Which act violates the Family Educational Rights and Privacy Act of 1974 (FERPA)?
Reveal answer details Close answer details
Correct answerA
IAPP · CIPP-US
Preview real exam questions, verified answers and available explanations before choosing a study plan.
|
Single choice
Which act violates the Family Educational Rights and Privacy Act of 1974 (FERPA)? Reveal answer details Close answer detailsCorrect answerA
Single choice
What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called? Reveal answer details Close answer detailsCorrect answerA
Single choice
Most states with data breach notification laws indicate that notice to affected individuals must be sent in the "most expeditious time possible without unreasonable delay." Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
In 2014, Google was alleged to have violated the Family Educational Rights and Privacy Act (FERPA) through its Apps for Education suite of tools. Reveal answer details Close answer detailsCorrect answerA Explanation References:
Single choice
SCENARIO When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern. Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it. When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws. Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee. What could the company have done differently prior to the breach to reduce their risk? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which of the following is an example of federal preemption? Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
In a case of civil litigation, what might a defendant who is being sued for distributing an employee's private information face? Reveal answer details Close answer detailsCorrect answerC
Single choice
Sarah lives in San Francisco, California. Based on a dramatic increase in unsolicited commercial emails, Sarah believes that a major social media platform with over 50 million users has collected a lot of personal information about her. The company that runs the platform is based in New York and France. Why is Sarah entitled to ask the social media platform to delete the personal information they have collected about her? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
SCENARIO Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in California. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask questions about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements. Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision. Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. In any case, Celeste feels that all they need is common sense ?like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina. Based on Felicia's Bring Your Own Device (BYOD) plan, the business consultant will most likely advise Felicia and Celeste to do what? Reveal answer details Close answer detailsCorrect answerD
Single choice
What was the original purpose of the Federal Trade Commission Act? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
SCENARIO Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your homework?" Matt asked hopefully. Matt looked over his son's shoulder at his computer screen. "What kind of survey?" "It's asking questions about my opinions." "Let me see," Matt said, and began reading the list of questions that his son had already answered. "It's asking your opinions about the government and citizenship. That's a little odd. You're only ten." Matt wondered how the web link to the survey had ended up in his son's email inbox. Thinking the message might have been sent to his son by mistake he opened it and read it. It had come from an entity called the Leadership Project, and the content and the graphics indicated that it was intended for children. To Matt, this clearly seemed like a marketing ploy to solicit goods and services to children. He asked his son if he had been prompted to give information about himself in order to take the survey. His son told him he had been asked to give his name, address, telephone number, and date of birth, and to answer questions about his favorite games and toys. Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from marketers advertising products for children in his son's inbox, and he decided it was time to report the incident to the proper authorities. How could the marketer have best changed its privacy management program to meet COPPA "Safe Harbor" requirements? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
SCENARIO You are the chief privacy officer at HealthCo, a major hospital in a large U.S. city in state A. HealthCo is a HIPAA-covered entity that provides healthcare services to more than 100,000 patients. A third-party cloud computing service provider, CloudHealth, stores and manages the electronic protected health information (ePHI) of these individuals on behalf of HealthCo. CloudHealth stores the data in state B. As part of HealthCo's business associate agreement (BAA) with CloudHealth, HealthCo requires CloudHealth to implement security measures, including industry standard encryption practices, to adequately protect the data. However, HealthCo did not perform due diligence on CloudHealth before entering the contract, and has not conducted audits of CloudHealth's security measures. A CloudHealth employee has recently become the victim of a phishing attack. When the employee unintentionally clicked on a link from a suspicious email, the PHI of more than 10,000 HealthCo patients was compromised. It has since been published