Microsoft Windows 98 Regulatory Frameworks & Compliance 4 โ Questions and Answers
Question 1: The Children's Online Privacy Protection Act (COPPA), enacted in 1998, required Windows 98 software connecting to the internet to consider which compliance obligation when targeting children under 13?
- Obtaining verifiable parental consent before collecting children's personal information (Correct answer)
- Installing parental-control hardware dongles on all school PCs
- Blocking all internet access by default until a parent activated it
- Encrypting all data using Windows 98's built-in CryptoAPI
Correct answer: Obtaining verifiable parental consent before collecting children's personal information
COPPA required websites and online services (including those accessed via Windows 98) to obtain parental consent before collecting personal data from children under 13.
Question 2: In 1998-era U.S. export law, Windows 98 versions shipped outside the United States initially used shorter encryption key lengths (40-bit) instead of the domestic 128-bit primarily because of:
- International customer preference for faster performance
- U.S. Export Administration Regulations restricting strong cryptography exports (Correct answer)
- European Union data protection requirements for weaker encryption
- Microsoft's cost-reduction strategy for international markets
Correct answer: U.S. Export Administration Regulations restricting strong cryptography exports
U.S. EAR classified 128-bit encryption as a controlled export, so international Windows 98 versions were shipped with weaker 40-bit encryption to comply.
Question 3: The Electronic Communications Privacy Act (ECPA) of 1986, still in force during the Windows 98 era, prohibited employers from doing what with employee Windows 98 workstations?
- Installing unlicensed software on company machines
- Intercepting employee electronic communications without authorization or consent (Correct answer)
- Using Windows 98 network shares to store company data
- Forcing employees to use Internet Explorer as their default browser
Correct answer: Intercepting employee electronic communications without authorization or consent
The ECPA restricted interception of electronic communications, meaning employers needed authorization or a valid exception to monitor employee emails and messages.
Question 4: Microsoft began requiring driver developers to submit drivers for Windows Hardware Quality Labs (WHQL) testing primarily to ensure:
- Drivers were priced competitively with open-source alternatives
- Hardware components met stability and compatibility standards before Windows certification (Correct answer)
- All drivers were written in C++ rather than Assembly language
- Drivers were approved by the FCC before distribution
Correct answer: Hardware components met stability and compatibility standards before Windows certification
WHQL testing verified that drivers met Microsoft's stability and compatibility standards, reducing system crashes and ensuring a baseline quality level.
Question 5: Under U.S. copyright law, a company IT administrator who made a single backup copy of Windows 98 installation media for disaster recovery purposes was:
- In clear violation of the DMCA regardless of licensing
- Permitted under the archival copy provision of 17 U.S.C. ยง 117 (Correct answer)
- Required to notify Microsoft within 30 days of making the copy
- Only allowed to do so if covered by a volume license agreement
Correct answer: Permitted under the archival copy provision of 17 U.S.C. ยง 117
17 U.S.C. ยง 117 explicitly allowed the lawful owner of software to make an archival (backup) copy for their own use.
Question 6: A healthcare organization deploying Windows 98 workstations in 1998 needed to begin considering which upcoming federal compliance requirement that would take full effect in 2003?
- Sarbanes-Oxley Act financial reporting controls
- HIPAA Security Rule technical safeguards for electronic protected health information (Correct answer)
- Gramm-Leach-Bliley Act financial data protections
- FERPA student records privacy requirements
Correct answer: HIPAA Security Rule technical safeguards for electronic protected health information
HIPAA was enacted in 1996 and the Security Rule (with its technical safeguards for ePHI) required compliance by April 2003, prompting early planning during the Windows 98 era.
Question 7: A software compliance audit revealed that a company had installed Windows 98 on 100 PCs but held only 75 licenses. Under BSA (Business Software Alliance) guidelines, the recommended remediation step was to:
- Immediately uninstall Windows 98 from all 100 machines and switch to Linux
- Purchase the 25 missing licenses and document the corrective action (Correct answer)
- File a formal self-disclosure report with the U.S. Copyright Office
- Downgrade the 25 unlicensed machines to Windows 95 which required no separate license
Correct answer: Purchase the 25 missing licenses and document the corrective action
BSA guidance recommended that organizations identify the shortfall, purchase the missing licenses, and document the remediation to demonstrate good-faith compliance.
The Children's Online Privacy Protection Act (COPPA), enacted in 1998, required Windows 98 software connecting to the internet to consider which compliance obligation when targeting children under 13?