Courseiva
Data Protection →mediumMatching

SCS-C02 Data Protection Practice Question

Match each AWS security-related acronym to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Center for Internet Security

Payment Card Industry Data Security Standard

Health Insurance Portability and Accountability Act

System and Organization Controls

International standard for information security management

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

SOC: Report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.

The correct matches are: SOC with service organization controls, PCI DSS with credit card security, HIPAA with healthcare privacy, and FedRAMP with cloud authorization. Common confusions include mixing HIPAA with SOC and PCI DSS with FedRAMP.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    SOC: Report on controls at a service organization relevant to security, availability, processing integrity, confidentiality, or privacy.

    Why this is correct

    SOC reports (System and Organization Controls) are independent attestation reports issued by a CPA firm, examining controls at a service organization against the AICPA Trust Services Criteria (security, availability, processing integrity, confidentiality, privacy). SOC 1 focuses on controls relevant to user entities' internal control over financial reporting (ICFR), while SOC 2 and SOC 3 focus on the five trust service criteria; they are not laws or government programs but bridge audited evidence for customers.

  • ✓

    PCI DSS: Set of security standards designed to ensure that all companies that accept, process, store or transmit credit card information maintain a secure environment.

    Why this is correct

    The Payment Card Industry Data Security Standard (PCI DSS) is a contractual/industry standard mandated by the card brands (Visa, Mastercard, etc.), not a US law or government program. It applies to any entity that stores, processes, or transmits cardholder data, and sets twelve baseline requirements spanning network security, encryption, access control, and ongoing monitoring. Compliance is validated via self-assessment questionnaires (SAQ) or a Report on Compliance (ROC) by an approved scanning vendor/assessor.

  • ✓

    HIPAA: US law designed to provide privacy standards to protect patients' medical records and other health information.

    Why this is correct

    The Health Insurance Portability and Accountability Act is a US federal statute enacted in 1996 that created national privacy and security rules for protected health information (PHI). Its Privacy Rule governs permissible uses and disclosures of PHI by covered entities and business associates, while the Security Rule mandates administrative, physical, and technical safeguards for electronic PHI (e-PHI). HIPAA is enforced by the HHS Office for Civil Rights, not a security assessment framework for cloud services.

  • ✓

    FedRAMP: US government program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services.

    Why this is correct

    The Federal Risk and Authorization Management Program (FedRAMP) is a US government initiative established to provide a standardized, repeatable approach for assessing, authorizing, and continuously monitoring cloud service offerings used by federal agencies. It relies on NIST SP 800-53 controls and requires a third-party assessment organization (3PAO) to validate an SSP and produce deliverables that allow a Joint Authorization Board (JAB) or agency to grant an Authority to Operate (ATO). It is neither a law nor a data-specific standard, but an accreditation process for cloud providers.

  • ✗

    SOC: US law designed to provide privacy standards to protect patients' medical records and other health information.

    Why it's wrong here

    This definition actually describes HIPAA, not SOC. SOC (System and Organization Controls) reports attest to service organization controls against AICPA trust service criteria; they have nothing to do with medical-record privacy or US healthcare law. The privacy and confidentiality protections for patients' medical records and other health information are codified in HIPAA, not in any SOC report published under AICPA attestation standards.

  • ✗

    PCI DSS: US government program that standardizes security assessment, authorization, and continuous monitoring for cloud products and services.

    Why it's wrong here

    This definition confuses PCI DSS with FedRAMP. PCI DSS is not a US government program or a cloud-authorization framework; it is a private-sector security standard required by the payment-card brands for organizations handling cardholder data. FedRAMP, in contrast, standardizes security assessment, authorization, and continuous monitoring specifically for cloud products and services used by federal agencies.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.