E025 - Terms Test Questions with Verified
Correct Answers
Which regulation governs data protection and privacy rights for EU residents?
GDPR — General Data Protection Regulation. EU regulation governing personal data
protection and privacy requirements.
Which law gives California residents rights to access, delete, and opt out of
selling/sharing personal data?
CCPA/CPRA — California Consumer Privacy Act / California Privacy Rights Act.
Which law protects health information (PHI) in the United States?
HIPAA — Health Insurance Portability and Accountability Act.
Which law requires U.S. federal agencies to create and maintain information security
programs?
FISMA — Federal Information Security Modernization Act.
What is FedRAMP used for?
FedRAMP provides standardized security assessment and authorization for cloud services
used by U.S. federal agencies.
What does CMMC protect?
CMMC protects Controlled Unclassified Information (CUI) for Department of Defense
contractors.
What is ISO/IEC 27001?
, An international standard for creating, implementing, maintaining, and improving an
Information Security Management System (ISMS).
What is ISO/IEC 27002?
A security control guidance standard used to implement an ISMS.
What does ISO/IEC 27018 focus on?
Protecting personal data in public cloud environments.
What is SOC 2?
An attestation standard evaluating service provider controls for security, availability,
processing integrity, confidentiality, and privacy.
What is CSA STAR?
A cloud assurance program documenting cloud provider security posture.
What are the five functions of the NIST Cybersecurity Framework?
Identify, Protect, Detect, Respond, Recover.
What is NIST SP 800-53?
A catalog of security and privacy controls for federal information systems.
What does ENISA provide?
EU cybersecurity guidance, threat analysis, and policy support.
What does CNCF manage?
Cloud-native open-source projects such as Kubernetes and Prometheus.
What is Infrastructure as a Service (IaaS)?
Correct Answers
Which regulation governs data protection and privacy rights for EU residents?
GDPR — General Data Protection Regulation. EU regulation governing personal data
protection and privacy requirements.
Which law gives California residents rights to access, delete, and opt out of
selling/sharing personal data?
CCPA/CPRA — California Consumer Privacy Act / California Privacy Rights Act.
Which law protects health information (PHI) in the United States?
HIPAA — Health Insurance Portability and Accountability Act.
Which law requires U.S. federal agencies to create and maintain information security
programs?
FISMA — Federal Information Security Modernization Act.
What is FedRAMP used for?
FedRAMP provides standardized security assessment and authorization for cloud services
used by U.S. federal agencies.
What does CMMC protect?
CMMC protects Controlled Unclassified Information (CUI) for Department of Defense
contractors.
What is ISO/IEC 27001?
, An international standard for creating, implementing, maintaining, and improving an
Information Security Management System (ISMS).
What is ISO/IEC 27002?
A security control guidance standard used to implement an ISMS.
What does ISO/IEC 27018 focus on?
Protecting personal data in public cloud environments.
What is SOC 2?
An attestation standard evaluating service provider controls for security, availability,
processing integrity, confidentiality, and privacy.
What is CSA STAR?
A cloud assurance program documenting cloud provider security posture.
What are the five functions of the NIST Cybersecurity Framework?
Identify, Protect, Detect, Respond, Recover.
What is NIST SP 800-53?
A catalog of security and privacy controls for federal information systems.
What does ENISA provide?
EU cybersecurity guidance, threat analysis, and policy support.
What does CNCF manage?
Cloud-native open-source projects such as Kubernetes and Prometheus.
What is Infrastructure as a Service (IaaS)?