CPCA Compliance and Auditing 3 — Questions and Answers
Question 1: A company is subject to HIPAA and stores electronic protected health information (ePHI). Which rule specifically addresses the security of ePHI?
- HIPAA Privacy Rule
- HIPAA Breach Notification Rule
- HIPAA Security Rule (Correct answer)
- HIPAA Enforcement Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule establishes national standards for protecting ePHI through administrative, physical, and technical safeguards.
Question 2: During an audit, a CPCA finds that a critical patch has not been applied to a production server for 90 days. This finding would most likely be classified as:
- An observation
- A minor non-conformity
- A major non-conformity (Correct answer)
- An opportunity for improvement
Correct answer: A major non-conformity
A 90-day unpatched critical vulnerability represents a significant failure of a required control, qualifying as a major non-conformity.
Question 3: What distinguishes a Type 1 SOC 2 report from a Type 2 SOC 2 report?
- Type 1 covers security only; Type 2 covers all five trust criteria
- Type 1 assesses design at a point in time; Type 2 assesses design and operating effectiveness over a period (Correct answer)
- Type 1 is for internal use; Type 2 is for external distribution
- Type 1 requires a third-party auditor; Type 2 can be self-assessed
Correct answer: Type 1 assesses design at a point in time; Type 2 assesses design and operating effectiveness over a period
A SOC 2 Type 1 report evaluates the suitability of control design at a specific point in time, while Type 2 evaluates both design and operating effectiveness over a period (typically 6–12 months).
Question 4: Which framework is most commonly used by US federal agencies to categorize information systems based on the potential impact of a security breach?
- COBIT 2019
- NIST FIPS 199 (Correct answer)
- ISO/IEC 27001
- CIS Controls v8
Correct answer: NIST FIPS 199
NIST FIPS 199 establishes security categorization standards for federal information and information systems using Low, Moderate, and High impact levels.
Question 5: An auditor is testing whether access to a sensitive database requires multi-factor authentication. This is an example of testing which type of control?
- Corrective control
- Detective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Multi-factor authentication is a preventive control because it acts before an event to stop unauthorized access from occurring.
Question 6: Under GDPR, what is the maximum timeframe an organization has to notify the supervisory authority of a personal data breach?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires organizations to notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it.
Question 7: Which of the following best describes the concept of 'scoping' in a compliance audit?
- Determining the budget allocated for audit activities
- Defining the systems, processes, and locations included in the audit (Correct answer)
- Selecting the audit team members and their responsibilities
- Scheduling audit activities across the fiscal year
Correct answer: Defining the systems, processes, and locations included in the audit
Scoping defines the boundaries of the audit by identifying which systems, processes, data types, and organizational units are included in the assessment.
A company is subject to HIPAA and stores electronic protected health information (ePHI).
Which rule specifically addresses the security of ePHI?