Microsoft Networking Essentials Exam Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Which US federal law governs the privacy of student education records and applies to institutions that receive federal funding?
- FERPA (Correct answer)
- HIPAA
- COPPA
- GLBA
Correct answer: FERPA
FERPA (Family Educational Rights and Privacy Act) protects the privacy of student education records at federally funded institutions.
Question 2: An organization must retain network logs for 7 years for audit purposes. Which compliance framework most likely mandates this for financial institutions?
- SOX (Sarbanes-Oxley Act) (Correct answer)
- HIPAA
- PCI DSS
- FERPA
Correct answer: SOX (Sarbanes-Oxley Act)
SOX requires financial institutions to retain certain records, including audit logs, for a minimum of 7 years.
Question 3: A company processes credit card payments online. Which standard mandates that cardholder data must be encrypted during transmission over public networks?
- ISO 27001
- PCI DSS (Correct answer)
- NIST CSF
- FTC Act
Correct answer: PCI DSS
PCI DSS Requirement 4 mandates encryption of cardholder data transmitted over open, public networks.
Question 4: Which NIST publication provides a comprehensive framework for improving critical infrastructure cybersecurity?
- NIST SP 800-53
- NIST SP 800-171
- NIST CSF (Cybersecurity Framework) (Correct answer)
- NIST SP 800-37
Correct answer: NIST CSF (Cybersecurity Framework)
The NIST Cybersecurity Framework (CSF) provides a voluntary framework for organizations to manage and reduce cybersecurity risk to critical infrastructure.
Question 5: Under GDPR, what is the maximum time an organization has to report a data breach to the supervisory authority after becoming aware of it?
- 24 hours
- 48 hours
- 72 hours (Correct answer)
- 7 days
Correct answer: 72 hours
GDPR Article 33 requires notifying the supervisory authority within 72 hours of becoming aware of a personal data breach.
Question 6: A healthcare network administrator is configuring access controls for electronic health records. Which HIPAA rule primarily governs these technical safeguards?
- HIPAA Privacy Rule
- HIPAA Security Rule (Correct answer)
- HIPAA Breach Notification Rule
- HIPAA Enforcement Rule
Correct answer: HIPAA Security Rule
The HIPAA Security Rule specifically addresses technical safeguards, including access controls for electronic protected health information (ePHI).
Question 7: Which of the following best describes the purpose of the Children's Online Privacy Protection Act (COPPA)?
- Protects children from cyberbullying on social media
- Requires parental consent before collecting personal data from children under 13 (Correct answer)
- Mandates content filtering on school networks
- Restricts minors from accessing adult websites
Correct answer: Requires parental consent before collecting personal data from children under 13
COPPA requires websites and online services to obtain verifiable parental consent before collecting personal information from children under 13.
Which US federal law governs the privacy of student education records and applies to institutions that receive federal funding?