online. The HealthCo cybersecurity team quickly identifies the perpetrator as a known hacker who has launched similar attacks on other hospitals ?ones that exposed the PHI of public figures including celebrities and politicians. During the course of its investigation, HealthCo discovers that CloudHealth has not encrypted the PHI in accordance with the terms of its contract. In addition, CloudHealth has not provided privacy or security training to its employees. Law enforcement has requested that HealthCo provide its investigative report of the breach and a copy of the PHI of the individuals affected. A patient affected by the breach then sues HealthCo, claiming that the company did not adequately protect the individual's ePHI, and that he has suffered substantial harm as a result of the exposed data. The patient's attorney has submitted a discovery request for the ePHI exposed in the breach. What is the most effective kind of training CloudHealth could have given its employees to help prevent this type of data breach? Reveal answer details Close answer detailsCorrect answerA
Single choice
SCENARIO Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Celeste open a jewelry store in California. Felicia, despite being excited at the prospect, has a number of security concerns, and has only grudgingly accepted the need to hire other employees. In order to guard against the loss of valuable merchandise, Felicia wants to carefully screen applicants. With their permission, Felicia would like to run credit checks, administer polygraph tests, and scrutinize videos of interviews. She intends to read applicants' postings on social media, ask questions about drug addiction, and solicit character references. Felicia believes that if potential employees are serious about becoming part of a dynamic new business, they will readily agree to these requirements. Felicia is also in favor of strict employee oversight. In addition to protecting the inventory, she wants to prevent mistakes during transactions, which will require video monitoring. She also wants to regularly check the company vehicle's GPS for locations visited by employees. She also believes that employees who use their own devices for work-related purposes should agree to a certain amount of supervision. Given her high standards, Felicia is skeptical about the proposed location of the store. She has been told that many types of background checks are not allowed under California law. Her friend Celeste thinks these worries are unfounded, as long as applicants verbally agree to the checks and are offered access to the results. Nor does Celeste share Felicia's concern about state breach notification laws, which, she claims, would be costly to implement even on a minor scale. hassle an honest business if an accidental security incident were to occur. In any case, Celeste feels that all they need is common sense ?like remembering to tear up sensitive documents before throwing them in the recycling bin. Felicia hopes that she's right, and that all of her concerns will be put to rest next month when their new business consultant (who is also a privacy professional) arrives from North Carolina. Which law will be most relevant to Felicia's plan to ask applicants about drug addiction? Reveal answer details Close answer detailsCorrect answerA Explanation References:
Single choice
Which federal agency plays a role in privacy policy, but does NOT have regulatory authority? Reveal answer details Close answer detailsCorrect answerC
Single choice
What is the main challenge financial institutions face when managing user preferences? Reveal answer details Close answer detailsCorrect answerC
Single choice
Which was NOT one of the five priority areas listed by the Federal Trade Commission in its 2012 report, "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for Businesses and Policymakers"? Reveal answer details Close answer detailsCorrect answerA Explanation References:
Single choice
SCENARIO Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. For this new initiative, Miraculous is considering a product built by MedApps, a company that makes quality telehealth apps for healthcare practices and licenses them to be used with the practices' branding. Riya is the Privacy Officer at Miraculous, responsible for the practice's compliance with HIPAA and other applicable laws, and she works with the Miraculous procurement team to get vendor agreements in place. Riya has also been asked by the Miraculous Healthcare business operations team to review the MedApps' optional benchmarking service. Of particular concern is the requirement that Miraculous Healthcare upload information about the appointments to a portal hosted by MedApps. What can Riya do to most effectively minimize the privacy risks of using an app for telehealth appointments? Reveal answer details Close answer detailsCorrect answerA
Single choice
Which of the following is NOT one of three broad categories of products offered by data brokers, as identified by the U.S. Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
In 2011, the FTC announced a settlement with Google regarding its social networking service Google Buzz. Reveal answer details Close answer detailsCorrect answerD Explanation References:
Single choice
