Skip to main content

DCPP-01 Real Exam Questions

DSCI certified Privacy Professional (DCPP)

162 questions available · Page 1 of 17

Updated Exam DumpsVerified AnswersPass Guarantee

Get Complete Exam Dumps
Question 1 Single choice

Data processing includes which of the following operations:

  1. A

    Collecting

  2. B

    Transmitting

  3. C

    Storing

  4. D

    Disclosing

  5. E

    All of the above

Show answer and explanation

Correct answer: C

Question 2 Single choice

What is the standard definition for Data Controller?

  1. A

    One who necessarily collects the data

  2. B

    One who stores the data

  3. C

    One who determines the purpose and means of processing

  4. D

    One who shares the data with third parties

Show answer and explanation

Correct answer: C

Question 3 Single choice

Privacy enhancing tools aim to allow users to take one or more of the following actions related to their personal data that is sent to, and used by online service providers, merchants or other users:

i. Increase control over their personal data ii. Choose whether to use services anonymously or not
iii. Obtain informed consent about sharing their personal data
iv. Opt-out of behavioral advertising or any other use of data

Please select correct option from below:

  1. A

    Only i

  2. B

    Only i and ii

  3. C

    All

  4. D

    Only ii

Show answer and explanation

Correct answer: C

Question 4 Single choice

Which of the following wasn't prescribed as a privacy principle under the OECD Privacy Guidelines, 1980?

  1. A

    Openness

  2. B

    Data minimization

  3. C

    Security Safeguard

  4. D

    Purpose Specification

Show answer and explanation

Correct answer: B

Question 5 Single choice

A multinational company with operations in several parts within EU and outside EU, involves international data transfer of both its employees and customers. In some of its EU branches, which are relatively larger in size, the organization has a works council. Most of the data transferred is personal, and some of the data that the organization collects is sensitive in nature, the processing of some of which is also outsourced to its branches in Asian countries.

For the outsourced work of its customers' data processing, in order to initiate data transfer to another organizations outside EU, which is the most appropriate among the following?

  1. A

    The vendor (data importer) in the third country, and not the exporter is responsible to put in place

    suitable model contractual clauses, and hence the exporter does not need to take any action.

  2. B

    Since the data is processed by the vendor outside the EU, the EU directive does not apply and hence there are no legal concerns

  3. C

    The data exporter needs to initiate model contractual clauses after obtaining approvals from data protection commissioner and have the vendor be a signatory on the same as data importer

  4. D

    The data importer need to notify about the transfer to data protection commissioner in the destination country and exporter need to similarly notify in the EU country of origin

Show answer and explanation

Correct answer: D

Question 6 Single choice

Which of the following does not fall under the category of Personal Financial Information (PFI)?

  1. A

    Credit card number with expiry date

  2. B

    Bank account Information

  3. C

    Loan account Information

  4. D

    Income tax return file acknowledgement number

Show answer and explanation

Correct answer: D

Question 7 Single choice

BS 10012 is a British standard used to establish ___________.

  1. A

    Personal information management system

  2. B

    Privacy technology architecture

  3. C

    Privacy reference architecture

  4. D

    Privacy by design framework

Show answer and explanation

Correct answer: A

Question 8 Single choice

Which of the following countries mandates localization of all personal data?

  1. A

    USA

  2. B

    Russia

  3. C

    India

  4. D

    Germany

Show answer and explanation

Correct answer: B

Question 9 Single choice

Which of the following statements is true with respect to organization's privacy training and awareness program?

  1. A

    Should define roles and responsibilities of personnel in privacy function

  2. B

    Should cover employees of service provider dealing with personal information

  3. C

    Should necessarily cover official from Law Enforcement Agencies that request lawful access to personal information

  4. D

    None of the above

Show answer and explanation

Correct answer: A

Question 10 Single choice

Which of the following term is commonly used to refer to a solution that protects users' right to choose whether their activities can be monitored by third-party websites or not:

  1. A

    Do not Disturb

  2. B

    Do not Record

  3. C

    Do not Track

  4. D

    Do not Follow

Show answer and explanation

Correct answer: C