200-201 Security Concepts Practice Question
A security engineer is implementing controls to meet compliance requirements. Which TWO of the following frameworks are specifically designed for protecting personal data?
⚠ Common exam trap
Cisco often tests the distinction between frameworks that are specifically designed for personal data protection (like HIPAA and GDPR) versus general cybersecurity or information security frameworks (like NIST CSF, PCI DSS, and ISO 27001) that may include data protection but are not their primary purpose.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
HIPAA
HIPAA (A) is correct because it is a U.S. regulation specifically designed to protect the privacy and security of protected health information (PHI), which is a category of personal data. GDPR (C) is correct because it is an EU regulation explicitly focused on the protection of personal data and the privacy rights of individuals. NIST Cybersecurity Framework (B) is a voluntary framework for managing cybersecurity risk generally, not specifically for personal data protection. PCI DSS (D) is designed to protect payment card data, which is a narrower and different scope than personal data. ISO 27001 (E) is a general information security management standard, not specifically focused on personal data protection.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
HIPAA
Why this is correct
HIPAA safeguards protected health information, a subset of personal data, through its Privacy and Security Rules. It satisfies the compliance constraint by mandating administrative, physical and technical safeguards for individually identifiable health data, making it a framework specifically designed to protect personal information rather than general security controls.
- ✗
NIST Cybersecurity Framework
Why it's wrong here
The NIST Cybersecurity Framework provides voluntary guidance for managing cybersecurity risk across critical infrastructure sectors, not personal data protection. It is tempting because it is a recognised security framework. It would be the correct choice for structuring an organisation's overall cyber risk management programme.
- ✓
GDPR
Why this is correct
GDPR is a legally binding regulation that mandates protection of personal data for EU residents, satisfying the stem's personal-data compliance constraint. It imposes obligations on data controllers and processors, including breach notification and data subject rights, unlike frameworks such as NIST CSF or ISO 27001, which address broader security governance rather than personal data specifically.
- ✗
PCI DSS
Why it's wrong here
PCI DSS protects payment card data specifically, not personal data generally. It is tempting because cardholder data is a subset of personal data. PCI DSS would be the correct choice when an organisation stores, processes or transmits cardholder data and must demonstrate compliance to card brands.
- ✗
ISO 27001
Why it's wrong here
ISO 27001 specifies requirements for an information security management system, addressing confidentiality, integrity and availability broadly rather than personal data protection specifically. It is tempting because it is a widely adopted security standard. It would be the right choice for certifying an organisation's overall ISMS governance.
Go deeper
Related to this question
About these practice questions
Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.