nerdexam
Cisco

100-160 · Question #33

Drag and Drop Question Move each framework from the list on the left to the correct purpose on the right. Note: You will receive partial credit for each correct answer. Answer:

The correct answer is GDPR; HIPAA; PCI-DSS; FERPA; FISMA. The question is missing the actual purpose labels on the right side, but based on the correct arrangement, I can infer the standard mapping. Here's what this question is testing: --- Framework → Purpose Mapping | # | Framework | Purpose | |---|-----------|---------| | 1 | GDPR…

Security Principles

Question

Drag and Drop Question Move each framework from the list on the left to the correct purpose on the right. Note: You will receive partial credit for each correct answer. Answer:

Exhibit

100-160 question #33 exhibit

Answer Area

Drag items

FERPAFISMAGDPRHIPAAPCI-DSS

Correct arrangement

  • GDPR
  • HIPAA
  • PCI-DSS
  • FERPA
  • FISMA

Explanation

The question is missing the actual purpose labels on the right side, but based on the correct arrangement, I can infer the standard mapping. Here's what this question is testing:


Framework → Purpose Mapping

#FrameworkPurpose
1GDPRPrivacy of EU residents' personal data
2HIPAAProtection of health/medical information
3PCI-DSSSecurity of payment card data
4FERPAProtection of student educational records
5FISMASecurity of U.S. federal government systems

Individual Explanations

1. GDPR (General Data Protection Regulation) EU law governing how organizations collect, store, and process personal data of EU citizens. Applies globally to any entity handling EU resident data. Key right: the "right to be forgotten."

2. HIPAA (Health Insurance Portability and Accountability Act) U.S. federal law protecting Protected Health Information (PHI). Applies to healthcare providers, insurers, and their business associates. Governs electronic health records and disclosures.

3. PCI-DSS (Payment Card Industry Data Security Standard) Not a law - an industry standard created by card brands (Visa, Mastercard, etc.). Applies to any entity that stores, processes, or transmits cardholder data. Non-compliance risks fines and loss of card processing privileges.

4. FERPA (Family Educational Rights and Privacy Act) U.S. federal law protecting student education records at institutions receiving federal funding. Gives parents (and students over 18) rights to access and correct their records.

5. FISMA (Federal Information Security Management Act) U.S. federal law requiring federal agencies to implement information security programs. Tied to NIST frameworks. Applies specifically to government systems, not private sector.


Common Mistakes

  • GDPR vs. HIPAA confusion: Both protect personal data, but GDPR is EU-wide and sector-agnostic; HIPAA is U.S.-only and healthcare-specific.
  • PCI-DSS is not a law: It's a contractual industry standard, not legislation. Many students misclassify it alongside HIPAA/FERPA.
  • FISMA scope: Students often think FISMA applies broadly to all U.S. companies - it only covers federal agencies and their contractors.
  • FERPA audience: It protects student records, not all educational content. The data subject is the student, not the institution.

Topics

#security frameworks#NIST#compliance frameworks#framework purpose

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice