Cognizant Industry Regulations 3 — Questions and Answers
Question 1: Which framework provides a set of best practices specifically for IT service management (ITSM)?
- COBIT
- ITIL (Correct answer)
- ISO 27001
- NIST CSF
Correct answer: ITIL
ITIL (Information Technology Infrastructure Library) provides best-practice guidance for IT service management across the service lifecycle.
Question 2: A company processing health information for a HIPAA-covered entity must sign which type of agreement?
- Non-Disclosure Agreement
- Business Associate Agreement (Correct answer)
- Data Processing Agreement
- Service Level Agreement
Correct answer: Business Associate Agreement
A Business Associate Agreement (BAA) is required when a vendor handles protected health information (PHI) on behalf of a covered entity under HIPAA.
Question 3: Under CCPA, which right allows California consumers to request deletion of their personal information?
- Right to Know
- Right to Opt-Out
- Right to Delete (Correct answer)
- Right to Non-Discrimination
Correct answer: Right to Delete
The Right to Delete under CCPA allows consumers to request that businesses delete personal information collected about them, subject to certain exceptions.
Question 4: ISO/IEC 27001 is an international standard for which domain?
- Quality management systems
- Information security management systems (Correct answer)
- IT service management
- Business continuity management
Correct answer: Information security management systems
ISO/IEC 27001 specifies requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
Question 5: Which U.S. regulation requires financial institutions to implement a customer identification program (CIP) to prevent money laundering?
- Gramm-Leach-Bliley Act
- Bank Secrecy Act (Correct answer)
- Dodd-Frank Act
- Community Reinvestment Act
Correct answer: Bank Secrecy Act
The Bank Secrecy Act (BSA) and its implementing regulations require financial institutions to establish CIPs and file Suspicious Activity Reports to combat money laundering.
Question 6: In the context of data residency regulations, what does 'data localization' require?
- Encrypting data at rest within a country
- Storing and processing data within the borders of a specific country (Correct answer)
- Translating data into local languages
- Backing up data on local servers only
Correct answer: Storing and processing data within the borders of a specific country
Data localization laws require that data about a country's citizens or residents be collected, processed, or stored within that country's borders.
Question 7: Which regulation governs the handling of nonpublic personal financial information by financial institutions in the United States?
- SOX
- FCPA
- GLBA (Correct answer)
- FISMA
Correct answer: GLBA
The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to explain their information-sharing practices and safeguard sensitive customer data.
Which framework provides a set of best practices specifically for IT service management (ITSM)?