← All CCCP Flashcard Decks

Technology & Data Compliance Flashcards

7 cards from real CCCP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Technology & Data Compliance flashcards as text
  1. A financial institution must comply with the Gramm-Leach-Bliley Act (GLBA). Which rule specifically requires the institution to implement an information security program?

    Answer: Safeguards Rule

    The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive information security program to protect customer financial data.

  2. Under SOC 2 auditing standards, which Trust Services Criteria category addresses whether the system is available for operation and use as committed?

    Answer: Availability

    The Availability criteria in SOC 2 evaluates whether systems and information are accessible for operation and use as promised in service level agreements.

  3. Which technique renders personal data permanently anonymous by removing all identifiers so that re-identification is no longer possible?

    Answer: Anonymization

    Anonymization irreversibly removes all identifying information so data can no longer be linked to an individual, distinguishing it from pseudonymization which is reversible.

  4. A company's AI algorithm is found to systematically deny loans to applicants from certain zip codes that correlate with racial demographics. This scenario raises concerns under which compliance area?

    Answer: Algorithmic bias and fair lending laws

    Algorithmic decision-making that produces disparate impact based on protected characteristics violates fair lending laws such as the Equal Credit Opportunity Act (ECOA) and Fair Housing Act.

  5. What is the standard maximum fine for a GDPR violation categorized as a Tier 2 infringement (most serious)?

    Answer: €20 million or 4% of global annual turnover

    GDPR Tier 2 violations, such as breaching core principles or data subject rights, carry fines up to €20 million or 4% of total worldwide annual turnover, whichever is higher.

  6. An organization stores credit card numbers and wants to reduce PCI DSS scope. Which method replaces card data with a randomly generated surrogate value that retains no exploitable value?

    Answer: Tokenization

    Tokenization substitutes sensitive card data with a non-sensitive token that has no exploitable value, effectively reducing the systems that fall within PCI DSS scope.

  7. Under the FTC Act Section 5, what type of data security practice can constitute an unfair or deceptive act?

    Answer: Failing to implement reasonable data security measures after promising consumers their data is secure

    The FTC has authority to take action against companies that fail to implement reasonable data security, particularly when their practices contradict privacy policy promises made to consumers.