Summer Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: ecus65

IAPP CIPT - Certified Information Privacy Technologist

Page: 2 / 7
Total 220 questions

What was the first privacy framework to be developed?

A.

OECD Privacy Principles.

B.

Generally Accepted Privacy Principles.

C.

Code of Fair Information Practice Principles (FIPPs).

D.

The Asia-Pacific Economic Cooperation (APEC) Privacy Framework.

Information classification helps an organization protect confidential and nonpublic information primarily because?

A.

It helps identify sensitive and critical information that require very strict safeguards.

B.

It falls under the security principles of confidentiality, integrity, and availability.

C.

It promotes employee accountability for safeguarding confidential information.

D.

It is legally required under most regulations.

What is typically NOT performed by sophisticated Access Management (AM) techniques?

A.

Restricting access to data based on location.

B.

Restricting access to data based on user role.

C.

Preventing certain types of devices from accessing data.

D.

Preventing data from being placed in unprotected storage.

All of the following topics should be included in a workplace surveillance policy EXCEPT?

A.

Who can be tracked and when.

B.

Who can access surveillance data.

C.

What areas can be placed under surveillance.

D.

Who benefits from collecting surveillance data.

Which of the following does NOT illustrate the ‘respect to user privacy’ principle?

A.

Implementing privacy elements within the user interface that facilitate the use of technology by any visually-challenged users.

B.

Enabling Data Subject Access Request (DSARs) that provide rights for correction, deletion, amendment and rectification of personal information.

C.

Developing a consent management self-service portal that enables the data subjects to review the details of consent provided to an organization.

D.

Filing breach notification paperwork with data protection authorities which detail the impact to data subjects.

A computer user navigates to a page on the Internet. The privacy notice pops up and the user clicks the box to accept cookies, then continues to scroll the page to read the Information displayed. This is an example of which type of consent?

A.

Explicit.

B.

Implicit.

C.

Specific

D.

Valid.

Which technique is most likely to facilitate the deletion of every instance of data associated with a deleted user account from every data store held by an organization?

A.

Auditing the code which deletes user accounts.

B.

Building a standardized and documented retention program for user data deletion.

C.

Monitoring each data store for presence of data associated with the deleted user account.

D.

Training engineering teams on the importance of deleting user accounts their associated data from all data stores when requested.

What would be an example of an organization transferring the risks associated with a data breach?

A.

Using a third-party service to process credit card transactions.

B.

Encrypting sensitive personal data during collection and storage

C.

Purchasing insurance to cover the organization in case of a breach.

D.

Applying industry standard data handling practices to the organization’ practices.

Ivan is a nurse for a home healthcare service provider in the US. The company has implemented a mobile application which Ivan uses to record a patient's vital statistics and access a patient's health care records during home visits. During one visitj^van is unable to access the health care application to record the patient's vitals. He instead records the information on his mobile phone's note-taking application to enter the data in the health care application the next time it is accessible. What would be the best course of action by the IT department to ensure the data is protected on his device?

A.

Provide all healthcare employees with mandatory annual security awareness training with a focus on the health

information protection.

B.

Complete a SWOT analysis exercise on the mobile application to identify what caused the application to be

inaccessible and remediate any issues.

C.

Adopt mobile platform standards to ensure that only mobile devices that support encryption capabilities are used.

D.

Implement Mobile Device Management (MDM) to enforce company security policies and configuration settings.

Which of the following activities would be considered the best method for an organization to achieve the privacy principle of data quality'?

A.

Clash customer information with information from a data broker

B.

Build a system with user access controls and approval workflows to edit customer data

C.

Set a privacy notice covering the purpose for collection of a customer's data

D.

Provide a customer with a copy of their data in a machine-readable format