Cognizant Safety and Compliance 2 — Questions and Answers
Question 1: An employee receives an email from an unknown sender claiming to be Cognizant IT asking for their login credentials to resolve an urgent account issue. What is the correct action?
- Reply with credentials immediately to resolve the issue
- Delete the email and report it to the IT security team (Correct answer)
- Forward it to a colleague to verify
- Call the sender using the number provided in the email
Correct answer: Delete the email and report it to the IT security team
Legitimate IT teams never request credentials via email; this is a phishing attempt and must be reported to IT security.
Question 2: Under Cognizant's Code of Business Ethics, an employee who suspects a colleague is engaged in fraudulent billing should first:
- Confront the colleague directly to resolve it internally
- Report the concern through Cognizant's Ethics Helpline or other designated reporting channels (Correct answer)
- Ignore it unless they have documented proof
- Discuss it with clients to verify
Correct answer: Report the concern through Cognizant's Ethics Helpline or other designated reporting channels
Cognizant's ethics policy requires associates to report suspected fraud through official channels such as the Ethics Helpline without needing definitive proof first.
Question 3: Which regulation primarily governs the protection of personal health information (PHI) in the United States, directly impacting Cognizant's healthcare clients?
- SOX
- PCI-DSS
- HIPAA (Correct answer)
- GDPR
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) regulates PHI and applies to Cognizant when handling healthcare client data.
Question 4: A Cognizant associate finishes working on a client project and still has access to that client's systems. According to least-privilege principles, what should happen?
- Access should remain in case the client needs support later
- Access should be revoked promptly once the project ends (Correct answer)
- The associate's manager should retain access instead
- Access should be transferred to a junior team member
Correct answer: Access should be revoked promptly once the project ends
Least-privilege principles require revoking access as soon as it is no longer needed to minimize security risk.
Question 5: During a business continuity drill, the drill coordinator asks employees to simulate evacuating the building within a set time. An employee in the middle of a critical client call should:
- Complete the client call before participating in the drill
- Inform the client briefly, then follow evacuation procedures (Correct answer)
- Skip the drill since client service takes priority
- Contact the drill coordinator to request an exemption
Correct answer: Inform the client briefly, then follow evacuation procedures
Safety drills require participation; associates should briefly notify the client and then follow emergency evacuation procedures.
Question 6: What is the purpose of a Data Processing Agreement (DPA) between Cognizant and a client operating under GDPR?
- To define service-level uptime guarantees
- To establish legal obligations for processing personal data on behalf of the controller (Correct answer)
- To set payment terms for data services
- To outline software licensing conditions
Correct answer: To establish legal obligations for processing personal data on behalf of the controller
A DPA defines the roles, responsibilities, and legal obligations of both parties when Cognizant processes personal data as a data processor under GDPR.
Question 7: An associate notices that a fire exit door in their office is blocked by stored equipment. The most appropriate immediate action is:
- Work around it and report it in the next monthly safety meeting
- Remove or report the obstruction to facilities management immediately (Correct answer)
- Place a caution sign near the blockage
- Only act if a manager approves the removal
Correct answer: Remove or report the obstruction to facilities management immediately
Blocked fire exits are an immediate safety hazard and must be reported or cleared right away, not deferred.
An employee receives an email from an unknown sender claiming to be Cognizant IT asking for their login credentials to resolve an urgent account issue.
What is the correct action?