CSM Regulatory Compliance & Governance 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 302
- Section 404 (Correct answer)
- Section 906
- Section 201
Correct answer: Section 404
SOX Section 404 requires management to assess and report on the effectiveness of internal controls over financial reporting annually.
Question 2: A software manager discovers that a third-party vendor has access to customer PII but has not signed a Data Processing Agreement (DPA). Under GDPR, what is the immediate required action?
- Terminate the vendor contract immediately
- Execute a DPA before any further data processing (Correct answer)
- Report the vendor to the supervisory authority
- Encrypt all data shared with the vendor
Correct answer: Execute a DPA before any further data processing
GDPR Article 28 requires a written DPA to be in place before a processor can lawfully handle personal data on behalf of a controller.
Question 3: In IT governance frameworks, which COBIT 5 domain is primarily responsible for ensuring that IT services are delivered effectively and efficiently?
- Evaluate, Direct and Monitor (EDM)
- Align, Plan and Organize (APO)
- Deliver, Service and Support (DSS) (Correct answer)
- Build, Acquire and Implement (BAI)
Correct answer: Deliver, Service and Support (DSS)
The DSS (Deliver, Service and Support) domain in COBIT 5 focuses on the delivery of IT services and support operations.
Question 4: Which U.S. federal law primarily governs the privacy and security of protected health information (PHI) in software systems used by healthcare providers?
- FERPA
- GLBA
- HIPAA (Correct answer)
- COPPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes national standards for protecting PHI in healthcare-related software and systems.
Question 5: A software manager is conducting a risk assessment for compliance purposes. Which approach best aligns with the NIST Risk Management Framework (RMF)?
- Identify assets, then immediately patch all vulnerabilities
- Categorize systems, select controls, implement, assess, authorize, and monitor continuously (Correct answer)
- Outsource all compliance activities to a third-party auditor
- Apply the same controls uniformly regardless of system sensitivity
Correct answer: Categorize systems, select controls, implement, assess, authorize, and monitor continuously
The NIST RMF follows a six-step process: Categorize, Select, Implement, Assess, Authorize, and Monitor.
Question 6: Under PCI DSS, what is the maximum number of digits that may be displayed when truncating a Primary Account Number (PAN) for display purposes?
- First 6 and last 4 digits only (Correct answer)
- First 4 and last 4 digits only
- First 8 digits only
- Last 8 digits only
Correct answer: First 6 and last 4 digits only
PCI DSS Requirement 3.3 permits displaying no more than the first six and last four digits of the PAN.
Question 7: An organization's software audit reveals that change management procedures were bypassed for an emergency hotfix. Which governance control is most directly violated?
- Separation of duties
- Change control policy (Correct answer)
- Access control policy
- Data classification policy
Correct answer: Change control policy
Bypassing the change management process violates the change control policy, which ensures all modifications are authorized, tested, and documented.
Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on the effectiveness of internal controls over financial reporting?