 requires management and auditors to assess internal controls, and the SEC now requires timely cybersecurity incident disclosure.
What is the primary difference between a vulnerability assessment and a penetration test?