Compliance Frameworks Flashcards
7 cards from real CySA+ Test practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Compliance Frameworks flashcards as text
An organization subject to SOX must ensure that controls over financial reporting are audited annually. Which section of SOX specifically addresses internal control requirements?
Answer: Section 404
SOX Section 404 requires management and external auditors to report annually on the adequacy of the internal control structure over financial reporting.
Which NIST SP 800-37 step involves authorizing the system to operate based on acceptable risk?
Answer: Authorize
The Authorize step in the RMF requires an authorizing official to make a risk-based decision to operate the system based on evaluated controls and residual risk.
A CySA+ analyst is mapping organizational controls to the NIST CSF. An IDS alert workflow falls under which NIST CSF function?
Answer: Detect
The Detect function covers anomalies and events, continuous security monitoring, and detection processes — including IDS alert workflows.
Under CCPA, California residents have the right to opt out of which specific business activity involving their personal information?
Answer: Selling their personal information to third parties
CCPA grants California residents the right to opt out of the sale of their personal information to third parties.
Which NIST SP 800-53 control family directly addresses supply chain risk management?
Answer: SR — Supply Chain Risk Management
The SR control family, added in NIST SP 800-53 Rev. 5, specifically addresses supply chain risk management including supplier assessments and component integrity.
During a PCI DSS assessment, the QSA finds that the organization uses multi-factor authentication only for remote access. According to PCI DSS v4.0, where else is MFA now required?
Answer: For all non-console administrative access into the CDE
PCI DSS v4.0 Requirement 8.4.2 requires MFA for all non-console administrative access into the CDE, expanding beyond just remote access.
A company uses the COBIT framework for IT governance. Which COBIT domain covers the monitoring and evaluation of IT performance and controls?
Answer: Monitor and Evaluate (ME)
The Monitor and Evaluate (ME) domain in COBIT covers monitoring IT performance, internal controls, regulatory compliance, and IT governance.