CIPT Practice Exam Tests Latest Updated on Aug-2021
Pass CIPT Exam in First Attempt Guaranteed Dumps!
NEW QUESTION 74
SCENARIO - Please use the following to answer the next question:
Carol was a US-based glassmaker who sold her work at art festivals. She kept things simple by only accepting cash and personal checks.
As business grew, Carol couldn't keep up with demand, and traveling to festivals became burdensome. Carol opened a small boutique and hired Sam to run it while she worked in the studio. Sam was a natural salesperson, and business doubled. Carol told Sam, :'l don't know what you are doing, but keep doing it; But months later, the gift shop was in chaos. Carol realized that Sam needed help so she hired Jane, who had business expertise and could handle the back-office tasks. Sam would continue to focus on sales. Carol gave Jane a few weeks to get acquainted with the artisan craft business, and then scheduled a meeting for the three of them to discuss Jane s first impressions.
At the meeting, Carol could not wait to hear Jane s thoughts, but she was unprepared for what Jane had to say.
"Carol. I know that he doesn't realize it, but some of Sam s efforts to increase sales have put you in a vulnerable position. You are not protecting customers personal information like you should." Sam said, :'l am protecting our information. I keep it in the safe with our bank deposit. It's only a list of customers names, addresses and phone numbers that I get from their checks before I deposit them. I contact them when you finish a piece that I think they would like. That's the only information I have! The only other thing I do is post photos and information about your work on the photo sharing site that I use with family and friends. I provide my email address and people send me their information if they want to see more of your work. Posting online really helps sales, Carol. In fact, the only complaint I hear is about having to come into the shop to make a purchase." Carol replied, "Jane, that doesn't sound so bad. Could you just fix things and help us to post even more online?"
''I can," said Jane. "But it's not quite that simple. I need to set up a new program to make sure that we follow the best practices in data management. And I am concerned for our customers. They should be able to manage how we use their personal information. We also should develop a social media strategy" Sam and Jane worked hard during the following year. One of the decisions they made was to contract with an outside vendor to manage online sales. At the end of the year Carol shared some exciting news. ''Sam and Jane, you have done such a great job that one of the biggest names in the glass business wants to buy us out!
And Jane, they want to talk to you about merging all of our customer and vendor information with theirs beforehand " What type of principles would be the best guide for Jane s ideas regarding a new data management program?
- A. Fair Information Practice Principles.
- B. Incident preparedness principles.
- C. Collection limitation principles.
- D. Vendor management principles.
Answer: C
NEW QUESTION 75
After downloading and loading a mobile app, the user is presented with an account registration page requesting the user to provide certain personal details. Two statements are also displayed on the same page along with a box for the user to check to indicate their confirmation:
Statement 1 reads: "Please check this box to confirm you have read and accept the terms and conditions of the end user license agreement" and includes a hyperlink to the terms and conditions.
Statement 2 reads: "Please check this box to confirm you have read and understood the privacy notice" and includes a hyperlink to the privacy notice.
Under the General Data Protection Regulation (GDPR), what lawful basis would you primarily except the privacy notice to refer to?
- A. Consent.
- B. Legal obligation.
- C. Legitimate interests.
- D. Vital interests.
Answer: A
NEW QUESTION 76
SCENARIO
WebTracker Limited is a cloud-based online marketing service located in London. Last year, WebTracker migrated its IT infrastructure to the cloud provider AmaZure, which provides SQL Databases and Artificial Intelligence services to WebTracker. The roles and responsibilities between the two companies have been formalized in a standard contract, which includes allocating the role of data controller to WebTracker.
The CEO of WebTracker, Mr. Bond, would like to assess the effectiveness of AmaZure's privacy controls, and he recently decided to hire you as an independent auditor. The scope of the engagement is limited only to the marketing services provided by WebTracker, you will not be evaluating any internal data processing activity, such as HR or Payroll.
This ad-hoc audit was triggered due to a future partnership between WebTracker and SmartHome - a partnership that will not require any data sharing. SmartHome is based in the USA, and most recently has dedicated substantial resources to developing smart refrigerators that can suggest the recommended daily calorie intake based on DNA information. This and other personal data is collected by WebTracker.
To get an idea of the scope of work involved, you have decided to start reviewing the company's documentation and interviewing key staff to understand potential privacy risks.
The results of this initial work include the following notes:
* There are several typos in the current privacy notice of WebTracker, and you were not able to find the privacy notice for SmartHome.
* You were unable to identify all the sub-processors working for SmartHome. No subcontractor is indicated in the cloud agreement with AmaZure, which is responsible for the support and maintenance
* of the cloud infrastructure.
* There are data flows representing personal data being collected from the internal employees of WebTracker, including an interface from the HR system.
* Part of the DNA data collected by WebTracker was from employees, as this was a prototype approved by the CEO of WebTracker.
* All the WebTracker and SmartHome customers are based in USA and Canada.
Based on the initial assessment and review of the available data flows, which of the following would be the most important privacy risk you should investigate first?
- A. Review the list of subcontractors employed by AmaZure and ensure these are included in the formal agreement with WebTracker.
- B. Confirm whether the data transfer from London to the USA has been fully approved by AmaZure and the appropriate institutions in the USA and the European Union.
- C. Evaluate and review the basis for processing employees' personal data in the context of the prototype created by WebTracker and approved by the CEO.
- D. Verify that WebTracker's HR and Payroll systems implement the current privacy notice (after the typos are fixed).
Answer: C
NEW QUESTION 77
What distinguishes a "smart" device?
- A. It is programmable by a user without specialized training.
- B. It can perform multiple data functions simultaneously.
- C. It can reapply access controls stored in its internal memory.
- D. It augments its intelligence with information from the internet.
Answer: D
NEW QUESTION 78
What must be done to destroy data stored on "write once read many" (WORM) media?
- A. The media must be reformatted.
- B. The media must be physically destroyed.
- C. The erase function must be used to remove all data.
- D. The data must be made inaccessible by encryption.
Answer: D
NEW QUESTION 79
SCENARIO
Clean-Q is a company that offers house-hold and office cleaning services. The company receives requests from consumers via their website and telephone, to book cleaning services. Based on the type and size of service, Clean-Q then contracts individuals that are registered on its resource database - currently managed in-house by Clean-Q IT Support. Because of Clean-Q's business model, resources are contracted as needed instead of permanently employed.
The table below indicates some of the personal information Clean-Q requires as part of its business operations:
Clean-Q has an internal employee base of about 30 people. A recent privacy compliance exercise has been conducted to align employee data management and human resource functions with applicable data protection regulation. Therefore, the Clean-Q permanent employee base is not included as part of this scenario.
With an increase in construction work and housing developments, Clean-Q has had an influx of requests for cleaning services. The demand has overwhelmed Clean-Q's traditional supply and demand system that has caused some overlapping bookings.
Ina business strategy session held by senior management recently, Clear-Q invited vendors to present potential solutions to their current operational issues. These vendors included Application developers and Cloud-Q's solution providers, presenting their proposed solutions and platforms.
The Managing Director opted to initiate the process to integrate Clean-Q's operations with a cloud solution (LeadOps) that will provide the following solution one single online platform: A web interface that Clean-Q accesses for the purposes of resource and customer management. This would entail uploading resource and customer information.
A customer facing web interface that enables customers to register, manage and submit cleaning service requests online.
A resource facing web interface that enables resources to apply and manage their assigned jobs.
An online payment facility for customers to pay for services.
Considering that LeadOps will host/process personal information on behalf of Clean-Q remotely, what is an appropriate next step for Clean-Q senior management to assess LeadOps' appropriateness?
- A. Involve the Information Security team to understand in more detail the types of services and solutions LeadOps is proposing.
- B. Nothing at this stage as the Managing Director has made a decision.
- C. Determine if any Clean-Q competitors currently use LeadOps as a solution.
- D. Obtain a legal opinion from an external law firm on contracts management.
Answer: A
NEW QUESTION 80
How should the sharing of information within an organization be documented?
- A. With a memorandum of agreement.
- B. With a disclosure statement.
- C. With a data flow diagram.
- D. With a binding contract.
Answer: B
NEW QUESTION 81
Properly configured databases and well-written website codes are the best protection against what online threat?
- A. SQL injection.
- B. System modification.
- C. Pharming.
- D. Malware execution.
Answer: A
NEW QUESTION 82
SCENARIO
Wesley Energy has finally made its move, acquiring the venerable oil and gas exploration firm Lancelot from its long-time owner David Wilson. As a member of the transition team, you have come to realize that Wilson's quirky nature affected even Lancelot's data practices, which are maddeningly inconsistent. "The old man hired and fired IT people like he was changing his necktie," one of Wilson's seasoned lieutenants tells you, as you identify the traces of initiatives left half complete.
For instance, while some proprietary data and personal information on clients and employees is encrypted, other sensitive information, including health information from surveillance testing of employees for toxic exposures, remains unencrypted, particularly when included within longer records with less-sensitive dat a. You also find that data is scattered across applications, servers and facilities in a manner that at first glance seems almost random.
Among your preliminary findings of the condition of data at Lancelot are the following:
Cloud technology is supplied by vendors around the world, including firms that you have not heard of. You are told by a former Lancelot employee that these vendors operate with divergent security requirements and protocols.
The company's proprietary recovery process for shale oil is stored on servers among a variety of less-sensitive information that can be accessed not only by scientists, but by personnel of all types at most company locations.
DES is the strongest encryption algorithm currently used for any file.
Several company facilities lack physical security controls, beyond visitor check-in, which familiar vendors often bypass.
Fixing all of this will take work, but first you need to grasp the scope of the mess and formulate a plan of action to address it.
Which is true regarding the type of encryption Lancelot uses?
- A. It employs the data scrambling technique known as obfuscation.
- B. It is a data masking methodology.
- C. It uses a single key for encryption and decryption.
