100-160 · Question #33
Drag and Drop Question Move each framework from the list on the left to the correct purpose on the right. Note: You will receive partial credit for each correct answer. Answer:
The correct answer is GDPR; HIPAA; PCI-DSS; FERPA; FISMA. The question is missing the actual purpose labels on the right side, but based on the correct arrangement, I can infer the standard mapping. Here's what this question is testing: --- Framework → Purpose Mapping | # | Framework | Purpose | |---|-----------|---------| | 1 | GDPR…
Question
Drag and Drop Question Move each framework from the list on the left to the correct purpose on the right. Note: You will receive partial credit for each correct answer. Answer:
Exhibit
Answer Area
Drag items
Correct arrangement
- GDPR
- HIPAA
- PCI-DSS
- FERPA
- FISMA
Explanation
The question is missing the actual purpose labels on the right side, but based on the correct arrangement, I can infer the standard mapping. Here's what this question is testing:
Framework → Purpose Mapping
| # | Framework | Purpose |
|---|---|---|
| 1 | GDPR | Privacy of EU residents' personal data |
| 2 | HIPAA | Protection of health/medical information |
| 3 | PCI-DSS | Security of payment card data |
| 4 | FERPA | Protection of student educational records |
| 5 | FISMA | Security of U.S. federal government systems |
Individual Explanations
1. GDPR (General Data Protection Regulation) EU law governing how organizations collect, store, and process personal data of EU citizens. Applies globally to any entity handling EU resident data. Key right: the "right to be forgotten."
2. HIPAA (Health Insurance Portability and Accountability Act) U.S. federal law protecting Protected Health Information (PHI). Applies to healthcare providers, insurers, and their business associates. Governs electronic health records and disclosures.
3. PCI-DSS (Payment Card Industry Data Security Standard) Not a law - an industry standard created by card brands (Visa, Mastercard, etc.). Applies to any entity that stores, processes, or transmits cardholder data. Non-compliance risks fines and loss of card processing privileges.
4. FERPA (Family Educational Rights and Privacy Act) U.S. federal law protecting student education records at institutions receiving federal funding. Gives parents (and students over 18) rights to access and correct their records.
5. FISMA (Federal Information Security Management Act) U.S. federal law requiring federal agencies to implement information security programs. Tied to NIST frameworks. Applies specifically to government systems, not private sector.
Common Mistakes
- GDPR vs. HIPAA confusion: Both protect personal data, but GDPR is EU-wide and sector-agnostic; HIPAA is U.S.-only and healthcare-specific.
- PCI-DSS is not a law: It's a contractual industry standard, not legislation. Many students misclassify it alongside HIPAA/FERPA.
- FISMA scope: Students often think FISMA applies broadly to all U.S. companies - it only covers federal agencies and their contractors.
- FERPA audience: It protects student records, not all educational content. The data subject is the student, not the institution.
Topics
Community Discussion
No community discussion yet for this question.
