โ† All CSA Flashcard Decks

Regulatory Compliance & Licensing Flashcards

7 cards from real CSA practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Regulatory Compliance & Licensing flashcards as text
  1. An organization subject to GDPR experiences a personal data breach. Within what timeframe must they notify the relevant supervisory authority if the breach poses a risk to individuals?

    Answer: 72 hours

    GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a breach, where feasible.

  2. Microsoft's volume licensing 'License Mobility through Software Assurance' benefit allows customers to do which of the following?

    Answer: Reassign licenses to shared servers in third-party hosted environments more frequently than normally permitted

    License Mobility through Software Assurance allows customers to reassign eligible server application licenses to third-party shared servers without the standard 90-day reassignment restriction.

  3. Which compliance standard specifically addresses security controls for organizations processing, storing, or transmitting cardholder data?

    Answer: PCI DSS

    The Payment Card Industry Data Security Standard (PCI DSS) was established by major card brands specifically to protect cardholder data environments.

  4. Under the Computer Fraud and Abuse Act (CFAA), which activity would most likely constitute a federal violation?

    Answer: A contractor accessing a database beyond the scope of their authorization

    The CFAA prohibits accessing a computer without authorization or exceeding authorized access, which includes a contractor accessing data outside the permitted scope.

  5. An organization holds Oracle Database Enterprise Edition licenses with 'Named User Plus' (NUP) licensing. The minimum NUP count per processor is:

    Answer: 25 NUPs per processor

    Oracle requires a minimum of 25 Named User Plus licenses per processor for Oracle Database Enterprise Edition.

  6. The Children's Online Privacy Protection Act (COPPA) requires operators of websites directed at children under 13 to obtain verifiable parental consent before:

    Answer: Collecting, using, or disclosing personal information from children

    COPPA mandates verifiable parental consent before collecting, using, or disclosing personal information from children under 13.

  7. A system administrator wants to verify that all software installed on company systems is licensed. Which process best describes this ongoing compliance activity?

    Answer: Software asset management (SAM)

    Software Asset Management (SAM) is the practice of managing and optimizing the purchase, deployment, and retirement of software licenses within an organization.