CSC Security Controls & Compliance Implementation 3 — Questions and Answers
Question 1: A healthcare organization must ensure that a business associate handles PHI according to HIPAA requirements. What document formalizes this obligation?
- Data Processing Agreement (DPA)
- Business Associate Agreement (BAA) (Correct answer)
- Service Level Agreement (SLA)
- Non-Disclosure Agreement (NDA)
Correct answer: Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is required by HIPAA when a covered entity shares PHI with a third-party business associate, specifying permissible uses and required safeguards.
Question 2: In the context of the NIST Risk Management Framework (RMF), what happens during the 'Authorize' step?
- Security controls are selected based on system categorization
- A senior official accepts residual risk and grants an Authorization to Operate (ATO) (Correct answer)
- The system is monitored continuously for security control effectiveness
- Security controls are tested to verify they function as intended
Correct answer: A senior official accepts residual risk and grants an Authorization to Operate (ATO)
During the Authorize step, an Authorizing Official reviews the security authorization package and formally accepts residual risk by granting or denying an ATO.
Question 3: Which of the following BEST describes the scope of GDPR applicability?
- It applies only to organizations physically located within EU member states
- It applies to any organization that processes personal data of EU residents, regardless of where the organization is located (Correct answer)
- It applies only to organizations with more than 250 employees
- It applies only to organizations in the financial and healthcare sectors
Correct answer: It applies to any organization that processes personal data of EU residents, regardless of where the organization is located
GDPR has extraterritorial reach and applies to any organization worldwide that processes personal data of individuals located in the EU, regardless of the organization's location.
Question 4: A security team uses a vulnerability scanner and discovers a critical vulnerability in a web application. According to common compliance frameworks, what is the typical required remediation timeframe for critical vulnerabilities?
- Within 180 days
- Within 30 days (Correct answer)
- Within 7 days
- Within 1 year
Correct answer: Within 30 days
Most compliance frameworks, including PCI DSS, require critical vulnerabilities to be remediated within 30 days of discovery.
Question 5: What is the primary purpose of configuration baselines in compliance programs?
- To document the history of all system changes made over time
- To establish a known secure state against which systems are measured and deviations detected (Correct answer)
- To provide a rollback point if a system update causes performance issues
- To define the minimum hardware specifications for compliant systems
Correct answer: To establish a known secure state against which systems are measured and deviations detected
Configuration baselines define the approved secure configuration state, enabling organizations to detect and respond to unauthorized or non-compliant configuration changes.
Question 6: Under ISO 27001, what is the role of the Statement of Applicability (SoA)?
- It lists all vulnerabilities discovered during the internal audit
- It documents which Annex A controls are applicable, included, or excluded with justification (Correct answer)
- It specifies the certification body that will conduct the ISO 27001 audit
- It defines the risk appetite and tolerance thresholds for the organization
Correct answer: It documents which Annex A controls are applicable, included, or excluded with justification
The SoA is a required ISO 27001 document that maps each Annex A control to the organization, stating applicability, implementation status, and justification for exclusions.
Question 7: Which type of access control model enforces access decisions based on security labels assigned to both subjects and objects?
- Discretionary Access Control (DAC)
- Role-Based Access Control (RBAC)
- Mandatory Access Control (MAC) (Correct answer)
- Attribute-Based Access Control (ABAC)
Correct answer: Mandatory Access Control (MAC)
MAC uses security labels (classification levels and categories) assigned to subjects and objects, with access enforced by the system based on policy rather than owner discretion.
A healthcare organization must ensure that a business associate handles PHI according to HIPAA requirements.
What document formalizes this obligation?