Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Pass the IAPP Certified Information Privacy Manager CIPM Questions and answers with ValidTests

Exam CIPM All Questions
Exam CIPM Premium Access

View all detail and faqs for the CIPM exam

Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions
Questions # 61:

Which of the following best supports implementing controls to bring privacy policies into effect?

Options:

A.

The internal audit department establishing the audit controls which test for policy effectiveness.

B.

The legal department or outside counsel conducting a thorough review of the privacy program and policies.

C.

The Chief Information Officer as part of the Senior Management Team creating enterprise privacy policies to ensure controls are available.

D.

The information technology (IT) group supporting and enhancing the privacy program and privacy policy by developing processes and controls.

Expert Solution
Questions # 62:

Under the General Data Protection Regulation (GDPR), what must be included in a written agreement between the controller and processor in relation to processing conducted on the controller's behalf?

Options:

A.

An obligation on the processor to report any personal data breach to the controller within 72 hours,

B.

An obligation on both parties to report any serious personal data breach to the supervisory authority

C.

An obligation on both parties to agree to a termination of the agreement if the other party is responsible for a personal data breach.

D.

An obligation on the processor to assist the controller in complying with the controller's obligations to notify the supervisory authority about personal data breaches.

Expert Solution
Questions # 63:

Your company's lead applied scientist believes there's an opportunity to proactively address customer issues using machine learning. She requests access to all of the company's customer data and several publicly available datasets

All the following are appropriate next steps EXCEPT?

Options:

A.

Understanding the geographic location of your customers.

B.

Providing a public disclosure to all customers describing the purpose and nature of processing.

C.

Checking your company's public privacy notice to ensure this processing Is in line with current disclosures.

D.

Requesting further Information from your scientist to understand the goal of the model and the eventual operational description.

Expert Solution
Questions # 64:

When building a data privacy program, what is a good starting point to understand the scope of privacy program needs?

Options:

A.

Perform Data Protection Impact Assessments (DPIAs).

B.

Perform Risk Assessments

C.

Complete a Data Inventory.

D.

Review Audits.

Expert Solution
Questions # 65:

The theft of proprietary information could have best been prevented by?

Options:

A.

Doing criminal background checks on all contractors.

B.

Having requests for access reviewed by the privacy office.

C.

Escalating access requests for approval by the appropriate data custodian.

D.

Requiring multi-factor authentication for contractor access to confidential company data.

Expert Solution
Questions # 66:

What is the function of the privacy operational life cycle?

Options:

A.

It establishes initial plans for privacy protection and implementation

B.

It allows the organization to respond to ever-changing privacy demands

C.

It ensures that outdated privacy policies are retired on a set schedule

D.

It allows privacy policies to mature to a fixed form

Expert Solution
Questions # 67:

SCENARIO

Please use the following to answer the next QUESTION:

John is the new privacy officer at the prestigious international law firm – A&M LLP. A&M LLP is very proud of its reputation in the practice areas of Trusts & Estates and Merger & Acquisition in both U.S. and Europe.

During lunch with a colleague from the Information Technology department, John heard that the Head of IT, Derrick, is about to outsource the firm's email continuity service to their existing email security vendor – MessageSafe. Being successful as an email hygiene vendor, MessageSafe is expanding its business by leasing cloud infrastructure from Cloud Inc. to host email continuity service for A&M LLP.

John is very concerned about this initiative. He recalled that MessageSafe was in the news six months ago due to a security breach. Immediately, John did a quick research of MessageSafe's previous breach and learned that the breach was caused by an unintentional mistake by an IT administrator. He scheduled a meeting with Derrick to address his concerns.

At the meeting, Derrick emphasized that email is the primary method for the firm's lawyers to communicate with clients, thus it is critical to have the email continuity service to avoid any possible email downtime. Derrick has been using the anti-spam service provided by MessageSafe for five years and is very happy with the quality of service provided by MessageSafe. In addition to the significant discount offered by MessageSafe, Derrick emphasized that he can also speed up the onboarding process since the firm already has a service contract in place with MessageSafe. The existing on-premises email continuity solution is about to reach its end of life very soon and he doesn't have the time or resource to look for another solution. Furthermore, the off- premises email continuity service will only be turned on when the email service at A&M LLP's primary and secondary data centers are both down, and the email messages stored at MessageSafe site for continuity service will be automatically deleted after 30 days.

Which of the following is a TRUE statement about the relationship among the organizations?

Options:

A.

Cloud Inc. must notify A&M LLP of a data breach immediately.

B.

MessageSafe is liable if Cloud Inc. fails to protect data from A&M LLP.

C.

Cloud Inc. should enter into a data processor agreement with A&M LLP.

D.

A&M LLP's service contract must be amended to list Cloud Inc. as a sub-processor.

Expert Solution
Questions # 68:

Last year Ecosoft 8150 was hacked and a number of servers and programs were affected. Since the incident, the company started collecting metrics on data privacy and system outages to try to stop it from happening in the future.

What analysis would be most helpful based on the data they have collected?

Options:

A.

Return on Investment (ROI).

B.

Compliance analysis.

C.

Business Resiliency.

D.

Trend analysis.

Expert Solution
Questions # 69:

In a mobile app for purchasing and selling concert tickets, users are prompted to create a personalized profile prior to engaging in transactions. Once registered, users can securely access their profiles within the app, empowering them to manage and modify personal data as needed.

Which foundational Privacy by Design (PbD) principle does this feature follow?

Options:

A.

Proactive, not reactive; preventative, not remedial.

B.

Full functionality — positive-sum, not zero-sum.

C.

Respect for user privacy - keep it user-centric.

D.

End-to-end security — full life cycle protection.

Expert Solution
Questions # 70:

SCENARIO

Please use the following lo answer the next question:

You are the privacy manager within the privacy office of a National Forest Parks and Recreation Department. While having lunch with a colleague from the IT division, you learn that the IT director has put out a request for proposal (RFP) which calls for a system that collects the personal data of park attendees.

You consult with a few other colleagues in IT and learn that the RFP is worded such that it leaves it to the vendors to demonstrate what information they would collect from people who enter parks anywhere in the country, either in a vehicle or on foot. A partial list of the information collected includes:

• personal identifiers such as name, address, age, gender;

• vehicle registration information:

• facial images of park attendees;

• health information (e.g.. physical disabilities, use of mobility devices)

The stated purpose of the RFP is to:

"Improve the National Forest. Parks, and Recreation Department's ability to track and monitor service usage thereby Increasing the robustness of our customer data and to improve service offerings.''

Companies have already started submitting proposals for software solutions that address these information gathering practices. There is only one week left before the RFP closes.

The IT department has put together an RFP evaluation team but no one from the privacy office has been a Dart of the RFP ud to this point. This occurred deposite the fact….

From a privacy management perspective, what is problematic about the "stated purpose" of the RFP?

Options:

A.

It seeks to improve the robustness of customer data.

B.

It seeks to track and monitor service usage by the customers.

C.

It could lead to unauthorized collection of personal data to improve customer service.

D.

It does not specify what information will be collected for improving customer data.

Expert Solution
Viewing page 7 out of 9 pages
Viewing questions 61-70 out of questions