Complete list of current Q & A>> Download IAPP Certified Information Privacy Manager (IAPP-CIPM) – Quiz 1 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) What should a privacy professional keep in mind when selecting which metrics to collect? A. Metrics should be reported to the public. B. The number of metrics should be limited at first. C. Metrics should reveal strategies for increasing company earnings. D. A variety of metrics should be collected before determining their specific functions. 2 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) Which is TRUE about the scope and authority of data protection oversight authorities? A. The Office of the Privacy Commissioner (OPC) of Canada has the right to impose financial sanctions on violators. B. All authority in the European Union rests with the Data Protection Commission (DPC). C. No one agency officially oversees the enforcement of privacy regulations in the United States. D. The Asia-Pacific Economic Cooperation (APEC) Privacy Frameworks require all member nations to designate a national data protection authority. 3 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) What should be the first major goal of a company developing a new privacy program? A. To survey potential funding sources for privacy team resources. B. To schedule conversations with executives of affected departments. C. To identify potential third-party processors of the organization's information. D. To create Data Lifecycle Management policies and procedures to limit data collection. 4 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) Which of the following best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor? A. Employees must sign an ad hoc contractual agreement each time personal data is exported. B. All employees are subject to the rules in their entirety, regardless of where the work is taking place. C. All employees must follow the privacy regulations of the jurisdictions where the current scope of their work is established. D. Employees who control personal data must complete a rigorous certification procedure, as they are exempt from legal enforcement. 5 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) In privacy protection, what is a “covered entity”? A. Personal data collected by a privacy organization. B. An organization subject to the privacy provisions of the Health Insurance Portability and Accountability Act (HIPAA). C. A privacy office or team fully responsible for protecting personal information. D. Hidden gaps in privacy protection that may go unnoticed without expert analysis 6 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) As a Data Protection Officer (DPO), one of your roles entails monitoring changes in laws and regulations and updating policies accordingly. How would you most effectively execute this responsibility? A. Consult an external lawyer. B. Regularly engage regulators. C. Attend workshops and interact with other professionals. C. Attend workshops and interact with other professionals. D. Subscribe to email list-serves that report on regulatory changes 7 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) Which of the following is TRUE about the Data Protection Impact Assessment (DPIA) process as required under the General Data Protection Regulation (GDPR)? A. The DPIA result must be reported to the corresponding supervisory authority. B. The DPIA report must be published to demonstrate the transparency of the data processing. C. The DPIA must include a description of the proposed processing operation and its purpose. D. The DPIA is required if the processing activity entails risk to the rights and freedoms of an EU individual 8 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) What is the main function of the Asia-Pacific Economic Cooperation Privacy Framework? A. Enabling regional data transfers. B. Protecting data from parties outside the region. C. Establishing legal requirements for privacy protection in the region. D. Marketing privacy protection technologies developed in the region 9 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) Why were the nongovernmental privacy organizations, Electronic Frontier Foundation (EFF) and Electronic Privacy Information Center (EPIC), established? A. To promote consumer confidence in the Internet industry. B. To improve the user experience during online shopping. C. To protect civil liberties and raise consumer awareness. D. To promote security on the Internet through strong encryption. 10 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) An organization’s privacy officer was just notified by the benefits manager that she accidentally sent out the retirement enrollment report of all employees to a wrong vendor. Which of the following actions should the privacy officer take first? A. Perform a risk of harm analysis. B. Report the incident to law enforcement. C. Contact the recipient to delete the email. D. Send firm-wide email notification to employees. 11 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) Which statement is FALSE regarding the use of technical security controls? A. Technical security controls are part of a data governance strategy. B. Technical security controls deployed for one jurisdiction often satisfy another jurisdiction. C. Most privacy legislation lists the types of technical security controls that must be implemented. D. A person with security knowledge should be involved with the deployment of technical security controls 12 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) What is the best way to understand the location, use and importance of personal data within an organization? A. By analyzing the data inventory. B. By testing the security of data systems C. By evaluating methods for collecting data. D. By interviewing employees tasked with data entry. 13 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) What are you doing if you succumb to “overgeneralization” when analyzing data from metrics? A. Using data that is too broad to capture specific meanings. B. Possessing too many types of data to perform a valid analysis. C. Using limited data in an attempt to support broad conclusions. D. Trying to use several measurements to gauge one aspect of a program. 14 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) In addition to regulatory requirements and business practices, what important factors must a global privacy strategy consider? A. Monetary exchange. B. Geographic features. C. Political history. D. Cultural norms. 15 / 15 Category: IAPP Certified Information Privacy Manager (IAPP-CIPM) What have experts identified as an important trend in privacy program development? A. The narrowing of regulatory definitions of personal information. B. The rollback of ambitious programs due to budgetary restraints. C. The movement beyond crisis management to proactive prevention. D. The stabilization of programs as the pace of new legal mandates slows. Your score is 0% Restart quiz Send feedback