Legal, Risk, and Compliance Flashcards
6 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 Legal, Risk, and Compliance flashcards as text
Which regulation requires organizations that handle payment card data to comply with a set of security standards?
Answer: PCI DSS
PCI DSS (Payment Card Industry Data Security Standard) is a set of security requirements for all organizations that store, process, or transmit cardholder data.
What is vendor lock-in risk in cloud computing and how does it affect compliance?
Answer: Dependency on a single cloud provider's proprietary technology making migration difficult, which can affect data portability rights under regulations like GDPR
Vendor lock-in can conflict with GDPR's right to data portability and make it difficult for organizations to switch providers or comply with data residency requirements.
What is the purpose of a cloud service level agreement (SLA) from a risk and compliance perspective?
Answer: To contractually define performance, availability, and security obligations, establishing accountability and remedies for non-compliance
An SLA establishes measurable service commitments and financial penalties, giving customers contractual recourse if the provider fails to meet security, availability, or compliance obligations.
In the context of cloud eDiscovery, what is the primary challenge compared to on-premises environments?
Answer: Data may be distributed across multiple jurisdictions and commingled with other tenants' data, complicating legal hold and collection
Cloud eDiscovery challenges include multi-jurisdictional data storage, commingling of data across tenants, and limited customer access to enforce legal holds on provider-managed infrastructure.
Which risk treatment option involves transferring the financial impact of a risk to a third party?
Answer: Risk transference
Risk transference shifts the financial consequences of a risk to a third party, most commonly through cyber liability insurance or contractual indemnification clauses.
What does the FedRAMP program require cloud service providers to do before selling to US federal agencies?
Answer: Achieve a standardized security authorization based on NIST 800-53 controls through third-party assessment
FedRAMP (Federal Risk and Authorization Management Program) provides a standardized approach to security assessment and authorization for cloud services sold to US federal agencies.