IAPP CIPT - Certified Information Privacy Technologist (CIPT) Exam

Question #6 (Topic: Single Topic)
A key principle of an effective privacy policy is that it should be?
A. Written in enough detail to cover the majority of likely scenarios. B. Made general enough to maximize flexibility in its application. C. Presented with external parties as the intended audience. D. Designed primarily by the organization's lawyers.
Answer: A
Question #7 (Topic: Single Topic)
What was the first privacy framework to be developed?
A. OECD Privacy Principles. B. Generally Accepted Privacy Principles. C. Code of Fair Information Practice Principles (FIPPs). D. The Asia-Pacific Economic Cooperation (APEC) Privacy Framework.
Answer: C
Question #8 (Topic: Single Topic)
Which of the following became a foundation for privacy principles and practices of countries and organizations across the globe?
A. The Personal Data Ordinance. B. The EU Data Protection Directive. C. The Code of Fair Information Practices. D. The Organization for Economic Co-operation and Development (OECD) Privacy Principles.
Answer: D
Question #9 (Topic: Single Topic)
SCENARIO
Kyle is a new security compliance manager who will be responsible for coordinating and executing controls to ensure compliance with the company's information
security policy and industry standards. Kyle is also new to the company, where collaboration is a core value. On his first day of new-hire orientation, Kyle's
schedule included participating in meetings and observing work in the IT and compliance departments.
Kyle spent the morning in the IT department, where the CIO welcomed him and explained that her department was responsible for IT governance. The CIO and
Kyle engaged in a conversation about the importance of identifying meaningful IT governance metrics. Following their conversation, the CIO introduced Kyle to
Ted and Barney. Ted is implementing a plan to encrypt data at the transportation level of the organization's wireless network. Kyle would need to get up to speed
on the project and suggest ways to monitor effectiveness once the implementation was complete. Barney explained that his short-term goals are to establish rules
governing where data can be placed and to minimize the use of offline data storage.
Kyle spent the afternoon with Jill, a compliance specialist, and learned that she was exploring an initiative for a compliance program to follow self-regulatory
privacy principles. Thanks to a recent internship, Kyle had some experience in this area and knew where Jill could find some support. Jill also shared results of the
company's privacy risk assessment, noting that the secondary use of personal information was considered a high risk.
By the end of the day, Kyle was very excited about his new job and his new company. In fact, he learned about an open position for someone with strong
qualifications and experience with access privileges, project standards board approval processes, and application-level obligations, and couldn't wait to
recommend his friend Ben who would be perfect for the job.
Ted's implementation is most likely a response to what incident?
A. Encryption keys were previously unavailable to the organization's cloud storage host. B. Signatureless advanced malware was detected at multiple points on the organization's networks. C. Cyber criminals accessed proprietary data by running automated authentication attacks on the organization's network. D. Confidential information discussed during a strategic teleconference was intercepted by the organization's top competitor.
Answer: D
Question #10 (Topic: Single Topic)
SCENARIO
Kyle is a new security compliance manager who will be responsible for coordinating and executing controls to ensure compliance with the company's information
security policy and industry standards. Kyle is also new to the company, where collaboration is a core value. On his first day of new-hire orientation, Kyle's
schedule included participating in meetings and observing work in the IT and compliance departments.
Kyle spent the morning in the IT department, where the CIO welcomed him and explained that her department was responsible for IT governance. The CIO and
Kyle engaged in a conversation about the importance of identifying meaningful IT governance metrics. Following their conversation, the CIO introduced Kyle to
Ted and Barney. Ted is implementing a plan to encrypt data at the transportation level of the organization's wireless network. Kyle would need to get up to speed
on the project and suggest ways to monitor effectiveness once the implementation was complete. Barney explained that his short-term goals are to establish rules
governing where data can be placed and to minimize the use of offline data storage.
Kyle spent the afternoon with Jill, a compliance specialist, and learned that she was exploring an initiative for a compliance program to follow self-regulatory
privacy principles. Thanks to a recent internship, Kyle had some experience in this area and knew where Jill could find some support. Jill also shared results of the
company's privacy risk assessment, noting that the secondary use of personal information was considered a high risk.
By the end of the day, Kyle was very excited about his new job and his new company. In fact, he learned about an open position for someone with strong
qualifications and experience with access privileges, project standards board approval processes, and application-level obligations, and couldn't wait to
recommend his friend Ben who would be perfect for the job.
Which of the following should Kyle recommend to Jill as the best source of support for her initiative?
A. Investors. B. Regulators. C. Industry groups. D. Corporate researchers.
Answer: C
Download Exam
Page: 2 / 57
Total 285 questions