Which of the following are the mandatory pieces of information to be included in the documentation of records of processing activities for an organization that processes personal data on behalf of another organization?
-
A
Copies of the consent forms from each data subject.
-
B
Time limits for erasure of different categories of data.
-
C
Contact details of the processor and Data Protection Offer (DPO).
-
D
Descriptions of the processing activities and relevant data subjects.
Reveal answer details
Close answer details
To meet data protection and privacy legal requirements that may require personal data to be disposed of or deleted when no longer necessary for the use it was collected, what is the best privacy-enhancing solution a privacy technologist should recommend be implemented in application design to meet this requirement?
-
A
Implement a process to delete personal data on demand and maintain records on deletion requests.
-
B
Implement automated deletion of off-site backup of personal data based on annual risk assessments.
-
C
Develop application logic to validate and purge personal data according to legal hold status or retention schedule.
-
D
Securely archive personal data not accessed or used in the last 6 months. Automate a quarterly review to delete data from archive once no longer needed.
Reveal answer details
Close answer details
Correct answerC
ExplanationThis option aligns directly with data protection and privacy legal requirements that mandate the disposal or deletion of personal data when it is no longer necessary for the purposes for which it was collected. Developing application logic that validates and purges personal data according to a predefined retention schedule or legal hold status ensures that data is managed in compliance with legal requirements automatically. This solution is proactive and integrated into the system's operation, reducing the risk of human error and ensuring timely compliance with data retention policies.
Many modern vehicles incorporate technologies that increase the convenience of drivers, but collect information about driver behavior in order to Implement this. What should vehicle manufacturers prioritize to ensure enhanced privacy protection for drivers?
-
A
Share the sensitive data collected about driver behavior with the driver.
-
B
Derive implicit consent for the processing of sensitive data by the continued use of the vehicle.
-
C
Obtain affirmative consent for processing of sensitive data about the driver.
-
D
Provide easy to read, in-vehicle instructions about how to use the technology.
Reveal answer details
Close answer details
Correct answerC
Explanationvehicle manufacturers should prioritize obtaining affirmative consent for processing sensitive data about drivers in order to ensure enhanced privacy protection. Affirmative consent involves obtaining explicit agreement from individuals before collecting or processing their personal data.
Which of the following statements is true regarding software notifications and agreements?
-
A
Website visitors must view the site's privacy statement before downloading software.
-
B
Software agreements are designed to be brief, while notifications provide more details.
-
C
It is a good practice to provide users with information about privacy prior to software installation.
-
D
"Just in time" software agreement notifications provide users with a final opportunity to modify the agreement.
Reveal answer details
Close answer details
What privacy risk is NOT mitigated by the use of encrypted computation to target and serve online ads?
-
A
The ad being served to the user may not be relevant.
-
B
The user's sensitive personal information is used to display targeted ads.
-
C
The personal information used to target ads can be discerned by the server.
-
D
The user's information can be leaked to an advertiser through weak de-identification techniques.
Reveal answer details
Close answer details
SCENARIO Please use the following to answer the next question: Jordan just joined a fitness-tracker start-up based in California, USA, as its first Information Privacy and Security Officer. The company is quickly growing its business but does not sell any of the fitness trackers itself. Instead, it relies on a distribution network of third-party retailers in all major countries. Despite not having any stores, the company has a 78% market share in the EU. It has a website presenting the company and products, and a member section where customers can access their information. Only the email address and physical address need to be provided as part of the registration process in order to customize the site to the user's region and country. There is also a newsletter sent every month to all members featuring fitness tips, nutrition advice, product spotlights from partner companies based on user behavior and preferences. Jordan says the General Data Protection Regulation (GDPR) does not apply to the company. He says the company is not established in the EU, nor does it have a processor in the region. Furthermore, it does not do any "offering goods or services" in the EU since it does not do any marketing there, nor sell to consumers directly. Jordan argues that it is the customers who chose to buy the products on their own initiative and there is no "offering" from the company. The fitness trackers incorporate advanced features such as sleep tracking, GPS tracking, heart rate monitoring. wireless syncing, calorie-counting and step-tracking. The watch must be paired with either a smartphone or a computer in order to collect data on sleep levels, heart rates, etc. All information from the device must be sent to the company's servers in order to be processed, and then the results are sent to the smartphone or computer. Jordan argues that there is no personal information involved since the company does not collect banking or social security information. Why is Jordan's claim that the company does not collect personal information as identified by the GDPR inaccurate?
