
EC-CouncilCloud Security Essentials
Domain 8Objective 1
Regulatory and Industry Compliance CSE Practice Questions (Page 9)
Part of the Cloud Compliance and Governance domain, which makes up ~13% of our current practice bank.
44questions here
9free pages
7concepts
Questions 41–44
- 41
A company that processes both healthcare data and credit card payments is moving to the cloud. The compliance team needs to ensure that the cloud environment meets the requirements of both HIPAA and PCI DSS. What is the most important consideration?
Select an answer first - 42
A software company that develops a SaaS product for schools must comply with COPPA and FERPA. The company is migrating its application to a cloud provider. The compliance team has mapped the application's data flows and identified that student records are stored in a database that is also used for non-student data. What is the most significant compliance gap?
Select an answer first - 43
A financial services company is evaluating a cloud provider for a new application that will process credit card transactions. The compliance team requires that the provider's environment supports the company's obligation to maintain a network that is protected by a firewall and to restrict access to cardholder data. Which industry-specific compliance standard is most directly relevant to these requirements?
Select an answer first - 44
A cloud-based software company provides a platform for managing clinical trials. The company must comply with GCP (Good Clinical Practice) and HIPAA. The company's compliance team wants to automate the monitoring of access to clinical trial data. The team has implemented logging, but the logs are stored in the same cloud account as the clinical data. Which of the following is the most important additional control to implement?
Select an answer first
Finished these 4 questions?
Review the revealed explanations, or continue through the curriculum.
No more pagesBack to CSE
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.