โ† All CCP Flashcard Decks

Compliance, Legal, & Ethical Issues Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Compliance, Legal, & Ethical Issues flashcards as text
  1. A CISO wants to ensure the organization's security controls align with NIST SP 800-53. What does this framework primarily provide?

    Answer: A catalog of security and privacy controls for federal information systems

    NIST SP 800-53 provides a comprehensive catalog of security and privacy controls designed to protect federal information systems and organizations.

  2. Under GDPR, which lawful basis for processing personal data is most commonly used by commercial organizations for marketing purposes?

    Answer: Legitimate interests

    Legitimate interests is frequently used by commercial entities for marketing when the processing is balanced against the data subject's rights and freedoms.

  3. Which act prohibits intercepting electronic communications in transit without proper authorization and governs wiretapping?

    Answer: Electronic Communications Privacy Act (ECPA)

    ECPA Title I (Wiretap Act) prohibits the intentional interception of wire, oral, or electronic communications in transit without authorization.

  4. A security analyst discovers that a colleague is exfiltrating customer data. The analyst reports this to management, but no action is taken. What is the MOST ethical next step?

    Answer: Escalate to legal, compliance, or a regulatory authority

    When internal escalation fails, ethical duty requires reporting to appropriate external authorities such as legal counsel, compliance officers, or regulators.

  5. ISO/IEC 27001 requires organizations to establish an ISMS. What does ISMS stand for?

    Answer: Information Security Management System

    An Information Security Management System (ISMS) is a systematic approach to managing sensitive company information, as defined in ISO/IEC 27001.

  6. Which type of evidence is considered most reliable in a cybercrime investigation?

    Answer: Original digital evidence with verified hash values

    Original digital evidence with cryptographic hash verification ensures integrity and is the most reliable form of evidence in court proceedings.

  7. The Gramm-Leach-Bliley Act (GLBA) Safeguards Rule requires financial institutions to protect customer information. Which action BEST satisfies this requirement?

    Answer: Implementing a comprehensive information security program with risk assessments

    The GLBA Safeguards Rule requires financial institutions to develop, implement, and maintain a comprehensive written information security program that includes risk assessment.