Pre-Winter Sale Limited Time 65% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: pass65

Pass the IAPP Certified Information Privacy Manager CIPM Questions and answers with CertsForce

Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions
Questions # 41:

When implementing an organization's privacy program, what right should be granted to the data subject?

Options:

A.

To have their data amended or erased if errors are found.


B.

To limit or refuse the disclosure of their data for any reason.


C.

To provide feedback regarding an organization's privacy policy.


D.

To verify that an organization uses the highest level of privacy protection available.


Expert Solution
Questions # 42:

SCENARIO

Please use the following to answer the next QUESTION:

Perhaps Jack Kelly should have stayed in the U.S. He enjoys a formidable reputation inside the company, Special Handling Shipping, for his work in reforming certain "rogue" offices. Last year, news broke that a police sting operation had revealed a drug ring operating in the Providence, Rhode Island office in the United States. Video from the office's video surveillance cameras leaked to news operations showed a drug exchange between Special Handling staff and undercover officers.

In the wake of this incident, Kelly had been sent to Providence to change the "hands off" culture that upper management believed had let the criminal elements conduct their illicit transactions. After a few weeks under Kelly's direction, the office became a model of efficiency and customer service. Kelly monitored his workers' activities using the same cameras that had recorded the illegal conduct of their former co-workers.

Now Kelly has been charged with turning around the office in Cork, Ireland, another trouble spot. The company has received numerous reports of the staff leaving the office unattended. When Kelly arrived, he found that even when present, the staff often spent their days socializing or conducting personal business on their mobile phones. Again, he observed their behaviors using surveillance cameras. He issued written reprimands to six staff members based on the first day of video alone.

Much to Kelly's surprise and chagrin, he and the company are now under investigation by the Data Protection Commissioner of Ireland for allegedly violating the privacy rights of employees. Kelly was told that the company's license for the cameras listed facility security as their main use, but he does not know why this matters. He has pointed out to his superiors that the company's training programs on privacy protection and data collection mention nothing about surveillance video.

You are a privacy protection consultant, hired by the company to assess this incident, report on the legal and compliance issues, and recommend next steps.

What does this example best illustrate about training requirements for privacy protection?

Options:

A.

Training needs must be weighed against financial costs.


B.

Training on local laws must be implemented for all personnel.


C.

Training must be repeated frequently to respond to new legislation.


D.

Training must include assessments to verify that the material is mastered.


Expert Solution
Questions # 43:

Which most accurately describes the reasons an organization will conduct a PIA?

Options:

A.

To assess an organization's compliance with applicable laws, regulations, standards, and internal procedures.


B.

To establish an inventory of its data processing activities in compliance with Article 30 of the GDPR.


C.

To identify and reduce the privacy risks to individuals at the commencement of a project.


D.

To analyze the impact of an incident response and determine next steps.


Expert Solution
Questions # 44:

K a privacy professional wants to show that an organization's privacy program is working as intended, the professional should?

Options:

A.

Collect feedback from customers about the privacy program.


B.

Carry out a personal data breach tabletop exercise.


C.

Collect and analyze privacy program metrics.


D.

Review privacy policies.


Expert Solution
Questions # 45:

What is one obligation that the General Data Protection Regulation (GDPR) imposes on data processors?

Options:

A.

To honor all data access requests from data subjects.


B.

To inform data subjects about the identity and contact details of the controller.


C.

To implement appropriate technical and organizational measures that ensure an appropriate level of security.


D.

To carry out data protection impact assessments in cases where processing is likely to result in high risk to the rights and freedoms of individuals.


Expert Solution
Questions # 46:

A start-up tech company is developing its privacy policies and processes.

Which policy is most important to ensure the organization is successful at processing consumer health information?

Options:

A.

The employee notice.


B.

The consumer health data policy.


C.

The privacy impact assessment (PIA).


D.

The Health Insurance Portability and Accountability Act (HIPAA) privacy notice.


Expert Solution
Questions # 47:

In a sample metric template, what does “target” mean?

Options:

A.

The suggested volume of data to collect


B.

The percentage of completion


C.

The threshold for a satisfactory rating


D.

The frequency at which the data is sampled


Expert Solution
Questions # 48:

What is a key feature of the privacy metric template adapted from the National Institute of Standards and Technology (NIST)?

Options:

A.

It provides suggestions about how to collect and measure data.


B.

It can be tailored to an organization's particular needs.


C.

It is updated annually to reflect changes in government policy.


D.

It is focused on organizations that do business internationally.


Expert Solution
Questions # 49:

(A business resiliency metric measures an organization's ability to?)

Options:

A.

Reform policies after negative audit outcomes.


B.

Gain new business through privacy initiatives.


C.

Maintain continuous operations during crises.


D.

Adhere to changes in privacy legislation.


Expert Solution
Questions # 50:

A privacy maturity model provides all of the following EXCEPT?

Options:

A.

A standard reference to assess a privacy program's current level of development.


B.

A way to highlight what functions a company lacks for proper program management.


C.

A way to guarantee that a company is compliant with applicable laws and regulations.


D.

An example of the methods and practices necessary to evaluate a company’s level of risk.


Expert Solution
Viewing page 5 out of 8 pages
Viewing questions 41-50 out of questions