CSS Risk Management & Compliance 2 — Questions and Answers
Question 1: Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals of an unsecured PHI breach within how many days of discovery?
- 30 days
- 60 days (Correct answer)
- 90 days
- 180 days
Correct answer: 60 days
HIPAA requires covered entities to notify affected individuals without unreasonable delay and no later than 60 days after discovering a breach of unsecured PHI.
Question 2: A senior specialist is performing a risk assessment and identifies a threat with a likelihood of 'High' and an impact of 'Low.' According to standard risk matrix methodology, how should this risk be categorized?
- Critical
- High
- Medium (Correct answer)
- Low
Correct answer: Medium
On a standard 3×3 or 5×5 risk matrix, High likelihood × Low impact typically yields a Medium risk rating.
Question 3: Which federal law requires financial institutions to establish programs for customer identification and verification to prevent money laundering?
- Gramm-Leach-Bliley Act
- Bank Secrecy Act (Correct answer)
- Dodd-Frank Act
- Fair Credit Reporting Act
Correct answer: Bank Secrecy Act
The Bank Secrecy Act (BSA) and its Customer Identification Program (CIP) rules require financial institutions to verify customer identities to combat money laundering.
Question 4: In the NIST Cybersecurity Framework, which function focuses on developing and implementing appropriate safeguards to ensure delivery of critical infrastructure services?
- Identify
- Protect (Correct answer)
- Detect
- Respond
Correct answer: Protect
The 'Protect' function in the NIST CSF encompasses safeguards such as access control, training, data security, and maintenance to limit the impact of a cybersecurity event.
Question 5: A company's board of directors establishes the organization's risk appetite. Which document formally communicates acceptable risk levels to the entire organization?
- Business Continuity Plan
- Risk Register
- Risk Appetite Statement (Correct answer)
- Incident Response Policy
Correct answer: Risk Appetite Statement
A Risk Appetite Statement formally articulates the types and amount of risk the organization is willing to accept in pursuit of its objectives.
Question 6: Under SOX Section 404, management must assess the effectiveness of internal controls over financial reporting. Who must attest to and report on management's assessment?
- The Audit Committee
- The CFO only
- An independent registered public accounting firm (Correct answer)
- The Board of Directors
Correct answer: An independent registered public accounting firm
SOX Section 404(b) requires an independent registered public accounting firm to attest to and report on management's assessment of internal controls over financial reporting.
Question 7: Which risk response strategy involves sharing risk with a third party, such as through insurance or outsourcing?
- Risk avoidance
- Risk mitigation
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial or operational impact of a risk to another party, such as purchasing insurance or contracting with a vendor.
Under HIPAA's Breach Notification Rule, covered entities must notify affected individuals of an unsecured PHI breach within how many days of discovery?