Microsoft Networking Essentials Exam Regulatory Frameworks & Compliance 5 — Questions and Answers
Question 1: A retailer experiences a breach of 60,000 payment card records. Under PCI DSS, which action is immediately required?
- Notify all cardholders within 24 hours
- Contain the breach, notify acquiring bank and card brands, and preserve forensic evidence (Correct answer)
- Shut down all payment systems permanently
- File a report with the FTC within 48 hours
Correct answer: Contain the breach, notify acquiring bank and card brands, and preserve forensic evidence
PCI DSS incident response requires immediately containing the breach, notifying the acquiring bank and card brands, and preserving evidence for forensic investigation.
Question 2: Which of the following is an example of a technical control required by the NIST Cybersecurity Framework's 'Protect' function?
- Conducting annual employee security awareness training
- Implementing multi-factor authentication for network access (Correct answer)
- Developing an incident response plan
- Performing a business impact analysis
Correct answer: Implementing multi-factor authentication for network access
Implementing multi-factor authentication is a technical protective control aligned with the NIST CSF 'Protect' function's access control category.
Question 3: A healthcare organization wants to share de-identified patient data for research. Under HIPAA, what is the 'Safe Harbor' de-identification method?
- Encrypting all 18 categories of PHI identifiers
- Removing all 18 specific types of identifiers defined by HHS from the dataset (Correct answer)
- Obtaining explicit written consent from each patient
- Assigning pseudonyms to replace patient names
Correct answer: Removing all 18 specific types of identifiers defined by HHS from the dataset
HIPAA Safe Harbor de-identification requires removing all 18 specific identifier types defined by HHS, leaving no reasonable basis to identify an individual.
Question 4: Which federal law establishes security and privacy requirements for federal government information systems and requires each agency to implement an information security program?
- FISMA (Federal Information Security Modernization Act) (Correct answer)
- FERPA
- CFAA (Computer Fraud and Abuse Act)
- E-Government Act
Correct answer: FISMA (Federal Information Security Modernization Act)
FISMA requires federal agencies to develop, document, and implement an agency-wide information security program to protect federal information and information systems.
Question 5: An organization's network policy requires all data classified as 'Confidential' to be encrypted at rest. This policy aligns with which type of compliance control?
- Detective control
- Corrective control
- Preventive control (Correct answer)
- Compensating control
Correct answer: Preventive control
Encryption at rest is a preventive control because it proactively prevents unauthorized disclosure of data if storage media is compromised.
Question 6: Under which circumstance does the Electronic Communications Privacy Act (ECPA) permit an employer to monitor employee email without consent?
- Only if the employee is suspected of criminal activity
- When the employer owns the email system and has established a monitoring policy (Correct answer)
- Only with a court order
- Never — employee email is always private under ECPA
Correct answer: When the employer owns the email system and has established a monitoring policy
ECPA's business exception allows employers to monitor communications on company-owned systems when a legitimate business policy has been established and employees are notified.
Question 7: A network engineer is asked to verify that a third-party vendor's practices meet the organization's security standards before signing a contract. This process is best described as:
- Penetration testing
- Third-party vendor risk assessment (supply chain risk management) (Correct answer)
- Security information and event management (SIEM)
- Gap analysis against ISO 27001
Correct answer: Third-party vendor risk assessment (supply chain risk management)
Evaluating a vendor's security practices before engagement is called third-party vendor risk assessment, a key component of supply chain risk management under frameworks like NIST CSF.
A retailer experiences a breach of 60,000 payment card records.
Under PCI DSS, which action is immediately required?