โ† All ACT Flashcard Decks

Industry Regulations & Compliance Flashcards

7 cards from real ACT practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Industry Regulations & Compliance flashcards as text
  1. A trainer is deploying iPhones for a call center that records customer calls. Which US federal law requires that at least one party consent to call recording?

    Answer: ECPA (Electronic Communications Privacy Act)

    The ECPA sets the federal baseline for call recording consent, requiring at least one-party consent, though many states require all-party consent.

  2. What is 'data minimization' as it relates to deploying an iOS app for a US healthcare provider under HIPAA?

    Answer: Collecting and retaining only the minimum PHI necessary to accomplish the intended purpose

    HIPAA's minimum necessary standard (data minimization) requires covered entities to limit PHI collection and access to only what is needed for the specific use.

  3. Which Apple School Manager role has the authority to assign MDM servers and associate devices, directly impacting FERPA compliance controls?

    Answer: Administrator

    Only Administrators in Apple School Manager can assign MDM servers and manage device enrollment, controlling which compliance profiles are applied to student devices.

  4. Under the California Consumer Privacy Act (CCPA), what right does a California resident have regarding personal data collected by an iOS app?

    Answer: The right to know, delete, and opt-out of the sale of their personal data

    CCPA grants California residents rights to know what personal data is collected, request deletion, and opt out of its sale to third parties.

  5. When an Apple Certified Trainer helps a company implement a 'zero trust' security model, which Apple feature verifies managed device compliance before granting network access?

    Answer: MDM device compliance check integrated with identity provider (e.g., via certificate-based authentication)

    In a zero trust model, MDM-issued certificates or compliance signals are checked by an identity provider or network access control system before granting access.

  6. Which provision of the Family Educational Rights and Privacy Act (FERPA) is most relevant when an Apple Certified Trainer configures shared iPad mode in a classroom?

    Answer: The provision restricting disclosure of student education records to unauthorized parties

    Shared iPad mode must be configured so that each student's data is isolated, preventing one student from accessing another's education records in violation of FERPA's disclosure restrictions.

  7. A trainer must ensure a deployed Mac meets CIS (Center for Internet Security) Benchmark Level 1 recommendations. Which built-in macOS tool is best used to audit compliance with these settings?

    Answer: Terminal with the macOS Security Compliance Project (mSCP) scripts

    The macOS Security Compliance Project (mSCP) provides scripts that audit and remediate macOS settings against CIS Benchmarks and other compliance frameworks.