Full-Stack Development Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under HIPAA's Security Rule, which safeguard category requires organizations to implement policies and procedures for managing workforce access to ePHI?
- Physical Safeguards
- Administrative Safeguards (Correct answer)
- Technical Safeguards
- Organizational Safeguards
Correct answer: Administrative Safeguards
Administrative Safeguards cover workforce training, access management policies, and security management processes for ePHI.
Question 2: A developer builds an API that collects location data from EU users. Under GDPR, which legal basis most commonly applies when the user explicitly agrees to location tracking for personalized ads?
- Legitimate interests
- Legal obligation
- Consent (Correct answer)
- Vital interests
Correct answer: Consent
Consent is the correct legal basis when a user explicitly agrees to a specific processing purpose like personalized advertising.
Question 3: Which PCI DSS requirement mandates that cardholder data must be encrypted when transmitted over open, public networks?
- Requirement 3
- Requirement 4 (Correct answer)
- Requirement 6
- Requirement 8
Correct answer: Requirement 4
PCI DSS Requirement 4 specifically addresses protecting cardholder data in transit over open or public networks using strong cryptography.
Question 4: A company stores user passwords using MD5 hashing without a salt. Which compliance standard is most likely to flag this as a violation?
- COPPA
- CCPA
- PCI DSS (Correct answer)
- CAN-SPAM
Correct answer: PCI DSS
PCI DSS Requirement 8 mandates strong cryptographic controls for authentication credentials, ruling out weak algorithms like unsalted MD5.
Question 5: What is the maximum fine under GDPR for the most serious violations, such as unlawful processing of data?
- €10 million or 2% of global annual turnover
- €20 million or 4% of global annual turnover (Correct answer)
- €50 million or 5% of global annual turnover
- €5 million or 1% of global annual turnover
Correct answer: €20 million or 4% of global annual turnover
GDPR's upper tier penalty is €20 million or 4% of global annual turnover, whichever is higher, for the most serious infringements.
Question 6: A full-stack app uses a third-party analytics library that sets tracking cookies. Under GDPR's ePrivacy rules, when must users be informed and give consent?
- Only after the first page visit
- Before any non-essential cookies are set (Correct answer)
- Within 30 days of first visit
- Only if the user navigates to an account page
Correct answer: Before any non-essential cookies are set
Non-essential cookies (including analytics) require prior informed consent under ePrivacy Directive rules enforced alongside GDPR.
Question 7: Under SOC 2 Type II, what distinguishes it from SOC 2 Type I?
- Type II covers more Trust Service Criteria
- Type II tests controls over a period of time rather than a single point (Correct answer)
- Type II is only for financial data
- Type II requires government auditors
Correct answer: Type II tests controls over a period of time rather than a single point
SOC 2 Type II audits the effectiveness of controls over a period (typically 6–12 months), while Type I only assesses design at a point in time.
Under HIPAA's Security Rule, which safeguard category requires organizations to implement policies and procedures for managing workforce access to ePHI?