SC-100 Compliance, Governance & Data Security — Questions and Answers
Question 1: What is the purpose of data governance?
- To increase storage costs.
- To manage data effectively and ensure compliance (Correct answer)
- To delete old records.
- To bypass security policies.
Correct answer: To manage data effectively and ensure compliance
Data governance establishes a framework of policies, processes, and standards for managing an organization's data assets throughout their lifecycle. Its primary purpose is to ensure data quality, integrity, security, and usability. By doing so, it helps organizations meet regulatory requirements, mitigate risks, and make better business decisions based on reliable and compliant data.
Question 2: Which regulation is designed to protect personal data of EU citizens?
- HIPAA
- GDPR (Correct answer)
- FERPA
- SOX
Correct answer: GDPR
The General Data Protection Regulation (GDPR) is a comprehensive data privacy and security law enacted by the European Union. It grants individuals within the EU/EEA greater control over their personal data and imposes strict obligations on organizations that collect, process, or store data of EU citizens, regardless of the organization's location. Its aim is to harmonize data privacy laws across Europe and protect individual rights.
Question 3: What does data classification involve?
- Color-coding documents.
- Storing data in public drives.
- Identifying and categorizing data sensitivity levels (Correct answer)
- Sharing passwords freely.
Correct answer: Identifying and categorizing data sensitivity levels
Data classification is the process of organizing data into categories based on its sensitivity, value, and regulatory requirements. This categorization helps organizations apply appropriate security controls, access permissions, and retention policies to different types of information. By understanding the sensitivity of data, resources can be allocated effectively to protect the most critical information from unauthorized access or misuse.
Question 4: Which framework helps align IT with business compliance needs?
- CMMI
- COBIT (Correct answer)
- ITIL
- OSHA
Correct answer: COBIT
COBIT (Control Objectives for Information and Related Technologies) is a globally recognized framework that helps organizations govern and manage their enterprise IT. It provides a comprehensive set of principles, practices, and analytical tools to align IT with business objectives, including compliance needs and risk management. By integrating IT governance with overall corporate governance, COBIT ensures that IT supports the achievement of business goals while managing risks effectively.
Question 5: What is a data breach?
- Authorized access to secure files.
- A legal audit of company files.
- Unauthorized access to sensitive data (Correct answer)
- Routine system backup.
Correct answer: Unauthorized access to sensitive data
A data breach occurs when sensitive, protected, or confidential data is accessed, viewed, stolen, or used by an unauthorized individual or entity. This unauthorized access can lead to significant financial losses, reputational damage, and legal consequences for an organization. It represents a critical failure in security controls designed to protect information assets.
Question 6: Which standard outlines requirements for an information security management system (ISMS)?
- PCI DSS
- ISO/IEC 27001 (Correct answer)
- SOC 2
- NIST SP 800-53
Correct answer: ISO/IEC 27001
ISO/IEC 27001 is an internationally recognized standard that specifies the requirements for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS). An ISMS is a systematic approach to managing sensitive company information so that it remains secure. Achieving ISO 27001 certification demonstrates an organization's commitment to robust information security practices and helps manage information security risks effectively.
Question 7: Why is auditing important in compliance?
- To prevent system upgrades.
- To remove legacy systems.
- To verify compliance and identify gaps (Correct answer)
- To slow down operations.
Correct answer: To verify compliance and identify gaps
Auditing in compliance involves systematically examining an organization's processes, controls, and records against established regulations, policies, and standards. This process helps to verify that the organization is adhering to its compliance obligations and to identify any areas of non-compliance or weaknesses in its controls. Regular audits are crucial for maintaining a strong compliance posture, mitigating risks, and demonstrating due diligence to regulators.
Question 8: What is data retention policy?
- Unlimited data storage.
- Never deleting data.
- Guidelines for data retention and secure disposal (Correct answer)
- Storing all data in the cloud only.
Correct answer: Guidelines for data retention and secure disposal
A data retention policy defines how long specific types of data should be kept and how they should be securely disposed of once their retention period expires. This policy is crucial for meeting legal and regulatory requirements, managing storage costs, and minimizing the risk associated with holding unnecessary sensitive data. It ensures data is available when needed but removed when no longer legally or operationally required.
Question 9: What is the main benefit of compliance automation tools?
- They block user access.
- They reduce compliance errors and improve efficiency (Correct answer)
- They increase audit time.
- They simplify data breaches.
Correct answer: They reduce compliance errors and improve efficiency
Compliance automation tools streamline the process of monitoring, reporting, and managing adherence to various regulations and internal policies. By automating repetitive tasks, these tools minimize human error, accelerate compliance checks, and provide real-time visibility into an organization's compliance status. This leads to significant improvements in efficiency and accuracy, freeing up resources for more strategic tasks and reducing the overall cost of compliance.
What is the purpose of data governance?