-
A
The potential customers must browse for products online.
-
B
The fitness trackers capture sleep and heart rate data to monitor an individual's behavior.
-
C
The website collects the customers' and users' region and country information.
-
D
The customers must pair their fitness trackers to either smartphones or computers.
Reveal answer details
Close answer details
Correct answerB
ExplanationSleep and heart rate data collected by the fitness trackers can be considered personal information under the GDPR because it relates to an identified or identifiable natural person. This means that even if the company does not collect other types of personal information such as name or address, it is still collecting personal information as defined by the GDPR.
After committing to a Privacy by Design program, which activity should take place first?
-
A
Create a privacy standard that applies to all projects and services.
-
B
Establish a retention policy for all data being collected.
-
C
Implement easy to use privacy settings for users.
-
D
Perform privacy reviews on new projects.
Reveal answer details
Close answer details
SCENARIO Kyle is a new security compliance manager who will be responsible for coordinating and executing controls to ensure compliance with the company's information security policy and industry standards. Kyle is also new to the company, where collaboration is a core value. On his first day of new-hire orientation, Kyle's schedule included participating in meetings and observing work in the IT and compliance departments. Kyle spent the morning in the IT department, where the CIO welcomed him and explained that her department was responsible for IT governance. The CIO and Kyle engaged in a conversation about the importance of identifying meaningful IT governance metrics. Following their conversation, the CIO introduced Kyle to Ted and Barney. Ted is implementing a plan to encrypt data at the transportation level of the organization's wireless network. Kyle would need to get up to speed on the project and suggest ways to monitor effectiveness once the implementation was complete. Barney explained that his short-term goals are to establish rules governing where data can be placed and to minimize the use of offline data storage. Kyle spent the afternoon with Jill, a compliance specialist, and learned that she was exploring an initiative for a compliance program to follow self-regulatory privacy principles. Thanks to a recent internship, Kyle had some experience in this area and knew where Jill could find some support. Jill also shared results of the company's privacy risk assessment, noting that the secondary use of personal information was considered a high risk. By the end of the day, Kyle was very excited about his new job and his new company. In fact, he learned about an open position for someone with strong qualifications and experience with access privileges, project standards board approval processes, and application-level obligations, and couldn't wait to recommend his friend Ben who would be perfect for the job. Ted's implementation is most likely a response to what incident?
-
A
Encryption keys were previously unavailable to the organization's cloud storage host.
-
B
Signatureless advanced malware was detected at multiple points on the organization's networks.
-
C
Cyber criminals accessed proprietary data by running automated authentication attacks on the organization's network.
-
D
Confidential information discussed during a strategic teleconference was intercepted by the organization's top competitor.
Reveal answer details
Close answer details
Correct answerC
ExplanationIn the scenario, Ted implemented a new security measure that requires all employees to use two-factor authentication when accessing the organization's network. This measure is most likely a response to an incident where cyber criminals accessed proprietary data by running automated authentication attacks on the organization's network.
How does browser fingerprinting compromise privacy?
-
A
By creating a security vulnerability.
-
B
By differentiating users based upon parameters.
-
C
By persuading users to provide personal information.
-
D
By customizing advertising based on the geographic location.
Reveal answer details
Close answer details
Correct answerB
Explanationbrowser fingerprinting compromises privacy by differentiating users based upon parameters. Browser fingerprinting involves collecting information about a user's device and browser configuration in order to uniquely identify them. This can allow for tracking of user behavior across websites without their knowledge or consent.
