CSA Regulatory Compliance & Licensing 2 — Questions and Answers
Question 1: Under HIPAA, what is the maximum civil monetary penalty per violation category when willful neglect is corrected within the required timeframe?
- $10,000
- $50,000 (Correct answer)
- $100,000
- $1,900,000
Correct answer: $50,000
HIPAA sets a maximum civil penalty of $50,000 per violation for willful neglect that is corrected within the required period.
Question 2: A company deploys software on 200 servers using a per-core license that allows 16 cores per license. How many licenses are required if each server has 24 physical cores?
- 200
- 300 (Correct answer)
- 400
- 600
Correct answer: 300
Each 24-core server needs 24/16 = 1.5 licenses, rounded up to 2, but per-core models typically count actual cores: 200 servers × 24 cores ÷ 16 cores/license = 300 licenses.
Question 3: Which U.S. federal regulation specifically governs the export of encryption software and requires an Export Control Classification Number (ECCN)?
- ITAR
- EAR (Correct answer)
- FISMA
- GLBA
Correct answer: EAR
The Export Administration Regulations (EAR) govern dual-use items including encryption software and assign ECCNs to classify controlled items.
Question 4: An administrator discovers that a vendor's software EULA prohibits reverse engineering. Under which U.S. law does a narrow 'interoperability' exception allow limited reverse engineering despite such contractual prohibitions?
- Computer Fraud and Abuse Act
- Digital Millennium Copyright Act (Correct answer)
- Sarbanes-Oxley Act
- Electronic Communications Privacy Act
Correct answer: Digital Millennium Copyright Act
The DMCA Section 1201(f) provides an interoperability exception permitting reverse engineering of software solely to achieve compatibility.
Question 5: SOC 2 Type II reports differ from SOC 2 Type I reports primarily because Type II reports:
- Cover a broader set of Trust Service Criteria
- Evaluate design and operating effectiveness over a period of time (Correct answer)
- Are prepared by management rather than external auditors
- Apply only to cloud service providers
Correct answer: Evaluate design and operating effectiveness over a period of time
SOC 2 Type II evaluates both the design and operating effectiveness of controls over a defined review period, typically 6–12 months.
Question 6: Under GDPR, which legal basis allows an organization to process personal data without explicit user consent when it is necessary to fulfill a contract with that individual?
- Legitimate interest
- Vital interests
- Contractual necessity (Correct answer)
- Legal obligation
Correct answer: Contractual necessity
Article 6(1)(b) of GDPR permits processing when it is necessary for the performance of a contract to which the data subject is party.
Question 7: A system administrator at a federally funded university must ensure research systems comply with NIST SP 800-171. Which type of data does this standard specifically protect?
- Personally Identifiable Information (PII)
- Controlled Unclassified Information (CUI) (Correct answer)
- Protected Health Information (PHI)
- Classified National Security Information
Correct answer: Controlled Unclassified Information (CUI)
NIST SP 800-171 establishes requirements for protecting Controlled Unclassified Information (CUI) in non-federal systems and organizations.
Under HIPAA, what is the maximum civil monetary penalty per violation category when willful neglect is corrected within the required timeframe?