SCP-500 Regulatory Frameworks & Compliance 2 — Questions and Answers
Question 1: Under HIPAA, which SolarWinds feature helps demonstrate that audit logs have not been tampered with?
- Log Analyzer hash verification (Correct answer)
- NetPath route tracing
- IP Address Manager conflict detection
- Server & Application Monitor baselines
Correct answer: Log Analyzer hash verification
SolarWinds Log Analyzer uses hash-based integrity verification to prove logs are unaltered, satisfying HIPAA audit control requirements.
Question 2: Which compliance framework explicitly requires organizations to segment cardholder data environments from other networks?
- SOX
- HIPAA
- PCI DSS (Correct answer)
- FISMA
Correct answer: PCI DSS
PCI DSS Requirement 1 mandates network segmentation to isolate cardholder data environments, which SolarWinds NCM can help audit.
Question 3: A SolarWinds NCM compliance report shows a router config deviating from a baseline. Under NIST 800-53, which control family does this fall under?
- Access Control (AC)
- Configuration Management (CM) (Correct answer)
- Incident Response (IR)
- Audit and Accountability (AU)
Correct answer: Configuration Management (CM)
NIST 800-53 Configuration Management (CM) controls govern baseline configurations and deviation detection.
Question 4: Which SolarWinds product is MOST directly used to satisfy GDPR requirements around monitoring access to personal data stores?
- SolarWinds Database Performance Analyzer (Correct answer)
- SolarWinds Web Help Desk
- SolarWinds Patch Manager
- SolarWinds DameWare
Correct answer: SolarWinds Database Performance Analyzer
Database Performance Analyzer tracks query-level access to databases, enabling audit trails for GDPR Article 30 records of processing activities.
Question 5: FISMA requires federal agencies to categorize information systems by impact level. Which standard defines these impact levels?
- NIST SP 800-37
- FIPS 199 (Correct answer)
- ISO 27001 Annex A
- COBIT 5
Correct answer: FIPS 199
FIPS 199 defines the standards for security categorization of federal information and information systems as Low, Moderate, or High.
Question 6: When configuring SolarWinds Orion alerts for SOX compliance, which log retention period is typically required for audit trails?
- 90 days
- 1 year
- 7 years (Correct answer)
- 3 years
Correct answer: 7 years
SOX Section 802 requires records relevant to financial audits to be retained for 7 years.
Question 7: Which SolarWinds capability supports CIS Benchmark compliance verification across network devices?
- NCM policy reports with CIS templates (Correct answer)
- NPM bandwidth analysis
- IPAM subnet discovery
- SAM application templates
Correct answer: NCM policy reports with CIS templates
SolarWinds NCM includes policy report templates aligned with CIS Benchmarks to check device configurations against hardening guidelines.
Under HIPAA, which SolarWinds feature helps demonstrate that audit logs have not been tampered with?