CySA+ Test Compliance Frameworks 2 — Questions and Answers
Question 1: Which NIST CSF function focuses on developing organizational understanding to manage cybersecurity risk to systems, people, assets, and data?
- Protect
- Identify (Correct answer)
- Detect
- Respond
Correct answer: Identify
The Identify function establishes the foundation for an effective cybersecurity program by building organizational understanding of risk context.
Question 2: Under GDPR, what is the maximum timeframe for notifying a supervisory authority after discovering a personal data breach?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notification to the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 3: A healthcare organization uses a third-party billing company that accesses PHI. What agreement must be in place under HIPAA?
- Data Processing Agreement (DPA)
- Business Associate Agreement (BAA) (Correct answer)
- Non-Disclosure Agreement (NDA)
- Service Level Agreement (SLA)
Correct answer: Business Associate Agreement (BAA)
HIPAA requires a Business Associate Agreement with any third party that creates, receives, maintains, or transmits PHI on behalf of a covered entity.
Question 4: Which PCI DSS requirement mandates that cardholder data environments be separated from other network segments?
- Requirement 3 — Protect stored cardholder data
- Requirement 6 — Develop and maintain secure systems
- Requirement 1 — Install and maintain network security controls (Correct answer)
- Requirement 11 — Test security systems and networks regularly
Correct answer: Requirement 1 — Install and maintain network security controls
PCI DSS Requirement 1 covers network security controls including firewall configuration and network segmentation to isolate the cardholder data environment.
Question 5: SOC 2 Type II reports differ from SOC 2 Type I reports primarily because Type II reports evaluate:
- A broader set of trust service criteria
- Controls over a period of time, not just a point in time (Correct answer)
- Only financial reporting controls
- Third-party vendor controls as well
Correct answer: Controls over a period of time, not just a point in time
SOC 2 Type II assesses the operating effectiveness of controls over a defined period (typically 6–12 months), while Type I only evaluates design at a single point in time.
Question 6: Which NIST SP 800-53 control family addresses audit and accountability requirements?
- AC — Access Control
- AU — Audit and Accountability (Correct answer)
- CA — Assessment, Authorization and Monitoring
- SI — System and Information Integrity
Correct answer: AU — Audit and Accountability
The AU control family in NIST SP 800-53 covers audit event logging, audit record review, protection, and retention.
Question 7: An organization operating critical infrastructure must comply with NERC CIP. Which standard specifically addresses electronic security perimeters?
- NERC CIP-002
- NERC CIP-005 (Correct answer)
- NERC CIP-007
- NERC CIP-010
Correct answer: NERC CIP-005
NERC CIP-005 requires entities to identify and protect Electronic Security Perimeters and associated access points for critical cyber assets.
Which NIST CSF function focuses on developing organizational understanding to manage cybersecurity risk to systems, people, assets, and data?