Pass the IAPP Certified Information Privacy Professional CIPP-US Questions and answers with CertsForce

Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions
Questions # 11:

What is the main purpose of the Global Privacy Enforcement Network?

Options:

A.

To promote universal cooperation among privacy authorities


B.

To investigate allegations of privacy violations internationally


C.

To protect the interests of privacy consumer groups worldwide


D.

To arbitrate disputes between countries over jurisdiction for privacy laws


Expert Solution
Questions # 12:

SCENARIO

Please use the following to answer the next QUESTION

When there was a data breach involving customer personal and financial information at a large retail store, the company’s directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. There were neither adequate rules about access to customer information nor

procedures for purging and destroying outdated data. In her research, Roberta had discovered that even low- level employees had access to all of the company’s customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.

Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees’ access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers’ financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.

When the breach occurred, the company’s executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta’s guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.

Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.

Which principle of the Consumer Privacy Bill of Rights, if adopted, would best reform the company’s privacy program?

Options:

A.

Consumers have a right to exercise control over how companies use their personal data.


B.

Consumers have a right to reasonable limits on the personal data that a company retains.


C.

Consumers have a right to easily accessible information about privacy and security practices.


D.

Consumers have a right to correct personal data in a manner that is appropriate to the sensitivity.


Expert Solution
Questions # 13:

Which of the following data elements is most likely to be subject to comprehensive state data security and privacy laws?

Options:

A.

Account holders' social security numbers, maintained by a bank.


B.

Users' sexual orientations, maintained by a social media website


C.

Individual drivers' license numbers, maintained by a state agency.


D.

Contact details of individuals who report emergencies, maintained by local authorities


Expert Solution
Questions # 14:

What was the original purpose of the Foreign Intelligence Surveillance Act?

Options:

A.

To further define what information can reasonably be under surveillance in public places under the USA PATRIOT Act, such as Internet access in public libraries.


B.

To further clarify a reasonable expectation of privacy stemming from the Katz v. United States decision.


C.

To further define a framework for authorizing wiretaps by the executive branch for national security purposes under Article II of the Constitution.


D.

To further clarify when a warrant is not required for a wiretap performed internally by the telephone company outside the suspect’s home, stemming from the Olmstead v. United States decision.


Expert Solution
Questions # 15:

More than half of U.S. states require telemarketers to?

Options:

A.

Identify themselves at the beginning of a call


B.

Obtain written consent from potential customers


C.

Register with the state before conducting business


D.

Provide written contracts for customer transactions


Expert Solution
Questions # 16:

Which of the following privacy rights is NOT available under the Colorado Privacy Act?

Options:

A.

The right to access sensitive data.


B.

The right to correct sensitive data.


C.

The right to delete sensitive data.


D.

The right to limit the use of sensitive data.


Expert Solution
Questions # 17:

What role does the U.S. Constitution play in the area of workplace privacy?

Options:

A.

It provides enforcement resources to large employers, but not to small businesses


B.

It provides legal precedent for physical information security, but not for electronic security


C.

It provides contractual protections to members of labor unions, but not to employees at will


D.

It provides significant protections to federal and state governments, but not to private-sector employment


Expert Solution
Questions # 18:

Which of the following state laws has an entity exemption for organizations subject to the Gramm-Leach-Bliley Act (GLBA)?

Options:

A.

Nevada Privacy Law.


B.

California Privacy Rights Act.


C.

California Consumer Privacy Act.


D.

Virginia Consumer Data Protection Act


Expert Solution
Questions # 19:

The use of cookies on a website by a service provider is generally not deemed a ‘sale’ of personal information by CCPA, as long as which of the following conditions is met?

Options:

A.

The third party stores personal information to trigger a response to a consumer’s request to exercise their right to opt in.


B.

The analytics cookies placed by the service provider are capable of being tracked but cannot be linked to a particular consumer of that business.


C.

The service provider retains personal information obtained in the course of providing the services specified in the agreement with the subcontractors.


D.

The information collected by the service provider is necessary to perform debugging and the business and service provider have entered into an appropriate agreement.


Expert Solution
Questions # 20:

Which of the following became the first state to pass a law specifically regulating the practices of data brokers?

Options:

A.

Washington.


B.

California.


C.

New York.


D.

Vermont.


Expert Solution
Viewing page 2 out of 6 pages
Viewing questions 11-20 out of questions