SP Security and Compliance 1 — Questions and Answers
Question 1: Which security framework is commonly required for service providers handling credit card data?
- HIPAA
- PCI DSS (Correct answer)
- SOC 2
- FISMA
Correct answer: PCI DSS
Payment Card Industry Data Security Standard (PCI DSS) mandates security controls for any organization that stores, processes, or transmits cardholder data.
Question 2: What is a 'penetration test' and why do service providers conduct them?
- A performance benchmark for network throughput
- An authorized simulated cyberattack to identify security vulnerabilities before attackers do (Correct answer)
- A test of customer VPN connectivity
- A firewall rule validation exercise
Correct answer: An authorized simulated cyberattack to identify security vulnerabilities before attackers do
Penetration testing is an authorized, simulated attack on systems to discover exploitable vulnerabilities before malicious actors can find and use them.
Question 3: What does 'least privilege' mean in a service provider security context?
- Only executives have full system access
- Users and systems are granted only the minimum permissions required to perform their job function (Correct answer)
- New employees start with zero access until trained
- Service accounts share a single privileged login
Correct answer: Users and systems are granted only the minimum permissions required to perform their job function
The principle of least privilege limits access rights for users, accounts, and processes to only what is strictly necessary, minimizing potential damage from breaches.
Question 4: Which standard provides a framework for information security management systems (ISMS)?
- ISO 9001
- ISO 27001 (Correct answer)
- NIST SP 800-53
- CIS Controls
Correct answer: ISO 27001
ISO 27001 is the international standard for establishing, implementing, maintaining, and continually improving an Information Security Management System (ISMS).
Question 5: What is 'data encryption at rest' in a managed service context?
- Encrypting data only while it is being transmitted
- Encrypting stored data so it cannot be read if physical media is compromised (Correct answer)
- Archiving data in compressed format
- Securing backup tapes in a vault
Correct answer: Encrypting stored data so it cannot be read if physical media is compromised
Encryption at rest ensures that data stored on disks, databases, and backups is unreadable without the correct encryption keys, even if physical storage is stolen.
Question 6: What is a SOC 2 report and why is it important for service providers?
- A security audit report covering system availability, confidentiality, and processing integrity (Correct answer)
- A report on network outage root causes
- An annual financial statement for investors
- A software license compliance report
Correct answer: A security audit report covering system availability, confidentiality, and processing integrity
A SOC 2 report provides an independent auditor's assessment of a service provider's controls related to security, availability, confidentiality, processing integrity, and privacy.
Which security framework is commonly required for service providers handling credit card data?