D320 80 QUESTION VERSION (JYO2) EXAM
| NEWEST ACTUAL EXAM COMPLETE
QUESTIONS AND VERIFIED ANSWERS
GRADED A+ | 100% PASS | 2025 UPDATE!
SOC 2
SOC Report type: Intended to report audits of any controls on an
organization's security, availability, processing integrity, confidentiality,
and privacy.
SOC 3
SOC Report type: Designed to be shared with the public.
Seal of approval. Does not contain any actual data about the security
controls of the audit target.
encrypted
Data at rest should be _________.
,Defining
SDLC Phase focused on identifying the business requirements of the
application, such as accounting, database, or customer relationship
management
Designing
SDLC Phase: Begin to develop user stories (what the user will want to
accomplish, what interface will look like and whether it will require the
use or development of any APIs)
Development
SDLC Phase where the code is written.
Testing
SDLC Phase where activities such as initial pen testing and vulnerability
scanning against the application are performed. Will use both dynamic
and static testing or DSAT (Dynamic Application Security Testing) or
SAST (Static Application Security Testing).
Secure Operations
,SDLC Phase where after testing, the application is deemed secure.
Disposal
SDLC Phase where app has reached end of life or has been replaced
with a newer or different application.
Graham-Leach-Bliley Act (GLBA)
Allow banks to merge with and own insurance companies. Included in
the law were stipulations that customer account information be kept
secure and private, and that customers be allowed to opt out of any
information-sharing arrangements the bank or insurer might engage in.
Sarbanes-Oxley Act (SOX)
Law that increases transparency into publicly traded corporations'
financial activities.
HIPPA
Law that protects patient records and data.
, FERPA
Law that prevents academic institutions from sharing student data with
anyone other than parents or students (after age 18)
DMCA
provisions to protect owned data; cracking of access controls on
copyrighted media a crime and enables holders to require any site to
remove content
CLOUD Act
Allows US law enforcement and courts to compel American companies
to disclose data stored in foreign data centers.
GDPR
Most significant, powerful personal privacy law in the world. Describes
the appropriate handling of personal and private information of all EU
citizens.
Crypto-shredding
| NEWEST ACTUAL EXAM COMPLETE
QUESTIONS AND VERIFIED ANSWERS
GRADED A+ | 100% PASS | 2025 UPDATE!
SOC 2
SOC Report type: Intended to report audits of any controls on an
organization's security, availability, processing integrity, confidentiality,
and privacy.
SOC 3
SOC Report type: Designed to be shared with the public.
Seal of approval. Does not contain any actual data about the security
controls of the audit target.
encrypted
Data at rest should be _________.
,Defining
SDLC Phase focused on identifying the business requirements of the
application, such as accounting, database, or customer relationship
management
Designing
SDLC Phase: Begin to develop user stories (what the user will want to
accomplish, what interface will look like and whether it will require the
use or development of any APIs)
Development
SDLC Phase where the code is written.
Testing
SDLC Phase where activities such as initial pen testing and vulnerability
scanning against the application are performed. Will use both dynamic
and static testing or DSAT (Dynamic Application Security Testing) or
SAST (Static Application Security Testing).
Secure Operations
,SDLC Phase where after testing, the application is deemed secure.
Disposal
SDLC Phase where app has reached end of life or has been replaced
with a newer or different application.
Graham-Leach-Bliley Act (GLBA)
Allow banks to merge with and own insurance companies. Included in
the law were stipulations that customer account information be kept
secure and private, and that customers be allowed to opt out of any
information-sharing arrangements the bank or insurer might engage in.
Sarbanes-Oxley Act (SOX)
Law that increases transparency into publicly traded corporations'
financial activities.
HIPPA
Law that protects patient records and data.
, FERPA
Law that prevents academic institutions from sharing student data with
anyone other than parents or students (after age 18)
DMCA
provisions to protect owned data; cracking of access controls on
copyrighted media a crime and enables holders to require any site to
remove content
CLOUD Act
Allows US law enforcement and courts to compel American companies
to disclose data stored in foreign data centers.
GDPR
Most significant, powerful personal privacy law in the world. Describes
the appropriate handling of personal and private information of all EU
citizens.
Crypto-shredding