Drag a concept onto its matching description — or click a concept then click the description.
Data privacy in EU
Payment card security
Healthcare data protection
Financial reporting controls
Federal information security
Match each regulatory framework to its focus.
Drag a concept onto its matching description — or click a concept then click the description.
Data privacy in EU
Payment card security
Healthcare data protection
Financial reporting controls
Federal information security
Answer choices
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
GDPR: Protecting personal data of EU citizens
Correct matches: GDPR with data protection, HIPAA with health info, PCI DSS with credit card security, SOX with financial reporting. Common confusions include swapping HIPAA and PCI DSS due to both involving 'security', and confusing GDPR with SOX.
Answer analysis
For each option: why learners choose it and why it is or isn't the right answer here.
GDPR: Protecting personal data of EU citizens
Why this is correct
The General Data Protection Regulation (GDPR) is a comprehensive EU regulation that governs the processing of personal data of individuals in the European Economic Area, with extraterritorial reach. It establishes principles such as data minimization, purpose limitation, and rights like access, rectification, and erasure. Non-compliance can result in fines up to 4% of annual global turnover or €20 million, whichever is higher.
HIPAA: Safeguarding protected health information
Why this is correct
HIPAA's Privacy Rule creates national standards for protecting individually identifiable health information, termed protected health information (PHI), held or transmitted by covered entities and their business associates. It mandates safeguards for all forms of PHI, including electronic, paper, and oral, and grants patients rights over their health data. The Security Rule specifically addresses administrative, physical, and technical protections for electronic PHI.
PCI DSS: Securing credit card transactions and data
Why this is correct
PCI DSS is a contractual security standard imposed by the major payment card brands to reduce cardholder data breaches. It applies to all entities that store, process, or transmit cardholder data or sensitive authentication data, regardless of size. The standard requires network segmentation, encryption, access controls, continuous monitoring, and regular security testing to secure credit card transactions and related data.
SOX: Ensuring accuracy of financial reporting
Why this is correct
The Sarbanes-Oxley Act (SOX) is a U.S. federal law enacted to improve corporate governance and the accuracy of financial reporting after major accounting scandals. It requires CFOs and CEOs to certify the correctness of financial statements and mandates management's assessment of internal controls over financial reporting. Independent auditors must also attest to these controls, and the law establishes criminal penalties for fraudulent financial activities.
HIPAA: Securing credit card transactions
Why it's wrong here
This pairing misinterprets HIPAA's purpose: HIPAA exclusively protects protected health information (PHI) within the healthcare industry, including medical records and patients' identifiable health data. It contains no provisions addressing credit card transactions or payment card data. Securing credit card data is regulated by the PCI DSS, which is specifically designed to protect cardholder information during payment processing.
GDPR: Regulating financial disclosures
Why it's wrong here
GDPR is fundamentally a data protection and privacy regulation that governs the collection, processing, and storage of personal data belonging to EU/EEA residents. It does not address financial reporting or disclosure requirements; those are regulated by SOX, which focuses on corporate financial statement accuracy and internal controls. Therefore, attributing financial disclosure regulation to GDPR reflects a conflation of securities law with data protection law.
Go deeper
Learn chapter
Security Metrics and KPIs
Key term
General Data Protection Regulation
A European Union law that gives individuals control over their personal data and sets strict rules for how organizations collect, store, and process that data.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.