Regulatory Compliance & Legal Framework Flashcards
7 cards from real GCP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Regulatory Compliance & Legal Framework flashcards as text
Under the International Traffic in Arms Regulations (ITAR), which type of cloud data storage arrangement could expose a company to ITAR violations?
Answer: Allowing foreign nationals to access controlled technical data without authorization
ITAR defines 'export' to include giving foreign nationals access to controlled defense-related technical data, even within the U.S., without proper authorization.
A healthcare SaaS provider uses GCP to process PHI. To comply with HIPAA, the provider must ensure GCP has signed a:
Answer: Business Associate Agreement (BAA)
HIPAA requires a signed Business Associate Agreement between covered entities or business associates and any cloud service provider that creates, receives, maintains, or transmits PHI on their behalf.
The NIST Cybersecurity Framework (CSF) organizes security activities into five core functions. Which function focuses on detecting the occurrence of a cybersecurity event?
Answer: Detect
The 'Detect' function of the NIST CSF encompasses activities that enable timely discovery of cybersecurity events through continuous monitoring and anomaly detection.
An organization must comply with the Sarbanes-Oxley Act (SOX). Which GCP capability is most directly relevant to meeting SOX's internal control requirements for financial reporting?
Answer: Immutable Cloud Audit Logs with access controls
SOX Section 302 and 404 require reliable audit trails and internal controls; immutable audit logs with strict access controls provide evidence of those controls for financial systems.
Which principle in data privacy law states that only the minimum amount of personal data necessary for the specified purpose should be collected?
Answer: Data minimization
Data minimization, codified in GDPR Article 5(1)(c), requires that personal data be adequate, relevant, and limited to what is necessary for the processing purpose.
Which GCP service provides a managed Hardware Security Module (HSM) environment to help organizations meet FIPS 140-2 Level 3 compliance for key management?
Answer: Cloud HSM
Cloud HSM is a managed service that hosts cryptographic keys in FIPS 140-2 Level 3 certified hardware security modules within Google's data centers.
The EU-U.S. Data Privacy Framework (DPF), which replaced Privacy Shield, allows personal data to flow from the EU to the U.S. under what condition?
Answer: The U.S. company self-certifies adherence to DPF principles with the U.S. Department of Commerce
The DPF requires U.S. companies to self-certify their commitment to its privacy principles with the Department of Commerce, enabling lawful EU-to-U.S. personal data transfers.