Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: merry71

Free Certified Information Privacy Technologist Practice Questions

Exams4sure Dumps

Exam style questions across every CIPT domain

Last Update 2 hours ago
Total Questions : 256

Start with our free CIPT practice questions, carefully crafted to mirror the domains, phrasing, and difficulty of the real Information Privacy Technologist exam. Each CIPT exam question comes with a detailed rationale that explains not just which answer is correct but why the others fall short. That's how concepts stick. Use the free set to benchmark yourself: identify your IAPP weak domains, see where you're losing marks, and build a focused study plan in minutes.

CIPT PDF

CIPT PDF (Printable)
$46.5
$154.99

CIPT Testing Engine

CIPT PDF (Printable)
$51
$169.99

CIPT PDF + Testing Engine

CIPT PDF (Printable)
$63.9
$212.99
Question # 51

What must be done to destroy data stored on "write once read many" (WORM) media?

Options:

A.  

The data must be made inaccessible by encryption.

B.  

The erase function must be used to remove all data.

C.  

The media must be physically destroyed.

D.  

The media must be reformatted.

Discussion 0
Question # 52

SCENARIO

Clean-Q is a company that offers house-hold and office cleaning services. The company receives requests from consumers via their website and telephone, to book cleaning services. Based on the type and size of service, Clean-Q then contracts individuals that are registered on its resource database - currently managed in-house by Clean-Q IT Support. Because of Clean-Q's business model, resources are contracted as needed instead of permanently employed.

The table below indicates some of the personal information Clean-Q requires as part of its business operations:

Question # 52

Clean-Q has an internal employee base of about 30 people. A recent privacy compliance exercise has been conducted to align employee data management and human resource functions with applicable data protection regulation. Therefore, the Clean-Q permanent employee base is not included as part of this scenario.

With an increase in construction work and housing developments, Clean-Q has had an influx of requests for cleaning services. The demand has overwhelmed Clean-Q's traditional supply and demand system that has caused some overlapping bookings.

Ina business strategy session held by senior management recently, Clear-Q invited vendors to present potential solutions to their current operational issues. These vendors included Application developers and Cloud-Q’s solution providers, presenting their proposed solutions and platforms.

The Managing Director opted to initiate the process to integrate Clean-Q's operations with a cloud solution (LeadOps) that will provide the following solution one single online platform: A web interface that Clean-Q accesses for the purposes of resource and customer management. This would entail uploading resource and customer information.

    A customer facing web interface that enables customers to register, manage and submit cleaning service requests online.

    A resource facing web interface that enables resources to apply and manage their assigned jobs.

    An online payment facility for customers to pay for services.

If Clean-Q were to utilize LeadOps' services, what is a contract clause that may be included in the agreement entered into with LeadOps?

Options:

A.  

A provision that holds LeadOps liable for a data breach involving Clean-Q's information.

B.  

A provision prescribing technical and organizational controls that LeadOps must implement.

C.  

A provision that requires LeadOps to notify Clean-Q of any suspected breaches of information that involves customer or resource information managed on behalf of Clean-Q.

D.  

A provision that allows Clean-Q to conduct audits of LeadOps’ information processing and information security environment, at LeadOps’ cost and at any time that Clean-Q requires.

Discussion 0
Question # 53

Which of the following activities would be considered the best method for an organization to achieve the privacy principle of data quality'?

Options:

A.  

Clash customer information with information from a data broker

B.  

Build a system with user access controls and approval workflows to edit customer data

C.  

Set a privacy notice covering the purpose for collection of a customer's data

D.  

Provide a customer with a copy of their data in a machine-readable format

Discussion 0
Question # 54

Which of the following suggests the greatest degree of transparency?

Options:

A.  

A privacy disclosure statement clearly articulates general purposes for collection

B.  

The data subject has multiple opportunities to opt-out after collection has occurred.

C.  

A privacy notice accommodates broadly defined future collections for new products.

D.  

After reading the privacy notice, a data subject confidently infers how her information will be used.

Discussion 0
Question # 55

Which of the following would best improve an organization’ s system of limiting data use?

Options:

A.  

Implementing digital rights management technology.

B.  

Confirming implied consent for any secondary use of data.

C.  

Applying audit trails to resources to monitor company personnel.

D.  

Instituting a system of user authentication for company personnel.

Discussion 0
Question # 56

SCENARIO

Please use the following to answer next question:

EnsureClaim is developing a mobile app platform for managing data used for assessing car accident insurance claims. Individuals use the app to take pictures at the crash site, eliminating the need for a built-in vehicle camera. EnsureClaim uses a third-party hosting provider to store data collected by the app. EnsureClaim customer service employees also receive and review app data before sharing with insurance claim adjusters.

The app collects the following information:

First and last name

Date of birth (DOB)

Mailing address

Email address

Car VIN number

Car model

License plate

Insurance card number

Photo

Vehicle diagnostics

Geolocation

What IT architecture would be most appropriate for this mobile platform?

Options:

A.  

Peer-to-peer architecture.

B.  

Client-server architecture.

C.  

Plug-in-based architecture.

D.  

Service-oriented architecture.

Discussion 0
Question # 57

A privacy engineer reviews a newly developed on-line registration page on a company’s website. The purpose of the page is to enable corporate customers to submit a returns / refund request for physical goods. The page displays the following data capture fields: company name, account reference, company address, contact name, email address, contact phone number, product name, quantity, issue description and company bank account details.

After her review, the privacy engineer recommends setting certain capture fields as “non-mandatory”. Setting which of the following fields as “non-mandatory” would be the best example of the principle of data minimization?

Options:

A.  

The contact phone number field.

B.  

The company address and name.

C.  

The contact name and email address.

D.  

The company bank account detail field.

Discussion 0
Question # 58

Which of the following is an example of the privacy risks associated with the Internet of Things (loT)?

Options:

A.  

A group of hackers infiltrate a power grid and cause a major blackout.

B.  

An insurance company raises a person’s rates based on driving habits gathered from a connected car.

C.  

A website stores a cookie on a user's hard drive so the website can recognize the user on subsequent visits.

D.  

A water district fines an individual after a meter reading reveals excess water use during drought conditions.

Discussion 0
Question # 59

Which of the following is the least effective privacy preserving practice in the Systems Development Life Cycle (SDLC)?

Options:

A.  

Conducting privacy threat modeling for the use-case.

B.  

Following secure and privacy coding standards in the development.

C.  

Developing data flow modeling to identify sources and destinations of sensitive data.

D.  

Reviewing the code against Open Web Application Security Project (OWASP) Top 10 Security Risks.

Discussion 0
Question # 60

Which of the following entities would most likely be exempt from complying with the General Data Protection Regulation (GDPR)?

Options:

A.  

A South American company that regularly collects European customers’ personal data.

B.  

A company that stores all customer data in Australia and is headquartered in a European Union (EU) member state.

C.  

A Chinese company that has opened a satellite office in a European Union (EU) member state to service European customers.

D.  

A North American company servicing customers in South Africa that uses a cloud storage system made by a European company.

Discussion 0

Free Exams Sample Questions