NEW
Font size
WorksheetsCompTIA Security+ (SYO-701) Obj 5
Total questions: 24
Worksheet time: 12mins
In the context of privacy compliance, which of the following describes the role of a data controller?
The entity responsible for determining why data is processed.
The organization that handles data retention and storage.
The external auditor responsible for privacy compliance checks.
The individual whose data is being processed.
A cloud service provider recently underwent an audit to confirm their compliance with international data security standards. The final report provided by the auditors served as an attestation of the provider's security measures. What does this attestation signify to the cloud service provider's clients?
It certifies that the provider's services are the most cost-effective in the market.
It acknowledges the provider's marketing strategies are effective.
It guarantees that the security controls are impenetrable and all data is securely held.
It assures that the provider's security controls comply with established standards.
What is the primary purpose of internal compliance reporting?
To prove to third party auditors that a company is complying with its internal processes
To report compliance status to the public
To provide compliance updates to the organization's management
To request additional information from agencies that are in charge of compliance
Horizon Security, a cybersecurity training company, experienced a data breach due to a vendor's negligence. This breach led to a significant loss of sensitive customer information. Which type of consequence is Horizon MOST likely to face immediately?
Loss of license
Fines
Reputational damage
Sanctions
A financial services company is required to submit regular documentation demonstrating adherence to regulatory security standards. This documentation includes audit results, risk assessments, and evidence of data protection measures. What is this process called?
Configuration Management
Risk Management
Compliance Reporting
Incident Response
In the context of compliance monitoring, which of the following does "due diligence/care" refer to?
Automated compliance checks.
Taking steps to meet legal and other requirements.
Conducting internal audits on a regular basis.
Reviewing third-party vendor agreements.
Which of the following terms refer to situations in which specific laws and regulations set by a country's government dictate how the personal data of its citizens should be collected, stored, and processed?
General Data Protection Regulation (GDPR)
National legal implications
Data encryption
Consent management
Which of the following is a monetary penalty imposed as a result of non-compliance with regulations or violations of certain rules or agreements?
Deductible
Fine
Fee
Sanction
