CSIA 105 EXAM COMPLETE STUDY
GUIDE NEWEST 2026 | CSIA TEST
BANK | PRACTICE QUESTIONS AND
DETAILED RATIONALES 2026
EDITION
Question
Which act requires banks and financial institutions to alert customers of their policies and
practices in disclosing customer information?
A. HIPAA
B. Gramm-Leach-Bailey Act
C. Sarbanes-Oxley Act
D. FERPA
Expert Rationale: The Gramm-Leach-Bailey Act (GLBA) requires financial institutions to
explain their information-sharing practices to their customers and to safeguard sensitive
data. HIPAA protects health information; Sarbanes-Oxley governs corporate financial
practices; FERPA protects student records.
Question
Healthcare enterprises are required to guard protected health information and implement
policies and procedures whether in paper or electronic format under which law?
A. Gramm-Leach-Bailey Act
B. HIPAA
C. PCI DSS
D. The Children's Online Privacy Act
Expert Rationale: HIPAA (Health Insurance Portability and Accountability Act) mandates
the protection of protected health information (PHI) in all formats—paper, electronic, and
verbal. GLBA covers financial institutions; PCI DSS covers cardholder data; COPPA covers
children's online information.
,Question
Which act was created to strengthen domestic security and broaden the powers of law-
enforcement agencies with regards to identifying and stopping terrorists?
A. Computer Security Act
B. Sarbanes-Oxley Act
C. US Patriot Act
D. FERPA
Expert Rationale: The US Patriot Act was enacted to strengthen domestic security and
expand law enforcement's ability to detect and prevent terrorism. The Computer Security
Act addresses federal computer security; Sarbanes-Oxley addresses corporate
governance; FERPA addresses student privacy.
Question
The Americans with Disabilities Act (ADA) requires accessibility of which of the following?
A. Physical buildings only
B. Electronic media, including websites, software applications, and video
C. Financial records only
D. Healthcare records only
Expert Rationale: The ADA standards require accessibility of electronic media, including
websites, software applications, operating systems, and video, to ensure equal access for
individuals with disabilities. While physical accessibility is also part of ADA, the question
specifically addresses electronic media.
Question
Which act was created to improve the security and privacy of sensitive information and to
create acceptable security practices for federal computer systems?
A. Computer Security Act
B. HIPAA
C. Sarbanes-Oxley Act
D. Gramm-Leach-Bailey Act
Expert Rationale: The Computer Security Act was created to improve the security and
privacy of sensitive information in federal computer systems and to establish acceptable
,security practices. HIPAA covers health information; Sarbanes-Oxley covers corporate
governance; GLBA covers financial institutions.
Question
FERPA was created to protect the privacy of which type of records?
A. Medical records
B. Student records
C. Financial records
D. Criminal records
Expert Rationale: FERPA (Family Educational Rights and Privacy Act) protects the privacy
of student education records. It applies to all schools that receive funds from the U.S.
Department of Education. HIPAA protects medical records; GLBA protects financial
records.
Question
Which act was created to help protect children under the age of 13 from exploitation by
governing the online collection of their personal information?
A. FERPA
B. The Children's Online Privacy Act (COPPA)
C. HIPAA
D. Gramm-Leach-Bailey Act
Expert Rationale: The Children's Online Privacy Act (COPPA) governs the online collection
of personal information from children under 13. It requires parental consent and imposes
rules on website operators. FERPA protects student records; HIPAA protects health
information; GLBA protects financial information.
Question
The Sarbanes-Oxley Act was created for which primary purpose?
A. To protect student records
B. To govern corporate governance and financial practice
C. To protect health information
D. To protect children's online privacy
, Expert Rationale: The Sarbanes-Oxley Act (SOX) was created to govern corporate
governance and financial practice, ensuring accuracy and accountability in financial
reporting. It was enacted in response to corporate scandals. HIPAA covers health; FERPA
covers student; COPPA covers children.
Question
PCI DSS defines minimum requirements for which group to protect cardholder data?
A. Healthcare providers
B. Merchants and service providers
C. Educational institutions
D. Government agencies
Expert Rationale: PCI DSS (Payment Card Industry Data Security Standard) defines
minimum security requirements for merchants and service providers that handle
cardholder data. It applies to any entity that stores, processes, or transmits credit card
information. HIPAA covers healthcare; FERPA covers education.
Question
A group of threat actors has a strong aversion to certain political ideologies. They launch a
cyberattack against an organization to which its perceived adversarial counterpart belongs.
This type of threat actor is most appropriately classified as:
A. Nation-state actor
B. Hacktivist
C. Cybercriminal
D. Insider threat
Expert Rationale: Hacktivists are threat actors who use cyberattacks to promote political
ideologies, social change, or protest against perceived adversaries. They are motivated by
political or social causes rather than financial gain. Nation-state actors are government-
sponsored; cybercriminals are financially motivated; insider threats are from within the
organization.
