← All CySA+ Test Flashcard Decks

Compliance Frameworks Flashcards

7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Compliance Frameworks flashcards as text
  1. An organization subject to SOX must ensure that controls over financial reporting are audited annually. Which section of SOX specifically addresses internal control requirements?

    Answer: Section 404

    SOX Section 404 requires management and external auditors to report annually on the adequacy of the internal control structure over financial reporting.

  2. Which NIST SP 800-37 step involves authorizing the system to operate based on acceptable risk?

    Answer: Authorize

    The Authorize step in the RMF requires an authorizing official to make a risk-based decision to operate the system based on evaluated controls and residual risk.

  3. A CySA+ analyst is mapping organizational controls to the NIST CSF. An IDS alert workflow falls under which NIST CSF function?

    Answer: Detect

    The Detect function covers anomalies and events, continuous security monitoring, and detection processes — including IDS alert workflows.

  4. Under CCPA, California residents have the right to opt out of which specific business activity involving their personal information?

    Answer: Selling their personal information to third parties

    CCPA grants California residents the right to opt out of the sale of their personal information to third parties.

  5. Which NIST SP 800-53 control family directly addresses supply chain risk management?

    Answer: SR — Supply Chain Risk Management

    The SR control family, added in NIST SP 800-53 Rev. 5, specifically addresses supply chain risk management including supplier assessments and component integrity.

  6. During a PCI DSS assessment, the QSA finds that the organization uses multi-factor authentication only for remote access. According to PCI DSS v4.0, where else is MFA now required?

    Answer: For all non-console administrative access into the CDE

    PCI DSS v4.0 Requirement 8.4.2 requires MFA for all non-console administrative access into the CDE, expanding beyond just remote access.

  7. A company uses the COBIT framework for IT governance. Which COBIT domain covers the monitoring and evaluation of IT performance and controls?

    Answer: Monitor and Evaluate (ME)

    The Monitor and Evaluate (ME) domain in COBIT covers monitoring IT performance, internal controls, regulatory compliance, and IT governance.

Compliance Frameworks Flashcards — CySA+ Test Study Cards with Answers