Regulatory Compliance & Licensing Flashcards
7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Licensing flashcards as text
Under HIPAA, what is the maximum civil monetary penalty per violation category when willful neglect is corrected within the required timeframe?
Answer: $50,000
HIPAA sets a maximum civil penalty of $50,000 per violation for willful neglect that is corrected within the required period.
A company deploys software on 200 servers using a per-core license that allows 16 cores per license. How many licenses are required if each server has 24 physical cores?
Answer: 300
Each 24-core server needs 24/16 = 1.5 licenses, rounded up to 2, but per-core models typically count actual cores: 200 servers × 24 cores ÷ 16 cores/license = 300 licenses.
Which U.S. federal regulation specifically governs the export of encryption software and requires an Export Control Classification Number (ECCN)?
Answer: EAR
The Export Administration Regulations (EAR) govern dual-use items including encryption software and assign ECCNs to classify controlled items.
An administrator discovers that a vendor's software EULA prohibits reverse engineering. Under which U.S. law does a narrow 'interoperability' exception allow limited reverse engineering despite such contractual prohibitions?
Answer: Digital Millennium Copyright Act
The DMCA Section 1201(f) provides an interoperability exception permitting reverse engineering of software solely to achieve compatibility.
SOC 2 Type II reports differ from SOC 2 Type I reports primarily because Type II reports:
Answer: Evaluate design and operating effectiveness over a period of time
SOC 2 Type II evaluates both the design and operating effectiveness of controls over a defined review period, typically 6–12 months.
Under GDPR, which legal basis allows an organization to process personal data without explicit user consent when it is necessary to fulfill a contract with that individual?
Answer: Contractual necessity
Article 6(1)(b) of GDPR permits processing when it is necessary for the performance of a contract to which the data subject is party.
A system administrator at a federally funded university must ensure research systems comply with NIST SP 800-171. Which type of data does this standard specifically protect?
Answer: Controlled Unclassified Information (CUI)
NIST SP 800-171 establishes requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.