CSS Risk Management & Compliance 3 โ Questions and Answers
Question 1: The EU General Data Protection Regulation (GDPR) requires organizations to report a personal data breach to the relevant supervisory authority within what timeframe?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 mandates that controllers notify the competent supervisory authority of a personal data breach within 72 hours of becoming aware of it, where feasible.
Question 2: A senior specialist implements data masking on production database exports used for testing. This control is BEST described as which type?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Data masking is a preventive control because it proactively reduces exposure of sensitive data before unauthorized access can occur.
Question 3: Which compliance framework is specifically designed for payment card data security and applies to all entities that store, process, or transmit cardholder data?
- ISO 27001
- PCI DSS (Correct answer)
- COBIT 5
- FedRAMP
Correct answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) mandates security requirements for any organization involved in payment card processing.
Question 4: In enterprise risk management, 'inherent risk' is BEST defined as:
- Risk remaining after controls are applied
- Risk that is fully transferred to a third party
- Risk existing before any controls are implemented (Correct answer)
- Risk accepted by senior leadership
Correct answer: Risk existing before any controls are implemented
Inherent risk is the level of risk present in the absence of any controls or mitigation measures.
Question 5: A healthcare organization must conduct a Security Risk Analysis under which federal regulation?
- HITECH Act
- HIPAA Security Rule (Correct answer)
- HIPAA Privacy Rule
- Affordable Care Act
Correct answer: HIPAA Security Rule
The HIPAA Security Rule (45 CFR ยง 164.308(a)(1)) requires covered entities and business associates to conduct an accurate and thorough Security Risk Analysis.
Question 6: When a senior specialist performs a third-party vendor risk assessment, which document is MOST important to review for understanding the vendor's security posture?
- The vendor's marketing brochure
- SOC 2 Type II report (Correct answer)
- The vendor's SLA agreement only
- The vendor's business license
Correct answer: SOC 2 Type II report
A SOC 2 Type II report provides an independent auditor's assessment of a vendor's controls over security, availability, processing integrity, confidentiality, and privacy over a period of time.
Question 7: The concept of 'defense in depth' in risk management refers to:
- Using a single, highly robust control to mitigate all risks
- Transferring all identified risks to insurance carriers
- Implementing multiple layers of controls so that if one fails, others remain effective (Correct answer)
- Documenting all risks in a register before taking action
Correct answer: Implementing multiple layers of controls so that if one fails, others remain effective
Defense in depth employs multiple overlapping security controls so that the failure of any single control does not result in a complete security compromise.
The EU General Data Protection Regulation (GDPR) requires organizations to report a personal data breach to the relevant supervisory authority within what timeframe?