Question 10
Single choice
A privacy technologist has been asked to aid in a forensic investigation on the darknet following the compromise of a company's personal data. This will primarily involve an understanding of which of the following privacy-preserving techniques?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerA
Explanationa privacy technologist aiding in a forensic investigation on the darknet following the compromise of a company's personal data would primarily need an understanding of encryption. Encryption is a privacy-preserving technique that can help protect sensitive data from unauthorized access.
Question 11
Single choice
Properly configured databases and well-written website codes are the best protection against what online threat?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationProperly configured databases and well-written website code are essential protections against SQL injection attacks. SQL injection occurs when an attacker exploits a security vulnerability arising from improper input validation in code for web applications that interact with databases. By injecting malicious SQL statements into an entry field for execution, an attacker can read, modify, or delete data that they are not normally able to access. Ensuring that database queries are securely written and that databases are configured to reject malicious inputs is critical to defending against this type of security threat.
Question 12
Single choice
When deploying a consumer gadget that incorporates speech recognition, where is the speech generally best processed, from a privacy by design perspective?
-
A
Within the subject's jurisdiction
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 13
Single choice
What is the most important requirement to fulfill when transferring data out of an organization?
-
A
Ensuring the organization sending the data controls how the data is tagged by the receiver.
-
B
Ensuring the organization receiving the data performs a privacy impact assessment.
-
C
Ensuring the commitments made to the data owner are followed.
-
D
Extending the data retention schedule as needed.
Reveal answer details
Close answer details
Correct answerC
ExplanationThe most important requirement to fulfill when transferring data out of an organization is ensuring the commitments made to the data owner are followed. The data owner is the person who has provided their personal data to an organization for a specific purpose or consented to its collection. When transferring data out of an organization, such as sharing it with another entity or moving it across borders, it is essential that the organization respects the rights and expectations of the data owner and complies with any applicable laws or regulations. The other options are not requirements for transferring data out of an organization, but rather possible measures or considerations that may be relevant depending on the context or nature of the transfer.
Question 14
Single choice
What is the main reason the Do Not Track (DNT) header is not acknowledged by more companies?
-
A
Most web browsers incorporate the DNT feature.
-
B
The financial penalties for violating DNT guidelines are too high.
-
C
There is a lack of consensus about what the DNT header should mean.
-
D
It has been difficult to solve the technological challenges surrounding DNT.
Reveal answer details
Close answer details
Correct answerC
ExplanationReferences: https://en.wikipedia.org/wiki/Do_Not_Track
Question 15
Single choice
Which of the following is the LEAST effective at meeting the Fair Information Practice Principles (FIPPs) in the Systems Development Life Cycle (SDLC)?
-
A
Defining requirements to manage end user content
-
B
Conducting privacy threat modeling for the use-case
-
C
Developing data flow modeling to help the purpose, protection, and retention of sensitive data
-
D
Reviewing the code against Open Web Application Security Project (OWASP) Top 10 Security Risks
Reveal answer details
Close answer details
Question 16
Single choice
of the following best describes a network threat model and Its uses?
-
A
It Is used in software development to detect programming errors. .
-
B
It is a risk-based model used to calculate the probabilities of risks identified during vulnerability tests.
-
C
It helps assess the probability, the potential harm, and the priority of attacks to help minimize or eradicate the threats.
-
D
It combines the results of vulnerability and penetration tests to provide useful insights into the network's overall threat and security posture.
Reveal answer details
Close answer details
Correct answerC
Explanationa network threat model helps assess the probability, the potential harm, and the priority of attacks to help minimize or eradicate the threats.
Question 17
Single choice
SCENARIO It should be the most secure location housing data in all of Europe, if not the world. The Global Finance Data Collective (GFDC) stores financial information and other types of client data from large banks, insurance companies, multinational corporations and governmental agencies. After a long climb on a mountain road that leads only to the facility, you arrive at the security booth. Your credentials are checked and checked again by the guard to visually verify that you are the person pictured on your passport and national identification card. You are led down a long corridor with server rooms on each side, secured by combination locks built into the doors. You climb a flight of stairs and are led into an office that is lighted brilliantly by skylights where the GFDC Director of Security, Dr. Monique Batch, greets you. On the far wall you notice a bank of video screens showing different rooms in the facility. At the far end, several screens show different sections of the road up the mountain Dr. Batch explains once again your mission. As a data security auditor and consultant, it is a dream assignment: The GFDC does not want simply adequate controls, but the best and most effective security that current technologies allow. "We were hacked twice last year," Dr. Batch says, "and although only a small number of records were stolen, the bad press impacted our business. Our clients count on us to provide security that is nothing short of impenetrable and to do so quietly. We hope to never make the news again." She notes that it is also essential that the facility is in compliance with all relevant security regulations and standards. You have been asked to verify compliance as well as to evaluate all current security controls and security measures, including data encryption methods, authentication controls and the safest methods for transferring data into and out of the facility. As you prepare to begin your analysis, you find yourself considering an intriguing question: Can these people be sure that I am who I say I am? You are shown to the office made available to you and are provided with system login information, including the name of the wireless network and a wireless key. Still pondering, you attempt to pull up the facility's wireless network, but no networks appear in the wireless list. When you search for the wireless network by name, however it is readily found. What measures can protect client information stored at GFDC?
-
A
De-linking of data into client-specific packets.
-
B
Cloud-based applications.
-
C
-
D
Reveal answer details
Close answer details
Question 18
Single choice
Which of the following activities would be considered the best method for an organization to achieve the privacy principle of data quality'?
-
A
Clash customer information with information from a data broker
-
B
Build a system with user access controls and approval workflows to edit customer data
-
C
Set a privacy notice covering the purpose for collection of a customer's data
-
D
Provide a customer with a copy of their data in a machine-readable format
Reveal answer details
Close answer details
Correct answerB
Explanationbuilding a system with user access controls and approval workflows to edit customer data would be considered the best method for an organization to achieve the privacy principle of data quality.
Question 19
Single choice
SCENARIO Clean-Q is a company that offers house-hold and office cleaning services. The company receives requests from consumers via their website and telephone, to book cleaning services. Based on the type and size of service, Clean-Q then contracts individuals that are registered on its resource database - currently managed in-house by Clean-Q IT Support. Because of Clean-Q's business model, resources are contracted as needed instead of permanently employed. The table below indicates some of the personal information Clean-Q requires as part of its business operations:  Clean-Q has an internal employee base of about 30 people. A recent privacy compliance exercise has been conducted to align employee data management and human resource functions with applicable data protection regulation. Therefore, the Clean-Q permanent employee base is not included as part of this scenario. With an increase in construction work and housing developments, Clean-Q has had an influx of requests for cleaning services. The demand has overwhelmed Clean-Q's traditional supply and demand system that has caused some overlapping bookings. Ina business strategy session held by senior management recently, Clear-Q invited vendors to present potential solutions to their current operational issues. These vendors included Application developers and Cloud-Q's solution providers, presenting their proposed solutions and platforms. The Managing Director opted to initiate the process to integrate Clean-Q's operations with a cloud solution (LeadOps) that will provide the following solution one single online platform: A web interface that Clean-Q accesses for the purposes of resource and customer management. This would entail uploading resource and customer information. A customer facing web interface that enables customers to register, manage and submit cleaning service requests online. A resource facing web interface that enables resources to apply and manage their assigned jobs. An online payment facility for customers to pay for services. What is a key consideration for assessing external service providers like LeadOps, which will conduct personal information processing operations on Clean-Q's behalf?
-
A
Understanding LeadOps' costing model.
-
B
Establishing a relationship with the Managing Director of LeadOps.
-
C
Recognizing the value of LeadOps' website holding a verified security certificate.
-
D
Obtaining knowledge of LeadOps' information handling practices and information security environment.
Reveal answer details
Close answer details
Correct answerD
ExplanationWhen engaging an external service provider to process personal information on its behalf, it is important for Clean-Q to have a good understanding of the service provider's information handling practices and information security environment. This will help Clean-Q assess whether or not the service provider has appropriate measures in place to protect the personal information it entrusts to them.
