New Year Sale Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: xmas50

IAPP CIPT - Certified Information Privacy Technologist

Page: 6 / 7
Total 256 questions

An organization must terminate their cloud vendor agreement immediately. What is the most secure way to delete the encrypted data stored in the cloud?

A.

Transfer the data to another location.

B.

Invoke the appropriate deletion clause in the cloud terms and conditions.

C.

Obtain a destruction certificate from the cloud vendor.

D.

Destroy all encryption keys associated with the data.

After committing to a Privacy by Design program, which activity should take place first?

A.

Create a privacy standard that applies to all projects and services.

B.

Establish a retention policy for all data being collected.

C.

Implement easy to use privacy settings for users.

D.

Perform privacy reviews on new projects.

An organization is launching a smart watch which, in addition to alerts, will notify the the wearer of incoming calls allowing them to answer on the device. This convenience also comes with privacy concerns and is an example of?

A.

Value-Sensitive Design.

B.

Ubiquitous computing.

C.

Anthropomorphism.

D.

Coupling

Between November 30th and December 2nd, 2013, cybercriminals successfully infected the credit card payment systems and bypassed security controls of a United States-based retailer with malware that exfiltrated 40 million credit card numbers. Six months prior, the retailer had malware detection software installed to prevent against such an attack.

Which of the following would best explain why the retailer’s consumer data was still exfiltrated?

A.

The detection software alerted the retailer’s security operations center per protocol, but the information security personnel failed to act upon the alerts.

B.

The U.S Department of Justice informed the retailer of the security breach on Dec. 12th, but the retailer took three days to confirm the breach and eradicate the malware.

C.

The IT systems and security measures utilized by the retailer’s third-party vendors were in compliance with industry standards, but their credentials were stolen by black hat hackers who then entered the retailer’s system.

D.

The retailer’s network that transferred personal data and customer payments was separate from the rest of the corporate network, but the malware code was disguised with the name of software that is supposed to protect this information.

You are a wine collector who uses the web to do research about your hobby. You navigate to a news site and an ad for wine pops up. What kind of advertising is this?

A.

Remnant.

B.

Behavioral.

C.

Contextual.

D.

Demographic.

What is true of providers of wireless technology?

A.

They have the legal right in most countries to control and use any data on their systems.

B.

They can see all unencrypted data that crosses the system.

C.

They are typically exempt from data security regulations.

D.

They routinely backup data that crosses their system.

SCENARIO

Wesley Energy has finally made its move, acquiring the venerable oil and gas exploration firm Lancelot from its long-time owner David Wilson. As a member of the transition team, you have come to realize that Wilson's quirky nature affected even Lancelot's data practices, which are maddeningly inconsistent. “The old man hired and fired IT people like he was changing his necktie,” one of Wilson’s seasoned lieutenants tells you, as you identify the traces of initiatives left half complete.

For instance, while some proprietary data and personal information on clients and employees is encrypted, other sensitive information, including health information from surveillance testing of employees for toxic exposures, remains unencrypted, particularly when included within longer records with less-sensitive data. You also find that data is scattered across applications, servers and facilities in a manner that at first glance seems almost random.

Among your preliminary findings of the condition of data at Lancelot are the following:

    Cloud technology is supplied by vendors around the world, including firms that you have not heard of. You are told by a former Lancelot employee that these vendors operate with divergent security requirements and protocols.

    The company’s proprietary recovery process for shale oil is stored on servers among a variety of less-sensitive information that can be accessed not only by scientists, but by personnel of all types at most company locations.

    DES is the strongest encryption algorithm currently used for any file.

    Several company facilities lack physical security controls, beyond visitor check-in, which familiar vendors often bypass.

    Fixing all of this will take work, but first you need to grasp the scope of the mess and formulate a plan of action to address it.

Which is true regarding the type of encryption Lancelot uses?

A.

It employs the data scrambling technique known as obfuscation.

B.

Its decryption key is derived from its encryption key.

C.

It uses a single key for encryption and decryption.

D.

It is a data masking methodology.

Which of the following is NOT a step in the methodology of a privacy risk framework?

A.

Assessment.

B.

Monitoring.

C.

Response.

D.

Ranking.

A BaaS provider backs up the corporate data and stores it in an outsider provider under contract with the organization. A researcher notifies the organization that he found unsecured data in the cloud. The organization looked into the issue and realized $ne of its backups was misconfigured on the outside provider's cloud and the data fully exposed to the open internet. They quickly secured the backup. Which is the best next step the organization should take?

A.

Review the content of the data exposed.

B.

Review its contract with the outside provider.

C.

Investigate how the researcher discovered the unsecured data.

D.

Investigate using alternate BaaS providers or on-premise backup systems.

Value Sensitive Design (VSD) focuses on which of the following?

A.

Quality and benefit.

B.

Ethics and morality.

C.

Principles and standards.

D.

Privacy and human rights.