GCP Regulatory Compliance & Legal Framework 4 — Questions and Answers
Question 1: Under the International Traffic in Arms Regulations (ITAR), which type of cloud data storage arrangement could expose a company to ITAR violations?
- Storing unclassified technical data on a domestic-only server
- Allowing foreign nationals to access controlled technical data without authorization (Correct answer)
- Using encryption for data in transit
- Archiving publicly available aerospace documents
Correct answer: Allowing foreign nationals to access controlled technical data without authorization
ITAR defines 'export' to include giving foreign nationals access to controlled defense-related technical data, even within the U.S., without proper authorization.
Question 2: A healthcare SaaS provider uses GCP to process PHI. To comply with HIPAA, the provider must ensure GCP has signed a:
- Data Sharing Agreement
- Business Associate Agreement (BAA) (Correct answer)
- Privacy Shield certification
- Data Classification Contract
Correct answer: Business Associate Agreement (BAA)
HIPAA requires a signed Business Associate Agreement between covered entities or business associates and any cloud service provider that creates, receives, maintains, or transmits PHI on their behalf.
Question 3: The NIST Cybersecurity Framework (CSF) organizes security activities into five core functions. Which function focuses on detecting the occurrence of a cybersecurity event?
- Identify
- Protect
- Detect (Correct answer)
- Respond
Correct answer: Detect
The 'Detect' function of the NIST CSF encompasses activities that enable timely discovery of cybersecurity events through continuous monitoring and anomaly detection.
Question 4: An organization must comply with the Sarbanes-Oxley Act (SOX). Which GCP capability is most directly relevant to meeting SOX's internal control requirements for financial reporting?
- Cloud Load Balancing
- Immutable Cloud Audit Logs with access controls (Correct answer)
- Cloud CDN
- Managed Instance Groups
Correct answer: Immutable Cloud Audit Logs with access controls
SOX Section 302 and 404 require reliable audit trails and internal controls; immutable audit logs with strict access controls provide evidence of those controls for financial systems.
Question 5: Which principle in data privacy law states that only the minimum amount of personal data necessary for the specified purpose should be collected?
- Accountability
- Data minimization (Correct answer)
- Lawfulness
- Transparency
Correct answer: Data minimization
Data minimization, codified in GDPR Article 5(1)(c), requires that personal data be adequate, relevant, and limited to what is necessary for the processing purpose.
Question 6: Which GCP service provides a managed Hardware Security Module (HSM) environment to help organizations meet FIPS 140-2 Level 3 compliance for key management?
- Cloud KMS
- Cloud HSM (Correct answer)
- Secret Manager
- Certificate Manager
Correct answer: Cloud HSM
Cloud HSM is a managed service that hosts cryptographic keys in FIPS 140-2 Level 3 certified hardware security modules within Google's data centers.
Question 7: The EU-U.S. Data Privacy Framework (DPF), which replaced Privacy Shield, allows personal data to flow from the EU to the U.S. under what condition?
- The U.S. company has any active ISO certification
- The U.S. company self-certifies adherence to DPF principles with the U.S. Department of Commerce (Correct answer)
- The data is encrypted with AES-256
- The data transfer is approved by a GDPR supervisory authority
Correct answer: The U.S. company self-certifies adherence to DPF principles with the U.S. Department of Commerce
The DPF requires U.S. companies to self-certify their commitment to its privacy principles with the Department of Commerce, enabling lawful EU-to-U.S. personal data transfers.
Under the International Traffic in Arms Regulations (ITAR), which type of cloud data storage arrangement could expose a company to ITAR violations?