Question 20
Single choice
When considering dark patterns, which of the following should the privacy technologist be concerned about?
-
A
Illicit collection of personal data
-
B
Manipulation of a user's choice.
-
C
Discrimination stemming from user profiles.
-
D
Unauthorized access to an individual's data.
Reveal answer details
Close answer details
Question 21
Single choice
SCENARIO Looking back at your first two years as the Director of Personal Information Protection and Compliance for the Berry Country Regional Medical Center in Thorn Bay, Ontario, Canada, you see a parade of accomplishments, from developing state-of-the-art simulation based training for employees on privacy protection to establishing an interactive medical records system that is accessible by patients as well as by the medical personnel. Now, however, a question you have put off looms large: how do we manage all the data-not only records produced recently, but those still on hand from years ago? A data flow diagram generated last year shows multiple servers, databases, and work stations, many of which hold files that have not yet been incorporated into the new records system. While most of this data is encrypted, its persistence may pose security and compliance concerns. The situation is further complicated by several long-term studies being conducted by the medical staff using patient information. Having recently reviewed the major Canadian privacy regulations, you want to make certain that the medical center is observing them. You also recall a recent visit to the Records Storage Section, often termed "The Dungeon" in the basement of the old hospital next to the modern facility, where you noticed a multitude of paper records. Some of these were in crates marked by years, medical condition or alphabetically by patient name, while others were in undifferentiated bundles on shelves and on the floor. The back shelves of the section housed data tapes and old hard drives that were often unlabeled but appeared to be years old. On your way out of the dungeon, you noticed just ahead of you a small man in a lab coat who you did not recognize. He carried a batch of folders under his arm, apparently records he had removed from storage. Which cryptographic standard would be most appropriate for protecting patient credit card information in the records system?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerB
ExplanationTo protect patient credit card information in the records system at Berry Country Regional Medical Center, an appropriate cryptographic standard to use would be option B: Symmetric Encryption. Symmetric encryption uses a single secret key to encrypt and decrypt data. It is a fast and efficient method of encryption that can provide strong protection for sensitive data such as credit card information when implemented correctly.
Question 22
Single choice
SCENARIO Please use the following to answer the next question: Chuck, a compliance auditor for a consulting firm focusing on healthcare clients, was required to travel to the client's office to perform an onsite review of the client's operations. He rented a car from Finley Motors upon arrival at the airport as so he could commute to and from the client's office. The car rental agreement was electronically signed by Chuck and included his name, address, driver's license, make/model of the car, billing rate, and additional details describing the rental transaction. On the second night, Chuck was caught by a red light camera not stopping at an intersection on his way to dinner. Chuck returned the car back to the car rental agency at the end week without mentioning the infraction and Finley Motors emailed a copy of the final receipt to the address on file. Local law enforcement later reviewed the red light camera footage. As Finley Motors is the registered owner of the car, a notice was sent to them indicating the infraction and fine incurred. This notice included the license plate number, occurrence date and time, a photograph of the driver, and a web portal link to a video clip of the violation for further review. Finley Motors, however, was not responsible for the violation as they were not driving the car at the time and transferred the incident to AMP Payment Resources for further review. AMP Payment Resources identified Chuck as the driver based on the rental agreement he signed when picking up the car and then contacted Chuck directly through a written letter regarding the infraction to collect the fine. After reviewing the incident through the AMP Payment Resources' web portal, Chuck paid the fine using his personal credit card. Two weeks later, Finley Motors sent Chuck an email promotion offering 10% off a future rental. What is the most secure method Finley Motors should use to transmit Chuck's information to AMP Payment Resources?
-
A
Cloud file transfer services.
-
B
Certificate Authority (CA).
-
C
HyperText Transfer Protocol (HTTP).
-
D
Transport Layer Security (TLS).
