Microsoft Networking Essentials Exam Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: A network administrator is implementing controls for a DoD contractor. Which compliance framework specifically addresses cybersecurity maturity levels for defense contractors?
- FedRAMP
- CMMC (Cybersecurity Maturity Model Certification) (Correct answer)
- FISMA
- SOC 2
Correct answer: CMMC (Cybersecurity Maturity Model Certification)
CMMC (Cybersecurity Maturity Model Certification) is a DoD framework that assesses and certifies the cybersecurity posture of defense contractors across maturity levels.
Question 2: Under HIPAA, which entity type is primarily responsible for compliance — a hospital that creates patient records or a billing company that processes those records?
- Only the hospital (covered entity)
- Only the billing company (business associate)
- Both the hospital as a covered entity and the billing company as a business associate (Correct answer)
- Neither, if the data is encrypted
Correct answer: Both the hospital as a covered entity and the billing company as a business associate
HIPAA applies to both covered entities (like hospitals) and their business associates (like billing companies) that handle protected health information.
Question 3: What is the primary purpose of a SOC 2 Type II report for a cloud service provider?
- Certifying the provider meets PCI DSS requirements
- Demonstrating security controls were effective over a period of time (typically 6-12 months) (Correct answer)
- Confirming the provider is FedRAMP authorized
- Validating GDPR compliance for European customers
Correct answer: Demonstrating security controls were effective over a period of time (typically 6-12 months)
A SOC 2 Type II report provides an audit opinion on whether a service organization's controls were operating effectively over a defined review period.
Question 4: Which principle in US export control regulations (EAR) restricts the transfer of certain networking technology to foreign nationals even within the United States?
- Deemed Export Rule (Correct answer)
- Anti-boycott Rule
- De Minimis Rule
- Country of Origin Rule
Correct answer: Deemed Export Rule
The Deemed Export Rule treats sharing controlled technology with a foreign national in the US as an export to their home country, requiring an export license.
Question 5: An organization is required to conduct annual risk assessments as part of its compliance program. Which NIST document provides guidance on conducting information security risk assessments?
- NIST SP 800-61
- NIST SP 800-30 (Correct answer)
- NIST SP 800-53
- NIST SP 800-171
Correct answer: NIST SP 800-30
NIST SP 800-30 provides guidance for conducting risk assessments of federal information systems and organizations.
Question 6: A company operating in the EU must transfer personal data to the US. After the invalidation of Privacy Shield, what mechanism is commonly used for lawful EU-US data transfers?
- GDPR Article 6 derogation
- Standard Contractual Clauses (SCCs) (Correct answer)
- Safe Harbor Agreement
- Binding Corporate Rules only
Correct answer: Standard Contractual Clauses (SCCs)
Standard Contractual Clauses (SCCs) are the primary mechanism for lawful EU-US data transfers after Privacy Shield was invalidated by the Schrems II ruling.
Question 7: Which regulation requires US public companies to maintain internal controls over financial reporting and have executives certify the accuracy of financial statements?
- GLBA
- SOX Section 302 and 404 (Correct answer)
- FISMA
- FCPA
Correct answer: SOX Section 302 and 404
SOX Sections 302 and 404 require executives to certify financial statements and mandate management assessment of internal controls over financial reporting.
A network administrator is implementing controls for a DoD contractor.
Which compliance framework specifically addresses cybersecurity maturity levels for defense contractors?