Microsoft Networking Essentials Exam Regulatory Frameworks & Compliance 3 — Questions and Answers
Question 1: An IT administrator at a defense contractor must comply with regulations protecting Controlled Unclassified Information (CUI). Which NIST publication defines these requirements?
- NIST SP 800-53
- NIST SP 800-171 (Correct answer)
- NIST SP 800-37
- NIST SP 800-61
Correct answer: NIST SP 800-171
NIST SP 800-171 defines requirements for protecting CUI in non-federal systems and organizations, particularly for defense contractors.
Question 2: Which compliance framework uses a shared responsibility model where cloud providers and customers each own specific security controls?
- PCI DSS
- SOX
- FedRAMP (Correct answer)
- FERPA
Correct answer: FedRAMP
FedRAMP uses a shared responsibility model where the cloud service provider and the federal agency customer each maintain certain security controls.
Question 3: A network engineer must ensure that a system meets CIS Benchmarks. What do CIS Benchmarks primarily provide?
- Legal requirements for data handling
- Prescriptive configuration guidelines for securing systems (Correct answer)
- Penetration testing methodologies
- Incident response procedures
Correct answer: Prescriptive configuration guidelines for securing systems
CIS (Center for Internet Security) Benchmarks provide consensus-based, prescriptive configuration guidelines for securely configuring operating systems, applications, and network devices.
Question 4: Under the Gramm-Leach-Bliley Act (GLBA), which rule requires financial institutions to implement a comprehensive information security program?
- Financial Privacy Rule
- Safeguards Rule (Correct answer)
- Pretexting Protection Rule
- Customer Identification Rule
Correct answer: Safeguards Rule
The GLBA Safeguards Rule requires financial institutions to implement a written, comprehensive information security program to protect customer financial information.
Question 5: Which international standard provides requirements for establishing, implementing, and maintaining an Information Security Management System (ISMS)?
- ISO 9001
- ISO 27001 (Correct answer)
- ISO 31000
- ISO 22301
Correct answer: ISO 27001
ISO/IEC 27001 is the international standard that specifies requirements for establishing and maintaining an Information Security Management System (ISMS).
Question 6: A company operating in California must comply with CCPA. What is a key right CCPA grants to consumers?
- Right to receive free credit monitoring
- Right to know what personal information is collected and request its deletion (Correct answer)
- Right to data portability across all US states
- Right to opt out of all digital advertising globally
Correct answer: Right to know what personal information is collected and request its deletion
CCPA grants California consumers the right to know what personal information is collected about them, to delete that information, and to opt out of its sale.
Question 7: Which US government authorization process must cloud service providers complete to offer services to federal agencies?
- FISMA certification
- FedRAMP authorization (Correct answer)
- CMMC accreditation
- StateRAMP approval
Correct answer: FedRAMP authorization
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach for cloud product and service authorization for federal agencies.
An IT administrator at a defense contractor must comply with regulations protecting Controlled Unclassified Information (CUI).
Which NIST publication defines these requirements?