← All CSA Flashcard Decks

Regulatory Compliance & Licensing Flashcards

7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Licensing flashcards as text
  1. Under HIPAA, what is the maximum civil monetary penalty per violation category when willful neglect is corrected within the required timeframe?

    Answer: $50,000

    HIPAA sets a maximum civil penalty of $50,000 per violation for willful neglect that is corrected within the required period.

  2. A company deploys software on 200 servers using a per-core license that allows 16 cores per license. How many licenses are required if each server has 24 physical cores?

    Answer: 300

    Each 24-core server needs 24/16 = 1.5 licenses, rounded up to 2, but per-core models typically count actual cores: 200 servers × 24 cores ÷ 16 cores/license = 300 licenses.

  3. Which U.S. federal regulation specifically governs the export of encryption software and requires an Export Control Classification Number (ECCN)?

    Answer: EAR

    The Export Administration Regulations (EAR) govern dual-use items including encryption software and assign ECCNs to classify controlled items.

  4. An administrator discovers that a vendor's software EULA prohibits reverse engineering. Under which U.S. law does a narrow 'interoperability' exception allow limited reverse engineering despite such contractual prohibitions?

    Answer: Digital Millennium Copyright Act

    The DMCA Section 1201(f) provides an interoperability exception permitting reverse engineering of software solely to achieve compatibility.

  5. SOC 2 Type II reports differ from SOC 2 Type I reports primarily because Type II reports:

    Answer: Evaluate design and operating effectiveness over a period of time

    SOC 2 Type II evaluates both the design and operating effectiveness of controls over a defined review period, typically 6–12 months.

  6. Under GDPR, which legal basis allows an organization to process personal data without explicit user consent when it is necessary to fulfill a contract with that individual?

    Answer: Contractual necessity

    Article 6(1)(b) of GDPR permits processing when it is necessary for the performance of a contract to which the data subject is party.

  7. A system administrator at a federally funded university must ensure research systems comply with NIST SP 800-171. Which type of data does this standard specifically protect?

    Answer: Controlled Unclassified Information (CUI)

    NIST SP 800-171 establishes requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.