exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 346 discussion

Actual exam question from ISC's CCSP
Question #: 346
Topic #: 1
[All CCSP Questions]

Above and beyond general regulations for data privacy and protection, certain types of data are subjected to more rigorous regulations and oversight.
Which of the following is not a regulatory framework for more sensitive or specialized data?

  • A. FIPS 140-2
  • B. FedRAMP
  • C. PCI DSS
  • D. HIPAA
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
theyetifollowsme
Highly Voted 3 years, 11 months ago
The question is concerned with "data" and FIPS 140-2 is a standard that pertains to cryptographic "modules" and not data.
upvoted 9 times
...
MaciekMT
Most Recent 1 month, 3 weeks ago
Selected Answer: A
FIPS 140-2 (Federal Information Processing Standard 140-2) is not a regulatory framework for data privacy or specialized data protection. Instead, it is a cryptographic standard that specifies security requirements for cryptographic modules used by U.S. federal agencies and contractors. Why Not the Others? Each of the other options regulates sensitive or specialized data: B. FedRAMP (Federal Risk and Authorization Management Program): Regulates cloud security for U.S. government agencies and ensures stringent security controls. C. PCI DSS (Payment Card Industry Data Security Standard): Regulates payment card data and ensures credit card transaction security. D. HIPAA (Health Insurance Portability and Accountability Act): Regulates protected health information (PHI) in the healthcare sector.
upvoted 1 times
...
cloudenthusiast
7 months, 1 week ago
Selected Answer: A
FIPS 140-2 is a certification standard for cryptographic module and it is not a framework.
upvoted 1 times
...
joeee7
1 year, 2 months ago
FedRAMP.
upvoted 1 times
...
Pika26
1 year, 5 months ago
Selected Answer: C
C: PCI DSS
upvoted 2 times
...
DA95
1 year, 10 months ago
The correct answer is B. FedRAMP. FedRAMP, or the Federal Risk and Authorization Management Program, is not a regulatory framework for specialized data. Rather, it is a program run by the U.S. government that provides a standardized approach to security assessment, authorization, and continuous monitoring for cloud products and services used by federal agencies. The other three options, FIPS 140-2, PCI DSS, and HIPAA, are all regulatory frameworks that provide specific guidelines and requirements for the handling of sensitive or specialized data.
upvoted 1 times
...
akg001
2 years, 4 months ago
Selected Answer: A
A. FIPS 140-2
upvoted 1 times
...
[Removed]
2 years, 9 months ago
Answer C. "Which of the following is not a regulatory framework for more sensitive or specialized data?" FIPS 140-2 is not a framework at all, its a guidelines so I guess it gets ruled out from the options itself as the question is asking to rule out the Framework specifically.
upvoted 1 times
...
babusartop17
3 years, 3 months ago
This is the 2nd time they've done it. Choose two should be the case here both PCI-DSS and FIPS are not regulatory framework. I think the Question maker was clearly high on something and I want to know "on what"?
upvoted 3 times
AWSPro24
2 years, 9 months ago
I could not agree more. I recently passed the CISSP and now doing this one and I also happen to have been involved in test development at one point in my career. All of the questions on these exams read as though they gave a random person who does not work i technology a set of source and said "write questions", it is as if the authors are completely context ignorant.
upvoted 1 times
...
...
NobleGiantz
3 years, 8 months ago
A is correct
upvoted 3 times
...
kjjcraigskel
4 years ago
PCI DSS is not a regulatory requirement
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago