GCP Regulatory Compliance & Legal Framework 2 — Questions and Answers
Question 1: Under HIPAA, which entity is directly responsible for safeguarding protected health information (PHI) when using a cloud service provider?
- The cloud service provider only
- The covered entity and its business associates (Correct answer)
- The U.S. Department of Health and Human Services
- The patient whose data is stored
Correct answer: The covered entity and its business associates
Both covered entities and their business associates share responsibility for PHI protection under HIPAA, requiring a signed Business Associate Agreement (BAA) with cloud providers.
Question 2: Which U.S. federal law governs the privacy and security of student education records stored in cloud systems?
- COPPA
- FERPA (Correct answer)
- GLBA
- CCPA
Correct answer: FERPA
The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records and restricts their disclosure without consent.
Question 3: A company stores credit card data in Google Cloud Storage. Which compliance standard primarily governs how this data must be secured?
- SOC 2 Type II
- ISO 27001
- PCI DSS (Correct answer)
- NIST CSF
Correct answer: PCI DSS
The Payment Card Industry Data Security Standard (PCI DSS) specifically governs the storage, processing, and transmission of cardholder data.
Question 4: Under GDPR, what is the maximum timeframe within which a data breach must be reported to the supervisory authority?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires that personal data breaches be reported to the supervisory authority within 72 hours of becoming aware of the breach.
Question 5: Which GCP feature helps organizations demonstrate compliance by providing audit logs of all API calls and administrative actions?
- Cloud Trace
- Cloud Profiler
- Cloud Audit Logs (Correct answer)
- Cloud Monitoring
Correct answer: Cloud Audit Logs
Cloud Audit Logs records administrative activity and data access events, providing an immutable trail needed for compliance audits.
Question 6: The Children's Online Privacy Protection Act (COPPA) applies to websites and online services directed at children under what age?
- Under 13 (Correct answer)
- Under 16
- Under 18
- Under 21
Correct answer: Under 13
COPPA applies to operators of websites and online services directed to children under 13 years of age, requiring parental consent before collecting their data.
Question 7: Which legal concept requires that data collected for one specified purpose cannot be used for an unrelated purpose without additional consent under GDPR?
- Data minimization
- Purpose limitation (Correct answer)
- Storage limitation
- Integrity and confidentiality
Correct answer: Purpose limitation
GDPR's purpose limitation principle (Article 5(1)(b)) mandates that personal data be collected for specified, explicit, and legitimate purposes and not further processed incompatibly.
Under HIPAA, which entity is directly responsible for safeguarding protected health information (PHI) when using a cloud service provider?