nerdexam
(ISC)2

CCSP · Question #212

Which of the following is the best example of a key component of regulated PII?

The correct answer is B. Mandatory breach reporting. Regulated Personally Identifiable Information (PII) typically requires mandatory breach reporting, as defined by various privacy regulations.

Submitted by dimitri_ru· Apr 18, 2026Legal, Risk and Compliance

Question

Which of the following is the best example of a key component of regulated PII?

Options

  • AItems that should be implemented
  • BMandatory breach reporting
  • CAudit rights of subcontractors
  • DPCI DSS

How the community answered

(52 responses)
  • A
    8% (4)
  • B
    87% (45)
  • C
    2% (1)
  • D
    4% (2)

Why each option

Regulated Personally Identifiable Information (PII) typically requires mandatory breach reporting, as defined by various privacy regulations.

AItems that should be implemented

"Items that should be implemented" is too vague and general to be a specific component of regulated PII.

BMandatory breach reportingCorrect

Mandatory breach reporting is a key component of regulations governing PII, as it requires organizations to notify affected individuals and authorities when personal data breaches occur.

CAudit rights of subcontractors

Audit rights of subcontractors are related to data governance and third-party risk management, but not a direct component of the definition or handling of regulated PII itself.

DPCI DSS

PCI DSS (Payment Card Industry Data Security Standard) is a security standard for handling credit card data, not a general component of regulated PII.

Concept tested: PII regulations, data breach reporting

Source: https://learn.microsoft.com/en-us/compliance/regulatory/gdpr

Topics

#PII#Data Privacy#Breach Notification#Compliance

Community Discussion

No community discussion yet for this question.

Full CCSP Practice