SCENARIO A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent letter from a prominent EU-based retail partner. Triggered by an unresolved complaint lodged by an EU resident, the letter describes an ongoing investigation by a supervisory authority into the The complainant accuses the retailer of improperly disclosing her personal data, without consent, to parties in the United States. Further, the complainant accuses the EU-based retailer of failing to respond to her withdrawal of consent and request for erasure of her personal data. Your organization, the US-based startup company, was never informed of this request for erasure by the EU-based retail partner. The supervisory authority investigating the complaint has threatened the suspension of data flows if the parties involved do not cooperate with the investigation. The letter closes with an urgent request: "Please act immediately by identifying all personal data received from our company." This is an important partnership. Company executives know that its biggest fans come from Western Europe; and this retailer is primarily responsible for the startup's rapid market penetration. As the Company's data privacy leader, you are sensitive to the criticality of the relationship with the retailer. Under the General Data Protection Regulation (GDPR), how would the U.S. Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
Which of the following became the first state to pass a law specifically regulating the collection of biometric data? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
Which of the following federal agencies does NOT have regulatory authority related to privacy? Reveal answer details Close answer detailsCorrect answerB
Single choice
Which statement is FALSE regarding the provisions of the Employee Polygraph Protection Act of 1988 (EPPA)? Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
The rules for "e-discovery" mainly prevent which of the following? Reveal answer details Close answer detailsCorrect answerB
Single choice
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide? Reveal answer details Close answer detailsCorrect answerD Explanation References:
Single choice
Which is an exception to the general prohibitions on telephone monitoring that exist under the U.S. Reveal answer details Close answer detailsCorrect answerC Explanation References:
Single choice
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what? Reveal answer details Close answer detailsCorrect answerB Explanation References:
Single choice
SCENARIO Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has made better financial decisions in the past two years. One potential employer, Arnie's Emporium, recently called to tell Noah he did not get a position. As part of the application process, Noah signed a consent form allowing the employer to request his credit report from a consumer reporting agency (CRA). Noah thinks that the report hurt his chances, but believes that he may not ever know whether it was his credit that cost him the job. However, Noah is somewhat relieved that he was not offered this particular position. He noticed that the store where he interviewed was extremely disorganized. He imagines that his credit report could still be sitting in the office, unsecured. Two days ago, Noah got another interview for a position at Sam's Market. The interviewer told Noah that his credit report would be a factor in the hiring decision. Noah was surprised because he had not seen anything on paper about this when he applied. Regardless, the effect of Noah's credit on his employability troubles him, especially since he has tried so hard to improve it. Noah made his worst financial decisions fifteen years ago, and they led to bankruptcy. In addition, Noah feels that an experience investing with a large bank may have contributed to his financial troubles. In 2007, in an effort to earn money to help pay off his debt, Noah talked to a customer service representative at a large investment company who urged him to purchase stocks. Without understanding the risks, Noah agreed. Unfortunately, Noah lost a great deal of money. After losing the money, Noah was a customer of another financial institution that suffered a large security breach. Noah was one of millions of customers whose personal information was compromised. He wonders if he may have been a victim of identity theft and whether this may have negatively affected his credit. Noah hopes that he will soon be able to put these challenges behind him, build excellent credit, and find the perfect job. Consumers today are most likely protected from situations like the one Noah had buying stock because of which federal action or legislation? Reveal answer details Close answer detailsCorrect answerD
Single choice
What practice does the USA FREEDOM Act NOT authorize? Reveal answer details Close answer detailsCorrect answerB Explanation "he USA FREEDOM Act ended bulk collection conducted under Section 215.154 Going forward, requests by government officials must be based upon specific selectors, such as a telephone number. Company officials are now permitted to release statistics about the number of such requests they receive in a given time period, and the government is required to report its numbers once a year.155 In 2018, government officials obtained 56 court orders for traditional business records and 14 court orders for call detail records.156"
Single choice
When designing contact tracing apps in relation to COVID-19 or any other diagnosed virus, all of the following privacy measures should be considered EXCEPT? Reveal answer details Close answer detailsCorrect answerA |