- D. Its decryption key is derived from its encryption key.
Answer: A
NEW QUESTION 83
What term describes two re-identifiable data sets that both come from the same unidentified individual?
- A. Aggregated data.
- B. Pseudonymous data.
- C. Anonymous data.
- D. Imprecise data.
Answer: A
NEW QUESTION 84
What is the most important requirement to fulfill when transferring data out of an organization?
- A. Extending the data retention schedule as needed.
- B. Ensuring the organization receiving the data performs a privacy impact assessment.
- C. Ensuring the commitments made to the data owner are followed.
- D. Ensuring the organization sending the data controls how the data is tagged by the receiver.
Answer: D
NEW QUESTION 85
A privacy engineer reviews a newly developed on-line registration page on a company's website. The purpose of the page is to enable corporate customers to submit a returns / refund request for physical goods. The page displays the following data capture fields: company name, account reference, company address, contact name, email address, contact phone number, product name, quantity, issue description and company bank account details.
After her review, the privacy engineer recommends setting certain capture fields as "non-mandatory". Setting which of the following fields as "non-mandatory" would be the best example of the principle of data minimization?
- A. The company bank account detail field.
- B. The contact phone number field.
- C. The company address and name.
- D. The contact name and email address.
Answer: C
NEW QUESTION 86
Which of the following is NOT relevant to a user exercising their data portability rights?
- A. Validation of users with unauthenticated identifiers (e.g. IP address, physical address).
- B. Notice and consent for the downloading of data.
- C. Re-authentication of an account, including two-factor authentication as appropriate.
- D. Detection of phishing attacks against the portability interface.
Answer: A
NEW QUESTION 87
During a transport layer security (TLS) session, what happens immediately after the web browser creates a random PreMasterSecret?
- A. The server decrypts the PremasterSecret.
- B. The web browser encrypts the PremasterSecret with the server's public key.
- C. The web browser opens a TLS connection to the PremasterSecret.
- D. The server and client use the same algorithm to convert the PremasterSecret into an encryption key.
Answer: B
Explanation:
Explanation/Reference: https://books.google.com.pk/books?id=OaXise4B-p8C&pg=PA175&lpg=PA175&dq=iapp+During+a
+transport+layer+security+(TLS)+session,+what+happens+immediately+after+the+web+browser+creates+a
+random
+PreMasterSecret&source=bl&ots=zR0RCfnx3c&sig=ACfU3U0bTOeOfPfcoq_Y95SZs6imKKilug&hl=en&sa=X
&ved=2ahUKEwjkscDHpcbnAhUJuRoKHU5iC9cQ6AEwCnoECAkQAQ#v=onepage&q=iapp%20During%20a
%20transport%20layer%20security%20(TLS)%20session%2C%20what%20happens%20immediately%20after
%20the%20web%20browser%20creates%20a%20random%20PreMasterSecret&f=false
NEW QUESTION 88
What can be used to determine the type of data in storage without exposing its contents?
- A. Data mapping.
- B. Collection records.
- C. Server logs.
- D. Metadata.
Answer: D
NEW QUESTION 89
What is typically NOT performed by sophisticated Access Management (AM) techniques?
- A. Preventing data from being placed in unprotected storage.
- B. Restricting access to data based on location.
- C. Restricting access to data based on user role.
- D. Preventing certain types of devices from accessing data.
Answer: C
NEW QUESTION 90
A valid argument against data minimization is that it?
- A. Decreases the speed of data transfers.
- B. Increases the chance that someone can be identified from data.
- C. Can have an adverse effect on data quality.
- D. Can limit business opportunities.
Answer: D
NEW QUESTION 91
Which is the most accurate type of biometrics?
- A. Voiceprint.
- B. Facial recognition.
- C. Fingerprint.
- D. DNA
Answer: A
NEW QUESTION 92
Which of the following became a foundation for privacy principles and practices of countries and organizations across the globe?
- A. The Organization for Economic Co-operation and Development (OECD) Privacy Principles.
- B. The EU Data Protection Directive.
- C. The Personal Data Ordinance.
- D. The Code of Fair Information Practices.
Answer: A
Explanation:
Explanation/Reference: https://privacyrights.org/resources/review-fair-information-principles-foundation-privacy-public- policy
NEW QUESTION 93
How does k-anonymity help to protect privacy in micro data sets?
- A. By switching values between records in order to preserve most statistics while still maintaining privacy.
- B. By top-coding all age data above a value of "k."
- C. By adding sufficient noise to the data in order to hide the impact of any one individual.
- D. By ensuring that every record in a set is part of a group of "k" records having similar identifying information.
Answer: D
NEW QUESTION 94
......
Information Privacy Technologist Free Certification Exam Material from PrepAwayETE with 148 Questions: https://www.prepawayete.com/IAPP/CIPT-practice-exam-dumps.html
CIPT Dumps Full Questions - Exam Study Guide: https://drive.google.com/open?id=1WC6TBVYIY-_uliFbOOi1h-O0UOzAJMig