Question
What type of entity would a threat actor most likely attack to steal design documents for a
GUIDE NEWEST 2026 | CSIA TEST
BANK | PRACTICE QUESTIONS AND
DETAILED RATIONALES 2026
EDITION
Question
Which act requires banks and financial institutions to alert customers of their policies and
practices in disclosing customer information?
A. HIPAA
B. Gramm-Leach-Bailey Act
C. Sarbanes-Oxley Act
D. FERPA
Expert Rationale: The Gramm-Leach-Bailey Act (GLBA) requires financial institutions to
explain their information-sharing practices to their customers and to safeguard sensitive
data. HIPAA protects health information; Sarbanes-Oxley governs corporate financial
practices; FERPA protects student records.
Question
Healthcare enterprises are required to guard protected health information and implement
policies and procedures whether in paper or electronic format under which law?
A. Gramm-Leach-Bailey Act
B. HIPAA
C. PCI DSS
D. The Children's Online Privacy Act
Expert Rationale: HIPAA (Health Insurance Portability and Accountability Act) mandates
the protection of protected health information (PHI) in all formats—paper, electronic, and
verbal. GLBA covers financial institutions; PCI DSS covers cardholder data; COPPA covers
children's online information.
,Question
Which act was created to strengthen domestic security and broaden the powers of law-
enforcement agencies with regards to identifying and stopping terrorists?
A. Computer Security Act
B. Sarbanes-Oxley Act
C. US Patriot Act
D. FERPA
Expert Rationale: The US Patriot Act was enacted to strengthen domestic security and
expand law enforcement's ability to detect and prevent terrorism. The Computer Security
Act addresses federal computer security; Sarbanes-Oxley addresses corporate
governance; FERPA addresses student privacy.
Question
The Americans with Disabilities Act (ADA) requires accessibility of which of the following?
A. Physical buildings only
B. Electronic media, including websites, software applications, and video
C. Financial records only
D. Healthcare records only
Expert Rationale: The ADA standards require accessibility of electronic media, including
websites, software applications, operating systems, and video, to ensure equal access for
individuals with disabilities. While physical accessibility is also part of ADA, the question
specifically addresses electronic media.
Question
Which act was created to improve the security and privacy of sensitive information and to
create acceptable security practices for federal computer systems?
A. Computer Security Act
B. HIPAA
C. Sarbanes-Oxley Act
D. Gramm-Leach-Bailey Act
Expert Rationale: The Computer Security Act was created to improve the security and
privacy of sensitive information in federal computer systems and to establish acceptable
,security practices. HIPAA covers health information; Sarbanes-Oxley covers corporate
governance; GLBA covers financial institutions.
Question
FERPA was created to protect the privacy of which type of records?
A. Medical records
B. Student records
C. Financial records
D. Criminal records
Expert Rationale: FERPA (Family Educational Rights and Privacy Act) protects the privacy
of student education records. It applies to all schools that receive funds from the U.S.
Department of Education. HIPAA protects medical records; GLBA protects financial
records.
Question
Which act was created to help protect children under the age of 13 from exploitation by
governing the online collection of their personal information?
A. FERPA
B. The Children's Online Privacy Act (COPPA)
C. HIPAA
D. Gramm-Leach-Bailey Act
Expert Rationale: The Children's Online Privacy Act (COPPA) governs the online collection
of personal information from children under 13. It requires parental consent and imposes
rules on website operators. FERPA protects student records; HIPAA protects health
information; GLBA protects financial information.
Question
The Sarbanes-Oxley Act was created for which primary purpose?
A. To protect student records
B. To govern corporate governance and financial practice
C. To protect health information
D. To protect children's online privacy
, Expert Rationale: The Sarbanes-Oxley Act (SOX) was created to govern corporate
governance and financial practice, ensuring accuracy and accountability in financial
reporting. It was enacted in response to corporate scandals. HIPAA covers health; FERPA
covers student; COPPA covers children.
Question
PCI DSS defines minimum requirements for which group to protect cardholder data?
A. Healthcare providers
B. Merchants and service providers
C. Educational institutions
D. Government agencies
Expert Rationale: PCI DSS (Payment Card Industry Data Security Standard) defines
minimum security requirements for merchants and service providers that handle
cardholder data. It applies to any entity that stores, processes, or transmits credit card
information. HIPAA covers healthcare; FERPA covers education.
Question
A group of threat actors has a strong aversion to certain political ideologies. They launch a
cyberattack against an organization to which its perceived adversarial counterpart belongs.
This type of threat actor is most appropriately classified as:
A. Nation-state actor
B. Hacktivist
C. Cybercriminal
D. Insider threat
Expert Rationale: Hacktivists are threat actors who use cyberattacks to promote political
ideologies, social change, or protest against perceived adversaries. They are motivated by
political or social causes rather than financial gain. Nation-state actors are government-
sponsored; cybercriminals are financially motivated; insider threats are from within the
organization.
Question
What type of entity would a threat actor most likely attack to steal design documents for a