SCP-500 Regulatory Frameworks & Compliance 4 — Questions and Answers
Question 1: Which SolarWinds NCM feature enables automated remediation when a device configuration drifts from its compliance baseline?
- Config Change Templates with automatic rollback (Correct answer)
- NetPath hop analysis
- IPAM conflict detection
- SAM alert suppression
Correct answer: Config Change Templates with automatic rollback
NCM Config Change Templates can automatically push corrective configurations when drift is detected, enforcing continuous compliance.
Question 2: A healthcare organization must comply with HIPAA's Technical Safeguard for automatic logoff. How can SolarWinds SAM help verify this control?
- By monitoring session timeout settings on application servers (Correct answer)
- By scanning network bandwidth utilization
- By tracking IP address conflicts
- By generating network topology diagrams
Correct answer: By monitoring session timeout settings on application servers
SAM can monitor application-level metrics and alert when session timeout configurations are not set correctly on healthcare application servers.
Question 3: Under FedRAMP, continuous monitoring requires vulnerability scanning at defined frequencies. Which SolarWinds integration supports this requirement?
- Integration with Tenable or Qualys via SolarWinds Orion SDK (Correct answer)
- SolarWinds WPM synthetic transactions
- SolarWinds NCM config archiving
- SolarWinds NPM bandwidth graphing
Correct answer: Integration with Tenable or Qualys via SolarWinds Orion SDK
SolarWinds Orion integrates with vulnerability scanners like Tenable/Qualys to provide unified visibility needed for FedRAMP continuous monitoring.
Question 4: The EU NIS2 Directive requires operators of essential services to report significant incidents within how many hours?
- 72 hours
- 24 hours (Correct answer)
- 48 hours
- 96 hours
Correct answer: 24 hours
NIS2 requires an early warning to authorities within 24 hours of becoming aware of a significant incident, with a full report within 72 hours.
Question 5: Which SolarWinds SIEM feature BEST supports PCI DSS Requirement 11.4 (intrusion detection/prevention techniques)?
- Security Event Manager real-time correlation rules (Correct answer)
- NCM baseline deviation reports
- NPM packet capture
- IPAM rogue DHCP detection
Correct answer: Security Event Manager real-time correlation rules
SolarWinds Security Event Manager applies real-time correlation rules to detect intrusion patterns, directly addressing PCI DSS Requirement 11.4.
Question 6: When generating a SOX evidence package, which SolarWinds NCM report type BEST demonstrates segregation of duties in change management?
- Change Management Audit Trail showing who approved and who implemented each change (Correct answer)
- Bandwidth utilization trend report
- Device inventory report
- IP address allocation report
Correct answer: Change Management Audit Trail showing who approved and who implemented each change
NCM's change audit trail records who requested, approved, and executed each configuration change, providing SOX evidence for segregation of duties.
Question 7: Which compliance standard requires organizations to perform risk assessments before and after significant IT changes, which SolarWinds NCM can help document?
- ISO 27001 clause 6.1
- PCI DSS Requirement 6
- HIPAA Security Rule §164.308
- All of the above (Correct answer)
Correct answer: All of the above
ISO 27001, PCI DSS, and HIPAA all require risk assessment processes around significant changes, and NCM's change documentation supports all three frameworks.
Which SolarWinds NCM feature enables automated remediation when a device configuration drifts from its compliance baseline?