Reveal answer details
Close answer details
Correct answerD
ExplanationTLS is a cryptographic protocol that provides secure communication over a network. It can help protect against eavesdropping and tampering by encrypting data in transit. Cloud file transfer services (option A) can also provide secure transmission of data but their security depends on the specific service used. Certificate Authority (CA) (option B) is not a method for transmitting data but rather a trusted third party that issues digital certificates used for authentication. HyperText Transfer Protocol (HTTP) (option C) is not a secure method for transmitting sensitive data as it does not provide encryption.
Question 23
Single choice
Which activity should the privacy technologist undertake to reduce potential privacy risk when evaluating options to process data in a country other than where it would be collected? ^
-
A
Review the Data Life Cycle.
-
B
Review data retention policies.
-
C
Create enterprise data flow diagrams.
-
D
Recommend controls for data transfers.
Reveal answer details
Close answer details
Correct answerD
Explanationwhen evaluating options to process data in a country other than where it would be collected, a privacy technologist should recommend controls for data transfers. This can help reduce potential privacy risks associated with transferring data across borders.
Question 24
Single choice
An organization is evaluating a number of Machine Learning (ML) solutions to help automate a customer-facing part of its business From a privacy perspective, the organization should first?
-
A
Define their goals for fairness
-
B
Document the distribution of bias scores
-
C
Document the False Positive Rates (FPR).
-
D
Define how data subjects may object to the processing
Reveal answer details
Close answer details
Correct answerD
Explanationfrom a privacy perspective, an organization evaluating a number of Machine Learning (ML) solutions to help automate a customer-facing part of its business should first define how data subjects may object to the processing. This involves establishing clear and transparent mechanisms for individuals to exercise their rights with respect to their personal data.
Question 25
Single choice
An organization's customers have suffered a number of data breaches through successful social engineering attacks. One potential solution to remediate and prevent future occurrences would be to implement which of the following?
-
A
Differential identifiability.
-
B
Multi-factor authentication.
-
C
Greater password complexity.
-
D
Attribute-based access control.
Reveal answer details
Close answer details
Correct answerB
ExplanationMulti-factor authentication. Social engineering attacks often involve tricking individuals into revealing their login credentials. Implementing multi-factor authentication can help prevent unauthorized access even if an attacker obtains a user's password.
Question 26
Single choice
An organization is considering launching enhancements to improve security and authentication mechanisms in their products. To better identify the user and reduce friction from the authentication process, they plan to track physical attributes of an individual. A privacy technologist assessing privacy implications would be most interested in which of the following?
-
A
The purpose of the data tracking.
-
B
That the individual is aware tracking is occurring.
-
C
The authentication mechanism proposed.
-
D
The encryption of individual physical attributes.
Reveal answer details
Close answer details
Correct answerA
Explanationa privacy technologist assessing privacy implications would be most interested in the purpose of the data tracking.
Question 27
Single choice
SCENARIO Please use the following to answer the next question: Light Blue Health (LBH) is a healthcare technology company developing a new web and mobile application that collects personal health information from electronic patient health records. The application will use machine learning to recommend potential medical treatments and medications based on information collected from anonymized electronic health records. Patient users may also share health data collected from other mobile apps with the LBH app. The application requires consent from the patient before importing electronic health records into the application and sharing it with their authorized physicians or healthcare provider. The patient can then review and share the recommended treatments with their physicians securely through the app. The patient user may also share location data and upload photos in the app. The patient user may also share location data and upload photos in the app for a healthcare provider to review along with the health record. The patient may also delegate access to the app. LBH's privacy team meets with the Application development and Security teams, as well as key business stakeholders on a periodic basis. LBH also implements Privacy by Design (PbD) into the application development process. The Privacy Team is conducting a Privacy Impact Assessment (PIA) to evaluate privacy risks during development of the application. The team must assess whether the application is collecting descriptive, demographic or any other user related data from the electronic health records that are not needed for the purposes of the application. The team is also reviewing whether the application may collect additional personal data for purposes for which the user did not provide consent. The Privacy Team is conducting a Privacy Impact Assessment (PIA) for the new Light Blue Health application currently in development. Which of the following best describes a risk that is likely to result in a privacy breach?
-
A
Limiting access to the app to authorized personnel.
-
B
Including non-transparent policies, terms and conditions in the app.
-
C
Insufficiently deleting personal data after an account reaches its retention period.
-
D
Not encrypting the health record when it is transferred to the Light Blue Health servers.
Reveal answer details
Close answer details
Correct answerD
ExplanationNot encrypting health records when they are transferred to Light Blue Health servers can leave sensitive personal information vulnerable to interception and unauthorized access. This could result in a privacy breach if an attacker were able to access this unencrypted data.
Question 28
Single choice
Which of these is considered an ethical dark pattern on privacy?
-
A
Using attractive designs to influence an individual.
-
B
Rewarding users for providing more personal information
-
C
Giving users more privacy options in relation to their personal information
-
D
Providing dear and simple privacy notices to users
Reveal answer details
Close answer details
Correct answerB
Explanationrewarding users for providing more personal information is considered an unethical dark pattern on privacy. Dark patterns are user interface design choices that are intended to manipulate users into taking actions they might not otherwise take.
Question 29
Single choice
Value sensitive design focuses on which of the following?
-
A
-
B
-
C
Confidentiality and integrity.
-
D
Consent and human rights.
Reveal answer details
Close answer details
Question 30
Single choice
Which of the following is NOT a factor to consider in FAIR analysis?
-
A
The severity of the harm that might be caused by the privacy risk
-
B
The capability of a threat actor to exploit the analyzed privacy risk
-
C
The stage of the data life cycle in which the analyzed privacy risk occurs
-
D
The probability that a threat actor's attempts to exploit a privacy risk might succeed
Reveal answer details
Close answer details
Question 31
Single choice
An organization is deciding between building a solution in-house versus purchasing a solution for a new customer facing application. When security threats are taken into consideration, a key advantage of purchasing a solution would be the availability of?
-
A
Data Management and analytics.
-
B
Digital Rights Management.
-
C
Outsourcing of resources.
-
D
Reveal answer details
Close answer details
Question 32
Single choice
Organizations understand there are aggregation risks associated with the way the process their customer's data. They typically include the details of this aggregation risk in a privacy notice and ask that all customers acknowledge they understand these risks and consent to the processing. What type of risk response does this notice and consent represent?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Question 33
Single choice
Machine-learning based solutions present a privacy risk because?
-
A
Training data used during the training phase is compromised.
-
B
The solution may contain inherent bias from the developers.
-
C
The decision-making process used by the solution is not documented.
-
D
Machine-learning solutions introduce more vulnerabilities than other software.
Reveal answer details
Close answer details
Correct answerA
ExplanationMachine-learning based solutions present a privacy risk primarily due to the potential compromise of training data used during the training phase. This risk involves exposure or unauthorized access to sensitive or personal data that has been used to train the machine learning model. Such exposure can lead to privacy breaches and the leakage of personal information. Moreover, if the training data includes biased or sensitive information, it can also lead to biased model outputs, but the direct privacy risk comes from the potential exposure of the data itself.
Question 34
Single choice
One-way hash functions can be used is to?
-
A
Verify a password in a secure way.
-
B
Recover a credit card number at refund
-
C
Encrypt a document for confidentiality.
-
D
Secure an end-to-end communication.
Reveal answer details
Close answer details
Question 35
Single choice
Which is NOT a way to validate a person's identity?
-
A
Swiping a smartcard into an electronic reader.
-
B
Using a program that creates random passwords.
-
C
Answering a question about "something you know".
-
D
Selecting a picture and tracing a unique pattern on it
Reveal answer details
Close answer details
Question 36
Single choice
Information classification helps an organization protect confidential and nonpublic information primarily because?
-
A
It helps identify sensitive and critical information that require very strict safeguards.
-
B
It falls under the security principles of confidentiality, integrity, and availability.
-
C
It promotes employee accountability for safeguarding confidential information.
-
D
It is legally required under most regulations.
Reveal answer details
Close answer details
Correct answerA
ExplanationInformation classification helps an organization protect confidential and nonpublic information primarily because it helps identify sensitive and critical information that require very strict safeguards.
Question 37
Single choice
Which of the following modes of interaction often target both people who personally know and are strangers to the attacker?
-
A
-
B
-
C
Unsolicited sexual imagery.
-
D
Consensually-shared sexual imagery.
Reveal answer details
Close answer details
Question 38
Single choice
Which is NOT a drawback to using a biometric recognition system?
-
A
It can require more maintenance and support.
-
B
It can be more expensive than other systems
-
C
It has limited compatibility across systems.
-
D
It is difficult for people to use.
Reveal answer details
Close answer details
Question 39
Single choice
SCENARIO It should be the most secure location housing data in all of Europe, if not the world. The Global Finance Data Collective (GFDC) stores financial information and other types of client data from large banks, insurance companies, multinational corporations and governmental agencies. After a long climb on a mountain road that leads only to the facility, you arrive at the security booth. Your credentials are checked and checked again by the guard to visually verify that you are the person pictured on your passport and national identification card. You are led down a long corridor with server rooms on each side, secured by combination locks built into the doors. You climb a flight of stairs and are led into an office that is lighted brilliantly by skylights where the GFDC Director of Security, Dr. Monique Batch, greets you. On the far wall you notice a bank of video screens showing different rooms in the facility. At the far end, several screens show different sections of the road up the mountain Dr. Batch explains once again your mission. As a data security auditor and consultant, it is a dream assignment: The GFDC does not want simply adequate controls, but the best and most effective security that current technologies allow. "We were hacked twice last year," Dr. Batch says, "and although only a small number of records were stolen, the bad press impacted our business. Our clients count on us to provide security that is nothing short of impenetrable and to do so quietly. We hope to never make the news again." She notes that it is also essential that the facility is in compliance with all relevant security regulations and standards. You have been asked to verify compliance as well as to evaluate all current security controls and security measures, including data encryption methods, authentication controls and the safest methods for transferring data into and out of the facility. As you prepare to begin your analysis, you find yourself considering an intriguing question: Can these people be sure that I am who I say I am? You are shown to the office made available to you and are provided with system login information, including the name of the wireless network and a wireless key. Still pondering, you attempt to pull up the facility's wireless network, but no networks appear in the wireless list. When you search for the wireless network by name, however it is readily found. Why would you recommend that GFC use record encryption rather than disk, file or table encryption?
-
A
Record encryption is asymmetric, a stronger control measure.
-
B
Record encryption is granular, limiting the damage of potential breaches.
-
C
Record encryption involves tag masking, so its metadata cannot be decrypted
-
D
Record encryption allows for encryption of personal data only.
Reveal answer details
Close answer details
Correct answerB
ExplanationRecord encryption is granular, limiting the damage of potential breaches. Record encryption encrypts data at the record level, providing a more granular level of protection than disk, file or table encryption. This means that even if a breach were to occur, only the specific records that were accessed would be compromised.
Question 40
Single choice
Which of the following is the most important action to take prior to collecting personal data directly from a customer?
-
A
Define what data needs to be collected.
-
B
Define the purpose for collecting and using the data.
-
C
Identify business requirements for the data that will be collected.
-
D
Provide individuals with information about how their data will be used after collection.
Reveal answer details
Close answer details
Question 41
Single choice
The increase in remote working has resulted in greater use of videoconferencing by companies. When assessing the privacy risk from implementing and enabling recording functionality of video conferencing software, which of the following would a privacy technologist most likely require of the software?
-
A
That encryption is used for storage of the video recording data.
-
B
That the meeting recording can only be accessed by the attendees.
-
C
That there is a noticeable indication to all attendees when recording is active.
-
D
That the geographical location of the attendees is logged for compliance purposes.
Reveal answer details
Close answer details
Question 42
Single choice
Which of the following methods does NOT contribute to keeping the data confidential?
-
A
-
B
-
C
-
D
Reveal answer details
Close answer details
Correct answerD
Explanationreferential integrity does not contribute to keeping the data confidential.
|