Certified Cloud Security Professional (CCSP) Practice Exam

Disable ads (and more) with a membership for a one time $2.99 payment

Boost your CCSP exam readiness with precise flashcards and multiple-choice questions. Each question includes explanations to ensure a solid understanding. Start your preparation journey today!

Each practice test/flash card set has 50 randomly selected questions from a bank of over 500. You'll get a new set of questions each time!

Practice this question and more.


Which regulation is designed to control financial institutions' handling of private information?

  1. HIPAA

  2. EU GDPR

  3. GLBA

  4. SOC 1

The correct answer is: GLBA

The correct answer is C. GLBA (Gramm-Leach-Bliley Act). GLBA, also known as the Financial Services Modernization Act of 1999, is a United States federal law that requires financial institutions to explain their information-sharing practices to their customers and to safeguard sensitive data. It mandates financial institutions to establish information security programs to protect customers' nonpublic personal information. The other options are not specifically designed to control financial institutions' handling of private information: A. HIPAA (Health Insurance Portability and Accountability Act) focuses on safeguarding protected health information within the healthcare industry. B. EU GDPR (General Data Protection Regulation) is a regulation in EU law concerning data protection and privacy for all individuals within the European Union and the European Economic Area but is not specifically targeted at financial institutions. D. SOC 1 (Service Organization Control 1) is an auditing standard that focuses on controls relevant to financial reporting, specifically for service organizations, and not primarily on the protection of private information within financial institutions.