Cyber Security Jobs Security Compliance and Regulations 2 — Questions and Answers
Question 1: What is the purpose of a risk assessment in a compliance program?
- Identify, analyze, and prioritize risks to determine appropriate security controls (Correct answer)
- Enumerate all open network ports
- Test employee phishing awareness
- Verify software license compliance
Correct answer: Identify, analyze, and prioritize risks to determine appropriate security controls
Risk assessments identify potential threats, analyze their likelihood and impact, and help organizations prioritize which controls to implement first.
Question 2: Under GDPR, even though it is a European law, which US companies must comply with it?
- Any US company that processes personal data of EU residents (Correct answer)
- Only US companies with EU headquarters
- Companies listed on European stock exchanges
- Only technology companies with over 500 employees
Correct answer: Any US company that processes personal data of EU residents
GDPR applies to any organization worldwide that processes personal data of EU residents, regardless of where the company is headquartered.
Question 3: What is a SOC 2 report used for?
- Demonstrating that a service provider's controls meet trust service criteria for security, availability, and confidentiality (Correct answer)
- Filing quarterly financial statements with the SEC
- Documenting physical facility access logs
- Certifying compliance with HIPAA privacy rules
Correct answer: Demonstrating that a service provider's controls meet trust service criteria for security, availability, and confidentiality
SOC 2 reports (developed by AICPA) assess and attest to a service organization's controls related to security, availability, processing integrity, confidentiality, and privacy.
Question 4: What does 'least privilege' mean as a compliance and security principle?
- Users and systems should have only the minimum access needed to perform their role (Correct answer)
- All users should have equal access to all systems
- Administrators should hold the most privileged accounts at all times
- Guest accounts should be disabled by default
Correct answer: Users and systems should have only the minimum access needed to perform their role
The principle of least privilege limits user and system permissions to the bare minimum required for their function, reducing the blast radius of any compromise.
Question 5: What is a DPA (Data Processing Agreement) and when is it required?
- A contract between a data controller and processor outlining GDPR-compliant data handling obligations (Correct answer)
- A federal warrant authorizing data collection
- A firewall policy document
- An SLA for cloud storage uptime
Correct answer: A contract between a data controller and processor outlining GDPR-compliant data handling obligations
A DPA is a legally binding contract required under GDPR between organizations and their third-party data processors to ensure compliant data handling.
Question 6: Which US standard applies to organizations handling Controlled Unclassified Information (CUI) for the Department of Defense?
- CMMC (Cybersecurity Maturity Model Certification) (Correct answer)
- HIPAA
- PCI DSS
- ISO 9001
Correct answer: CMMC (Cybersecurity Maturity Model Certification)
CMMC requires defense contractors handling CUI to achieve certified cybersecurity maturity levels before being awarded DoD contracts.
What is the purpose of a risk assessment in a compliance program?