Compliance and regulation (core 2)

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/100

encourage image

There's no tags or description

Looks like no tags are added yet.

Last updated 5:32 AM on 7/27/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

101 Terms

1
New cards

A retail company stores and processes customer credit card information. Which compliance standard must they follow?

PCI DSS

2
New cards
3
New cards

What does PCI DSS stand for?

Payment Card Industry Data Security Standard

4
New cards
5
New cards

What is the primary purpose of PCI DSS?

To protect cardholder data and secure credit card transactions.

6
New cards
7
New cards

A hospital stores patient medical records electronically. Which regulation applies?

HIPAA

8
New cards
9
New cards

What does HIPAA stand for?

Health Insurance Portability and Accountability Act

10
New cards
11
New cards

What is the primary purpose of HIPAA?

To protect patients' protected health information (PHI).

12
New cards
13
New cards

A company operating in the European Union collects personal data from EU citizens. Which regulation applies?

GDPR

14
New cards
15
New cards

What does GDPR stand for?

General Data Protection Regulation

16
New cards
17
New cards

What is the primary purpose of GDPR?

To protect the privacy and personal data of individuals in the European Union.

18
New cards
19
New cards

A publicly traded company must maintain accurate financial records for audits. Which law applies?

Sarbanes-Oxley Act (SOX)

20
New cards
21
New cards

What does SOX stand for?

Sarbanes-Oxley Act

22
New cards
23
New cards

What is the primary purpose of SOX?

To improve financial reporting accuracy and prevent corporate fraud.

24
New cards
25
New cards

What does PII stand for?

Personally Identifiable Information

26
New cards
27
New cards

Which type of information is considered PII?

Information that can identify an individual, such as name, address, driver's license number, passport number, or Social Security number.

28
New cards
29
New cards

What does PHI stand for?

Protected Health Information

30
New cards
31
New cards

Which type of information is considered PHI?

Medical records, diagnoses, treatment history, insurance information, and other healthcare-related personal data.

32
New cards
33
New cards

A customer's full name and driver's license number are stored in a database. What type of data is this?

Personally Identifiable Information (PII)

34
New cards
35
New cards

A patient's medical diagnosis and treatment history are stored electronically. What type of information is this?

Protected Health Information (PHI)

36
New cards
37
New cards

Which compliance standard applies specifically to credit card processing?

PCI DSS

38
New cards
39
New cards

Which regulation protects healthcare information in the United States?

HIPAA

40
New cards
41
New cards

Which regulation protects personal data of European Union citizens?

GDPR

42
New cards
43
New cards

Which law primarily focuses on financial reporting and corporate accountability?

Sarbanes-Oxley Act (SOX)

44
New cards
45
New cards

A company is required to keep employee payroll records for seven years. What security concept does this represent?

Data retention

46
New cards
47
New cards

What is data retention?

The practice of storing information for a required period before securely disposing of it.

48
New cards
49
New cards

A company securely destroys old customer records after the required retention period ends. What security concept is being followed?

Data disposal

50
New cards
51
New cards

Why is secure data disposal important?

To prevent unauthorized access to sensitive information after it is no longer needed.

52
New cards
53
New cards

A company labels documents as Public, Confidential, Secret, and Top Secret. What security process is this?

Data classification

54
New cards
55
New cards

Why is data classification important?

It determines how sensitive information should be handled, stored, and protected.

56
New cards
57
New cards

What is the principle of least privilege?

Users should only receive the minimum permissions necessary to perform their job.

58
New cards
59
New cards

Why should organizations implement least privilege?

To reduce the risk of unauthorized access and limit the impact of compromised accounts.

60
New cards
61
New cards

A company requires employees to sign documents stating they will not disclose confidential company information. What document is this?

Non-Disclosure Agreement (NDA)

62
New cards
63
New cards

What is the purpose of a Non-Disclosure Agreement (NDA)?

To legally prevent individuals from sharing confidential information.

64
New cards
65
New cards

What is an Acceptable Use Policy (AUP)?

A policy that defines how employees are permitted to use company systems and devices.

66
New cards
67
New cards

Why do organizations require employees to acknowledge the Acceptable Use Policy?

To ensure users understand acceptable behavior and security responsibilities.

68
New cards
69
New cards

What is the purpose of a password policy?

To enforce secure password creation and management requirements.

70
New cards
71
New cards

What is the purpose of an account lockout policy?

To reduce the risk of brute-force password attacks by locking accounts after repeated failed login attempts.

72
New cards
73
New cards

A company requires employees to complete annual cybersecurity awareness training. What is the primary goal?

To reduce the risk of social engineering and human error.

74
New cards
75
New cards

A company performs regular audits to verify compliance with security policies and regulations. Why are audits important?

To identify security weaknesses and verify compliance requirements are being met.

76
New cards
77
New cards

A company grants employees access only to files required for their job responsibilities. Which security principle is being followed?

Least privilege

78
New cards
79
New cards

A healthcare employee accidentally emails patient records to the wrong person. Which regulation has most likely been violated?

HIPAA

80
New cards
81
New cards

A retail company stores customers' credit card numbers in plain text. Which compliance standard has most likely been violated?

PCI DSS

82
New cards
83
New cards

A European customer requests that a company delete all personal information held about them. Which regulation gives them this right?

GDPR

84
New cards
85
New cards

A company's financial statements are intentionally altered before an audit. Which law has most likely been violated?

Sarbanes-Oxley Act (SOX)

86
New cards
87
New cards

Which compliance framework is MOST likely to appear on the CompTIA A+ Core 2 exam when discussing payment card security?

PCI DSS

88
New cards
89
New cards

Which regulation is MOST likely to appear when discussing patient privacy?

HIPAA

90
New cards
91
New cards

Which regulation is MOST likely to appear when discussing European privacy laws?

GDPR

92
New cards
93
New cards

Which law is MOST likely to appear when discussing financial reporting requirements?

SOX

94
New cards
95
New cards

If an exam question mentions credit card information, which compliance standard should immediately come to mind?

PCI DSS

96
New cards
97
New cards

If an exam question mentions hospitals or medical records, which regulation should immediately come to mind?

HIPAA

98
New cards
99
New cards

If an exam question mentions citizens of the European Union, which regulation should immediately come to mind?

GDPR

100
New cards