Cognizant Safety and Compliance 3 — Questions and Answers
Question 1: Under PCI-DSS compliance requirements, which practice is mandatory when storing cardholder data?
- Store card data in plain text for easy retrieval
- Encrypt stored cardholder data using strong cryptography (Correct answer)
- Limit storage to spreadsheets accessible to the team
- Back up card data to personal cloud storage
Correct answer: Encrypt stored cardholder data using strong cryptography
PCI-DSS Requirement 3 mandates encryption of stored cardholder data to protect it from unauthorized access.
Question 2: What does the principle of 'need to know' mean in the context of Cognizant's information security policy?
- Employees should be informed of all company decisions
- Access to sensitive information is granted only to those who require it for their job function (Correct answer)
- All project team members automatically share equal data access
- Employees must know security policies before onboarding
Correct answer: Access to sensitive information is granted only to those who require it for their job function
The 'need to know' principle ensures that sensitive data is accessible only to individuals whose roles genuinely require it.
Question 3: Cognizant's anti-bribery and corruption policy prohibits associates from offering gifts to government officials. Which of the following scenarios MOST likely violates this policy?
- Sending a branded pen set to a client's procurement manager
- Providing a government auditor with expensive event tickets to influence a contract decision (Correct answer)
- Hosting a client lunch to celebrate a project milestone
- Giving a holiday card to a regulator contact
Correct answer: Providing a government auditor with expensive event tickets to influence a contract decision
Providing expensive tickets intended to influence a government official's decision is a clear violation of anti-bribery laws such as the FCPA and UK Bribery Act.
Question 4: Which framework does Cognizant commonly follow when managing information security controls for its IT service delivery?
- TOGAF
- ISO/IEC 27001 (Correct answer)
- PMBOK
- ITIL v4 only
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is the international standard for information security management systems (ISMS) widely adopted by Cognizant.
Question 5: A Cognizant associate working remotely connects to a public Wi-Fi network to access company systems. The required security measure is:
- Ensure the laptop screen is not visible to others and proceed
- Use an approved VPN before accessing any corporate resources (Correct answer)
- Access only non-sensitive emails to minimize risk
- Notify the manager and then proceed without VPN
Correct answer: Use an approved VPN before accessing any corporate resources
Cognizant policy requires using a company-approved VPN when connecting to public or untrusted networks to encrypt data in transit.
Question 6: An employee accidentally receives a misdirected email containing another company's confidential acquisition strategy. What should they do?
- Read the email to understand it and delete it without telling anyone
- Notify their manager and Cognizant's legal or compliance team, and avoid sharing the information (Correct answer)
- Forward it to a colleague who handles M&A matters
- Save the information in case it is useful for future projects
Correct answer: Notify their manager and Cognizant's legal or compliance team, and avoid sharing the information
Receiving confidential third-party information accidentally must be escalated to legal or compliance to avoid misappropriation of trade secrets.
Question 7: Which of the following best describes 'social engineering' in cybersecurity?
- Using social media platforms to market products
- Manipulating people into divulging confidential information or performing actions that compromise security (Correct answer)
- Building a corporate social network for employees
- Engineering software with social features
Correct answer: Manipulating people into divulging confidential information or performing actions that compromise security
Social engineering exploits human psychology rather than technical vulnerabilities to gain unauthorized access or sensitive information.
Under PCI-DSS compliance requirements, which practice is mandatory when storing cardholder data?