Compliance and Auditing IT Compliance and Security 1 — Questions and Answers
Question 1: Which PCI DSS requirement mandates the use of a firewall to protect cardholder data?
- Requirement 1 (Correct answer)
- Requirement 3
- Requirement 6
- Requirement 10
Correct answer: Requirement 1
PCI DSS Requirement 1 mandates installing and maintaining network security controls (firewalls) to protect the cardholder data environment from unauthorized access.
Question 2: Under HIPAA Security Rule, what is a 'covered entity' required to conduct periodically?
- External penetration tests
- Risk analysis of ePHI (Correct answer)
- Employee background checks
- Annual financial audits
Correct answer: Risk analysis of ePHI
The HIPAA Security Rule requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI.
Question 3: What is 'data at rest' encryption in the context of IT security compliance?
- Encrypting data while it is being transmitted over a network
- Encrypting data that is stored on devices, databases, or backup media (Correct answer)
- Encrypting data before it is entered into a system
- Encrypting temporary data in system memory
Correct answer: Encrypting data that is stored on devices, databases, or backup media
Data at rest encryption protects data stored on physical or virtual storage media, such as databases, hard drives, and backup tapes, from unauthorized access if physical security is breached.
Question 4: Which security concept involves verifying a user's identity through multiple verification factors?
- Single sign-on (SSO)
- Multi-factor authentication (MFA) (Correct answer)
- Role-based access control
- Privileged access management
Correct answer: Multi-factor authentication (MFA)
Multi-factor authentication (MFA) requires users to verify their identity using two or more factors: something they know (password), something they have (token), or something they are (biometric).
Question 5: What is a 'penetration test' in the context of IT security compliance?
- Testing employee password strength
- An authorized simulated attack to identify exploitable vulnerabilities (Correct answer)
- A review of firewall configuration rules
- An assessment of physical security measures
Correct answer: An authorized simulated attack to identify exploitable vulnerabilities
A penetration test is an authorized, simulated cyberattack performed by security professionals to identify exploitable vulnerabilities in systems, networks, or applications before malicious actors do.
Question 6: What does 'data classification' mean in an IT compliance program?
- Sorting files alphabetically on a server
- Categorizing data based on its sensitivity level to apply appropriate security controls (Correct answer)
- Classifying IT assets by their age
- Grouping employees by their data access needs
Correct answer: Categorizing data based on its sensitivity level to apply appropriate security controls
Data classification categorizes organizational data based on its sensitivity level (e.g., public, internal, confidential, restricted) to ensure appropriate security controls are applied proportionate to the data's value and risk.
Which PCI DSS requirement mandates the use of a firewall to protect cardholder data?