1/100
Looks like no tags are added yet.
Name | Mastery | Learn | Test | Matching | Spaced | Call with Kai | Chat |
|---|
No analytics yet
Send a link to your students to track their progress
A retail company stores and processes customer credit card information. Which compliance standard must they follow?
PCI DSS
What does PCI DSS stand for?
Payment Card Industry Data Security Standard
What is the primary purpose of PCI DSS?
To protect cardholder data and secure credit card transactions.
A hospital stores patient medical records electronically. Which regulation applies?
HIPAA
What does HIPAA stand for?
Health Insurance Portability and Accountability Act
What is the primary purpose of HIPAA?
To protect patients' protected health information (PHI).
A company operating in the European Union collects personal data from EU citizens. Which regulation applies?
GDPR
What does GDPR stand for?
General Data Protection Regulation
What is the primary purpose of GDPR?
To protect the privacy and personal data of individuals in the European Union.
A publicly traded company must maintain accurate financial records for audits. Which law applies?
Sarbanes-Oxley Act (SOX)
What does SOX stand for?
Sarbanes-Oxley Act
What is the primary purpose of SOX?
To improve financial reporting accuracy and prevent corporate fraud.
What does PII stand for?
Personally Identifiable Information
Which type of information is considered PII?
Information that can identify an individual, such as name, address, driver's license number, passport number, or Social Security number.
What does PHI stand for?
Protected Health Information
Which type of information is considered PHI?
Medical records, diagnoses, treatment history, insurance information, and other healthcare-related personal data.
A customer's full name and driver's license number are stored in a database. What type of data is this?
Personally Identifiable Information (PII)
A patient's medical diagnosis and treatment history are stored electronically. What type of information is this?
Protected Health Information (PHI)
Which compliance standard applies specifically to credit card processing?
PCI DSS
Which regulation protects healthcare information in the United States?
HIPAA
Which regulation protects personal data of European Union citizens?
GDPR
Which law primarily focuses on financial reporting and corporate accountability?
Sarbanes-Oxley Act (SOX)
A company is required to keep employee payroll records for seven years. What security concept does this represent?
Data retention
What is data retention?
The practice of storing information for a required period before securely disposing of it.
A company securely destroys old customer records after the required retention period ends. What security concept is being followed?
Data disposal
Why is secure data disposal important?
To prevent unauthorized access to sensitive information after it is no longer needed.
A company labels documents as Public, Confidential, Secret, and Top Secret. What security process is this?
Data classification
Why is data classification important?
It determines how sensitive information should be handled, stored, and protected.
What is the principle of least privilege?
Users should only receive the minimum permissions necessary to perform their job.
Why should organizations implement least privilege?
To reduce the risk of unauthorized access and limit the impact of compromised accounts.
A company requires employees to sign documents stating they will not disclose confidential company information. What document is this?
Non-Disclosure Agreement (NDA)
What is the purpose of a Non-Disclosure Agreement (NDA)?
To legally prevent individuals from sharing confidential information.
What is an Acceptable Use Policy (AUP)?
A policy that defines how employees are permitted to use company systems and devices.
Why do organizations require employees to acknowledge the Acceptable Use Policy?
To ensure users understand acceptable behavior and security responsibilities.
What is the purpose of a password policy?
To enforce secure password creation and management requirements.
What is the purpose of an account lockout policy?
To reduce the risk of brute-force password attacks by locking accounts after repeated failed login attempts.
A company requires employees to complete annual cybersecurity awareness training. What is the primary goal?
To reduce the risk of social engineering and human error.
A company performs regular audits to verify compliance with security policies and regulations. Why are audits important?
To identify security weaknesses and verify compliance requirements are being met.
A company grants employees access only to files required for their job responsibilities. Which security principle is being followed?
Least privilege
A healthcare employee accidentally emails patient records to the wrong person. Which regulation has most likely been violated?
HIPAA
A retail company stores customers' credit card numbers in plain text. Which compliance standard has most likely been violated?
PCI DSS
A European customer requests that a company delete all personal information held about them. Which regulation gives them this right?
GDPR
A company's financial statements are intentionally altered before an audit. Which law has most likely been violated?
Sarbanes-Oxley Act (SOX)
Which compliance framework is MOST likely to appear on the CompTIA A+ Core 2 exam when discussing payment card security?
PCI DSS
Which regulation is MOST likely to appear when discussing patient privacy?
HIPAA
Which regulation is MOST likely to appear when discussing European privacy laws?
GDPR
Which law is MOST likely to appear when discussing financial reporting requirements?
SOX
If an exam question mentions credit card information, which compliance standard should immediately come to mind?
PCI DSS
If an exam question mentions hospitals or medical records, which regulation should immediately come to mind?
HIPAA
If an exam question mentions citizens of the European Union, which regulation should immediately come to mind?
GDPR