CSLB General Building (B) — All Questions

Back to practice

14 questions

Governance & Compliance

Which document outlines acceptable and prohibited uses of an organization's IT systems by employees?

  • a.Acceptable use policy
  • b.Business impact analysis
  • c.Service level agreement
  • d.Memorandum of understanding

An acceptable use policy (AUP) defines how employees may and may not use company systems and data. It sets expectations and provides grounds for enforcement. Users typically acknowledge it as a condition of access.

Governance & Compliance

Which risk response involves purchasing insurance to shift financial impact to a third party?

  • a.Risk avoidance
  • b.Risk transference
  • c.Risk acceptance
  • d.Risk mitigation

Risk transference shifts the financial consequences of a risk to another party, commonly through insurance or contracts. The risk still exists, but its impact is borne elsewhere. It is chosen when handling the risk directly is impractical or costly.

Governance & Compliance

Choosing to take no action and knowingly bear a low-level risk is called:

  • a.Risk avoidance
  • b.Risk transference
  • c.Risk acceptance
  • d.Risk mitigation

Risk acceptance is a conscious decision to tolerate a risk, usually when the cost of controls exceeds the potential loss. It should be formally documented and approved. Acceptance is appropriate for low-impact or low-likelihood risks.

Governance & Compliance

Eliminating a risky activity entirely so the risk no longer applies is known as:

  • a.Risk acceptance
  • b.Risk transference
  • c.Risk mitigation
  • d.Risk avoidance

Risk avoidance removes the risk by discontinuing the activity that causes it. For example, not deploying a feature that would expose sensitive data. It fully eliminates that risk but may sacrifice a business opportunity.

Governance & Compliance

Which regulation governs the protection of personal data for individuals in the European Union?

  • a.GDPR
  • b.HIPAA
  • c.PCI DSS
  • d.SOX

The General Data Protection Regulation (GDPR) sets strict requirements for handling the personal data of EU residents. It mandates consent, breach notification, and data subject rights. Non-compliance can result in substantial fines.

Governance & Compliance

Which standard governs the secure handling of payment card data?

  • a.HIPAA
  • b.PCI DSS
  • c.GDPR
  • d.FERPA

The Payment Card Industry Data Security Standard (PCI DSS) defines controls for organizations that store, process, or transmit cardholder data. It is a contractual requirement rather than a law. Compliance reduces the risk of payment data breaches.

Governance & Compliance

Which US regulation protects the privacy and security of health information?

  • a.GDPR
  • b.PCI DSS
  • c.HIPAA
  • d.GLBA

The Health Insurance Portability and Accountability Act (HIPAA) sets requirements for safeguarding protected health information. It applies to healthcare providers, plans, and their business associates. Violations can lead to significant penalties.

Governance & Compliance

A calculation of expected yearly loss from a risk, found by multiplying single loss expectancy by annual rate of occurrence, is the:

  • a.Residual risk
  • b.Risk appetite
  • c.Exposure factor
  • d.Annualized loss expectancy

Annualized loss expectancy (ALE) estimates the expected yearly cost of a risk by multiplying single loss expectancy (SLE) by the annualized rate of occurrence (ARO). It supports cost-benefit decisions about controls. Spending more than the ALE on mitigation is usually not justified.

Governance & Compliance

Which assessment identifies the critical processes and the impact of their disruption to guide continuity planning?

  • a.Business impact analysis
  • b.Penetration test
  • c.Vulnerability scan
  • d.Gap analysis

A business impact analysis (BIA) identifies critical business functions and quantifies the effect of their disruption over time. It informs RTO and RPO targets and prioritizes recovery. It is a foundation of business continuity planning.

Governance & Compliance

Which agreement defines the measurable service levels a provider must meet, such as uptime guarantees?

  • a.MOU
  • b.Service level agreement
  • c.NDA
  • d.BPA

A service level agreement (SLA) specifies measurable commitments like availability and response times, with consequences for missing them. It sets clear expectations between provider and customer. Monitoring against the SLA holds the provider accountable.

Governance & Compliance

Which legal agreement prohibits parties from disclosing confidential information they receive?

  • a.SLA
  • b.MOU
  • c.Non-disclosure agreement
  • d.AUP

A non-disclosure agreement (NDA) legally binds parties to keep shared confidential information secret. It is common when sharing sensitive data with vendors, partners, or employees. Breaching it can result in legal liability.

Governance & Compliance

The residual risk that remains after all controls have been applied should be:

  • a.Ignored entirely
  • b.Transferred automatically
  • c.Eliminated completely
  • d.Accepted by management

Residual risk is what remains after mitigations are in place, and it cannot usually be reduced to zero. Senior management should formally acknowledge and accept it. This ensures leadership is aware of and owns the remaining exposure.

Governance & Compliance

Which framework provides a widely used structure for managing cybersecurity risk through functions like Identify, Protect, Detect, Respond, and Recover?

  • a.NIST Cybersecurity Framework
  • b.OWASP Top Ten
  • c.MITRE ATT&CK
  • d.PCI DSS

The NIST Cybersecurity Framework organizes security activities into core functions: Identify, Protect, Detect, Respond, and Recover. It offers a flexible, risk-based approach adaptable to any organization. It helps align security programs with business goals.

Governance & Compliance

Regular training that teaches employees to recognize phishing and follow security policies is called:

  • a.Penetration testing
  • b.Security awareness training
  • c.Change management
  • d.Vulnerability management

Security awareness training educates users to recognize threats like phishing and to follow safe practices. Because people are a common attack vector, this reduces human-related risk. Ongoing and simulated exercises reinforce the behavior over time.

Report