GRC Regulatory and Legal Compliance 2 — Questions and Answers
Question 1: Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on the effectiveness of internal controls over financial reporting?
- Section 302
- Section 401
- Section 404 (Correct answer)
- Section 802
Correct answer: Section 404
SOX Section 404 requires management to assess internal controls over financial reporting and external auditors to attest to that assessment.
Question 2: A company operating in California collects personal data from residents. Under the California Consumer Privacy Act (CCPA), what right allows consumers to prevent the sale of their personal information?
- Right to erasure
- Right to opt-out (Correct answer)
- Right to portability
- Right to correction
Correct answer: Right to opt-out
The CCPA grants consumers the right to opt-out of the sale of their personal information to third parties.
Question 3: Which U.S. federal law establishes privacy protections for individually identifiable health information held by covered entities and business associates?
- FERPA
- GLBA
- HIPAA (Correct answer)
- COPPA
Correct answer: HIPAA
HIPAA (Health Insurance Portability and Accountability Act) establishes national standards to protect individually identifiable health information.
Question 4: An organization subject to PCI DSS discovers a third-party vendor processed cardholder data without a signed agreement. Which PCI DSS requirement has been violated?
- Requirement 3 – Protect stored cardholder data
- Requirement 6 – Develop secure systems
- Requirement 12 – Maintain an information security policy (Correct answer)
- Requirement 7 – Restrict access to cardholder data
Correct answer: Requirement 12 – Maintain an information security policy
PCI DSS Requirement 12 mandates maintaining agreements with service providers that include acknowledgment of their responsibility for cardholder data security.
Question 5: The EU General Data Protection Regulation (GDPR) requires organizations to appoint a Data Protection Officer (DPO) in which scenario?
- When processing data of more than 500 individuals
- When the core activities involve large-scale processing of special category data (Correct answer)
- When annual revenue exceeds €10 million
- When operating in more than two EU member states
Correct answer: When the core activities involve large-scale processing of special category data
GDPR mandates a DPO when core activities consist of large-scale processing of special category data or large-scale systematic monitoring of data subjects.
Question 6: Which regulatory framework governs export controls on dual-use items, software, and technology from the United States?
- Foreign Corrupt Practices Act (FCPA)
- Export Administration Regulations (EAR) (Correct answer)
- International Traffic in Arms Regulations (ITAR)
- Office of Foreign Assets Control (OFAC) sanctions
Correct answer: Export Administration Regulations (EAR)
The Export Administration Regulations (EAR) govern the export and re-export of most commercial and dual-use items, software, and technology.
Question 7: A financial institution must implement a Customer Identification Program (CIP) as part of its Bank Secrecy Act obligations. What is the primary purpose of the CIP?
- To detect and report suspicious transactions
- To verify the identity of customers opening accounts (Correct answer)
- To maintain records of large cash transactions
- To screen customers against OFAC sanctions lists
Correct answer: To verify the identity of customers opening accounts
The CIP requires financial institutions to verify the identity of individuals opening accounts to prevent money laundering and terrorist financing.
Under the Sarbanes-Oxley Act (SOX), which section specifically requires management to assess and report on the effectiveness of internal controls over financial reporting?