Cognizant Industry Regulations 2 — Questions and Answers
Question 1: Under HIPAA, what is the maximum civil penalty per violation category per calendar year?
- $25,000
- $1,000,000
- $1,900,000 (Correct answer)
- $10,000,000
Correct answer: $1,900,000
HIPAA civil penalties are capped at $1,919,173 per violation category per calendar year (adjusted for inflation).
Question 2: Which regulation specifically governs the export of U.S. dual-use technology and software that IT companies like Cognizant must comply with?
- ITAR
- EAR (Correct answer)
- FCPA
- SOX
Correct answer: EAR
The Export Administration Regulations (EAR) govern dual-use items — commercial goods with potential military applications — that IT services firms must comply with.
Question 3: Which PCI DSS requirement mandates that organizations maintain a vulnerability management program?
- Requirement 3
- Requirement 6 (Correct answer)
- Requirement 8
- Requirement 11
Correct answer: Requirement 6
PCI DSS Requirement 6 requires organizations to develop and maintain secure systems and software as part of vulnerability management.
Question 4: The EU-U.S. Data Privacy Framework replaced which prior agreement invalidated by the Court of Justice of the EU?
- Safe Harbor
- Privacy Shield (Correct answer)
- Schrems I
- CLOUD Act
Correct answer: Privacy Shield
The EU-U.S. Data Privacy Framework replaced Privacy Shield, which was invalidated by the Schrems II ruling in 2020.
Question 5: Under the Sarbanes-Oxley Act, Section 404 requires management to assess the effectiveness of which type of controls?
- Physical access controls
- Internal controls over financial reporting (Correct answer)
- Network security controls
- Data retention controls
Correct answer: Internal controls over financial reporting
SOX Section 404 requires management and external auditors to report on the adequacy of internal controls over financial reporting (ICFR).
Question 6: Which law requires U.S. companies operating abroad to prohibit bribery of foreign government officials?
- Sherman Antitrust Act
- Foreign Corrupt Practices Act (Correct answer)
- Dodd-Frank Act
- Robinson-Patman Act
Correct answer: Foreign Corrupt Practices Act
The Foreign Corrupt Practices Act (FCPA) prohibits U.S. companies and individuals from bribing foreign government officials to obtain or retain business.
Question 7: Under GDPR, what is the maximum fine for the most serious violations?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 5% of global annual turnover
- €5 million or 1% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR's highest tier fines reach €20 million or 4% of the company's total global annual turnover, whichever is higher.
Under HIPAA, what is the maximum civil penalty per violation category per calendar year?