CSC Regulatory Compliance & Legal Aspects 2 — Questions and Answers
Question 1: Under HIPAA, what is the maximum annual civil penalty for violations in the 'willful neglect – not corrected' category?
- $25,000
- $100,000
- $1,000,000
- $1,919,173 (Correct answer)
Correct answer: $1,919,173
HHS adjusts HIPAA civil monetary penalties annually for inflation; the 2023 cap for willful neglect not corrected is $1,919,173 per violation category per year.
Question 2: Which legal doctrine holds that an organization must demonstrate it exercised reasonable care in protecting sensitive data to avoid negligence liability?
- Respondeat superior
- Duty of care (Correct answer)
- Proximate cause
- Strict liability
Correct answer: Duty of care
Duty of care requires organizations to take reasonable precautions to protect data; failure to meet this standard can establish negligence.
Question 3: The EU-US Data Privacy Framework (DPF) replaced which prior agreement that was invalidated by the Schrems II ruling?
- Safe Harbor
- Privacy Shield (Correct answer)
- BCRs
- Standard Contractual Clauses
Correct answer: Privacy Shield
The Court of Justice of the EU invalidated Privacy Shield in July 2020 (Schrems II); the DPF was adopted in 2023 as the replacement mechanism.
Question 4: A security consultant discovers that a client's retail POS system stores full PAN data after authorization. Which PCI DSS requirement is most directly violated?
- Requirement 1 – Network segmentation
- Requirement 3 – Protect stored cardholder data (Correct answer)
- Requirement 6 – Secure systems and applications
- Requirement 10 – Log and monitor access
Correct answer: Requirement 3 – Protect stored cardholder data
PCI DSS Requirement 3 prohibits storing sensitive authentication data (including full magnetic-stripe data) post-authorization.
Question 5: Which federal law specifically governs the export of cybersecurity tools and intrusion software under US export control regulations?
- CFAA
- EAR / ECCN 4E001 (Correct answer)
- ITAR
- FISMA
Correct answer: EAR / ECCN 4E001
The Export Administration Regulations (EAR) classify many cybersecurity tools under ECCN 4E001, requiring a license for export to controlled countries.
Question 6: Under SOX Section 302, who must personally certify the accuracy of financial reports and the effectiveness of internal controls?
- External auditors
- Chief Financial Officer and Chief Executive Officer (Correct answer)
- Board audit committee members
- Chief Information Security Officer
Correct answer: Chief Financial Officer and Chief Executive Officer
Section 302 requires the CEO and CFO to personally sign certifications attesting to disclosure controls and financial statement accuracy.
Question 7: A penetration tester obtains written authorization but inadvertently accesses a third-party cloud provider's infrastructure shared with the client. Which law most likely applies to this unauthorized access?
- HIPAA
- Computer Fraud and Abuse Act (CFAA) (Correct answer)
- Gramm-Leach-Bliley Act
- Electronic Communications Privacy Act
Correct answer: Computer Fraud and Abuse Act (CFAA)
The CFAA prohibits unauthorized access to protected computers; accessing third-party shared infrastructure outside the scope of authorization triggers potential CFAA liability.
Under HIPAA, what is the maximum annual civil penalty for violations in the 'willful neglect – not corrected' category?