exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 325 discussion

Actual exam question from ISC's CCSP
Question #: 325
Topic #: 1
[All CCSP Questions]

Which of the following is NOT a major regulatory framework?

  • A. PCI DSS
  • B. HIPAA
  • C. SOX
  • D. FIPS 140-2
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️
FIPS 140-2 is a United States certification standard for cryptographic modules, and it provides guidance and requirements for their use based on the requirements of the data classification. However, these are not actual regulatory requirements. The Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-
Oxley Act (SOX), and the Payment Card Industry Data Security Standard (PCI DSS) are all major regulatory frameworks either by law or specific to an industry.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
lolanczos
1 week, 1 day ago
Selected Answer: D
It's 100% D. FIPS 140-2 (Federal Information Processing Standard 140-2) is a standard for cryptographic modules used by U.S. federal agencies and contractors. While it is widely recognized, it is not a regulatory framework. Instead, it provides specific technical requirements for cryptographic module validation.
upvoted 1 times
...
JohnnyBG
4 months, 2 weeks ago
Selected Answer: A
PCI is not regulatory (Not from government)
upvoted 1 times
FranklinG
3 months, 2 weeks ago
PCI isn't a regulatory framework by law, but it is so to an industry. My answer is "D"
upvoted 1 times
...
...
Kneebee
8 months ago
My choice is answer "D". FIPS 140-2 is important, especially for government agencies and their contractors, it is not a broad regulatory framework that applies to a wide range of industries or organizations. Instead, it is a specific set of guidelines and requirements related to cryptographic security.
upvoted 1 times
...
Zeezee2
2 years, 7 months ago
FIPS is the worst answer so I'll just roll with that one.
upvoted 2 times
...
evilwizardington
3 years, 4 months ago
Frameworks created by a group of industries are also considered regulatory (in that sector). PCI is mandatory for companies processing card payments.
upvoted 1 times
evilwizardington
3 years, 4 months ago
Also, the key work in the question is 'major'. That's why FIPS is not the answer.
upvoted 1 times
...
...
kap0306
3 years, 5 months ago
If Answer is D then question should be asked in different wording. It should include compliance framework
upvoted 2 times
...
Sa007788
3 years, 5 months ago
both PCSI DSS and FIPS are not regulatory framework
upvoted 2 times
...
Guivent
3 years, 7 months ago
I think the answer should be PCI dss
upvoted 2 times
...
HCL
3 years, 7 months ago
PCI DSS is a regulatory framework; while FIPS-140 is just a standard which has four levels.
upvoted 1 times
HCL
3 years, 7 months ago
Correction: PCI DSS is a compliance framework
upvoted 1 times
...
...
CL888
3 years, 9 months ago
I agree, PCI is not even created by the government. FIPS should be the answer.
upvoted 1 times
...
bark101
3 years, 10 months ago
PCI is not regulatory it's a standard
upvoted 4 times
...
cisapriyank
3 years, 10 months ago
how is pci gegulatory
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago