Skip to main content

CIPP-C Real Exam Questions

Certified Information Privacy Professional/ Canada (CIPP/C)

226 questions available · Page 1 of 23

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

SCENARIO

Please use the following to answer the next QUESTION

When there was a data breach involving customer personal and financial information at a large retail store, the company's directors were shocked. However, Roberta, a privacy analyst at the company and a victim of identity theft herself, was not. Prior to the breach, she had been working on a privacy program report for the executives. How the company shared and handled data across its organization was a major concern.
There were neither adequate rules about access to customer information nor procedures for purging and destroying outdated data. In her research, Roberta had discovered that even low-level employees had access to all of the company's customer data, including financial records, and that the company still had in its possession obsolete customer data going back to the 1980s.

Her report recommended three main reforms. First, permit access on an as-needs-to-know basis. This would mean restricting employees' access to customer information to data that was relevant to the work performed. Second, create a highly secure database for storing customers' financial information (e.g., credit card and bank account numbers) separate from less sensitive information. Third, identify outdated customer information and then develop a process for securely disposing of it.

When the breach occurred, the company's executives called Roberta to a meeting where she presented the recommendations in her report. She explained that the company having a national customer base meant it would have to ensure that it complied with all relevant state breach notification laws. Thanks to Roberta's guidance, the company was able to notify customers quickly and within the specific timeframes set by state breach notification laws.

Soon after, the executives approved the changes to the privacy program that Roberta recommended in her report. The privacy program is far more effective now because of these changes and, also, because privacy and security are now considered the responsibility of every employee.

Which principle of the Consumer Privacy Bill of Rights, if adopted, would best reform the company's privacy program?

  1. A

    Consumers have a right to exercise control over how companies use their personal data.

  2. B

    Consumers have a right to reasonable limits on the personal data that a company retains.

  3. C

    Consumers have a right to easily accessible information about privacy and security practices.

  4. D

    Consumers have a right to correct personal data in a manner that is appropriate to the sensitivity.

Show answer and explanation

Correct answer: B

Question 2 Single choice

According to PIPEDA, all of the following data is considered sensitive: physical disability, ethnicity, sexual orientation and?

  1. A

    Age

  2. B

    Gender

  3. C

    Locality

  4. D

    Religion

Show answer and explanation

Correct answer: D

Question 3 Single choice

What important action should a health care provider take if the she wants to qualify for funds under the Health Information Technology for Economic and Clinical Health Act (HITECH)?

  1. A

    Make electronic health records (EHRs) part of regular care

  2. B

    Bill the majority of patients electronically for their health care

  3. C

    Send health information and appointment reminders to patients electronically

  4. D

    Keep electronic updates about the Health Insurance Portability and Accountability Act

Show answer and explanation

Correct answer: A

Question 4 Single choice

Which federal act does NOT contain provisions for preempting stricter state laws?

  1. A

    The CAN-SPAM Act

  2. B

    The Children's Online Privacy Protection Act (COPPA)

  3. C

    The Fair and Accurate Credit Transactions Act (FACTA)

  4. D

    The Telemarketing Consumer Protection and Fraud Prevention Act

Show answer and explanation

Correct answer: D

Question 5 Single choice

What is the main reason a country might adopt an "ombudsman" model of privacy oversight?

  1. A

    It provides a more streamlined process of complaint resolution.

  2. B

    It increases the power of the commissioner to enforce decisions.

  3. C

    It reduces the perception that compliance is a confrontational process.

  4. D

    It provides a more detailed set of guidelines regarding possible violations.

Show answer and explanation

Correct answer: C

Question 6 Single choice

What is critical to consider when an organization responsible for a large number of records wants to outsource the storage of those records?

  1. A

    Determining if the personal information stored on the records will be used for data matching.

  2. B

    Putting into place a contractual agreement between the organization and the records storage company.

  3. C

    Conducting a Privacy Impact Assessment (PIA) prior to establishing a relationship with the storage company.

  4. D

    Establishing that consent gathered from individuals by the organization in order to store their personal information was informed and meaningful.

Show answer and explanation

Correct answer: B

Question 7 Single choice

US.
federal laws protect individuals from employment discrimination based on all of the following EXCEPT?

  1. A

    Age.

  2. B

    Pregnancy.

  3. C

    Marital status.

  4. D

    Genetic information.

Show answer and explanation

Correct answer: B

Question 8 Single choice

Under the Personal Information Protection and Electronic Documents Act (PIPEDA), an organization must maintain a record of every breach of security safeguards involving personal information for a minimum of?

  1. A

    3 months.

  2. B

    12 months.

  3. C

    24 months.

  4. D

    36 months.

Show answer and explanation

Correct answer: C

Question 9 Single choice

Which of the following became the first state to pass a law specifically regulating the collection of biometric data?

  1. A

    California.

  2. B

    Texas.

  3. C

    Illinois.

  4. D

    Washington.

Show answer and explanation

Correct answer: C

Question 10 Single choice

The Cable Communications Policy Act of 1984 requires which activity?

  1. A

    Delivery of an annual notice detailing how subscriber information is to be used

  2. B

    Destruction of personal information a maximum of six months after it is no longer needed

  3. C

    Notice to subscribers of any investigation involving unauthorized reception of cable services

  4. D

    Obtaining subscriber consent for disseminating any personal information necessary to render cable services

Show answer and explanation

Correct answer: C