SY0-601 Governance, Risk & Compliance 2 — Questions and Answers
Question 1: Which compliance standard specifically governs the protection of payment card data and requires quarterly external vulnerability scans of cardholder data environments?
- HIPAA
- GLBA
- SOX
- PCI-DSS (Correct answer)
Correct answer: PCI-DSS
PCI-DSS (Payment Card Industry Data Security Standard) mandates security controls for cardholder data environments, including quarterly vulnerability scans.
Question 2: A hospital must implement safeguards to protect the privacy and security of patients' electronic medical records. Which U.S. regulation applies?
- FERPA
- COPPA
- GLBA
- HIPAA (Correct answer)
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) requires healthcare entities to protect the privacy and security of Protected Health Information (PHI).
Question 3: A server failure has an Annual Rate of Occurrence (ARO) of 2 and a Single Loss Expectancy (SLE) of $15,000. What is the Annual Loss Expectancy (ALE)?
- $7,500
- $15,000
- $30,000 (Correct answer)
- $45,000
Correct answer: $30,000
ALE = SLE × ARO = $15,000 × 2 = $30,000, representing the expected annual financial loss from this specific risk.
Question 4: A procurement team reviews a cloud vendor's SOC 2 Type II report before signing a contract. What type of assessment does this represent?
- Penetration test
- Vulnerability scan
- Third-party audit (Correct answer)
- Internal risk assessment
Correct answer: Third-party audit
A SOC 2 Type II report is produced by an independent third-party auditor, making its review part of third-party risk and audit evaluation.
Question 5: Which SOC report type evaluates the five trust service criteria (security, availability, processing integrity, confidentiality, privacy) over a defined period of time and is restricted to specified parties?
- SOC 1 Type I
- SOC 2 Type I
- SOC 2 Type II (Correct answer)
- SOC 3
Correct answer: SOC 2 Type II
SOC 2 Type II covers the same five trust criteria as Type I but assesses controls over a period of time (6–12 months) and is not publicly available.
Question 6: An organization's policy requires all email records to be stored for 7 years to satisfy legal and regulatory requirements. In which type of policy is this defined?
- Acceptable Use Policy
- Change Management Policy
- Incident Response Policy
- Data Retention Policy (Correct answer)
Correct answer: Data Retention Policy
A data retention policy specifies how long different categories of data must be stored and the procedures for their eventual secure disposal.
Question 7: Which U.S. state law grants residents the right to know what personal information is collected about them, the right to opt out of its sale, and the right to request its deletion?
- HIPAA
- FERPA
- SOX
- CCPA (Correct answer)
Correct answer: CCPA
The California Consumer Privacy Act (CCPA) provides California residents with rights over the collection, sale, and deletion of their personal data.
Which compliance standard specifically governs the protection of payment card data and requires quarterly external vulnerability scans of cardholder data environments?