← All CPCA Flashcard Decks

Compliance and Auditing Flashcards

7 cards from real CPCA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance and Auditing flashcards as text
  1. A company is subject to HIPAA and stores electronic protected health information (ePHI). Which rule specifically addresses the security of ePHI?

    Answer: HIPAA Security Rule

    The HIPAA Security Rule establishes national standards for protecting ePHI through administrative, physical, and technical safeguards.

  2. During an audit, a CPCA finds that a critical patch has not been applied to a production server for 90 days. This finding would most likely be classified as:

    Answer: A major non-conformity

    A 90-day unpatched critical vulnerability represents a significant failure of a required control, qualifying as a major non-conformity.

  3. What distinguishes a Type 1 SOC 2 report from a Type 2 SOC 2 report?

    Answer: Type 1 assesses design at a point in time; Type 2 assesses design and operating effectiveness over a period

    A SOC 2 Type 1 report evaluates the suitability of control design at a specific point in time, while Type 2 evaluates both design and operating effectiveness over a period (typically 6–12 months).

  4. Which framework is most commonly used by US federal agencies to categorize information systems based on the potential impact of a security breach?

    Answer: NIST FIPS 199

    NIST FIPS 199 establishes security categorization standards for federal information and information systems using Low, Moderate, and High impact levels.

  5. An auditor is testing whether access to a sensitive database requires multi-factor authentication. This is an example of testing which type of control?

    Answer: Preventive control

    Multi-factor authentication is a preventive control because it acts before an event to stop unauthorized access from occurring.

  6. Under GDPR, what is the maximum timeframe an organization has to notify the supervisory authority of a personal data breach?

    Answer: 72 hours

    GDPR Article 33 requires organizations to notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it.

  7. Which of the following best describes the concept of 'scoping' in a compliance audit?

    Answer: Defining the systems, processes, and locations included in the audit

    Scoping defines the boundaries of the audit by identifying which systems, processes, data types, and organizational units are included in the assessment.