CIPM Exam Questions
295 real CIPM exam questions with expert-verified answers and explanations. Page 1 of 6.
- Question #1
As a Data Protection Officer (DPO), one of your roles entails monitoring changes in laws and regulations and updating policies accordingly. How would you most effectively execute t...
- Question #2
SCENARIO Please use the following to answer the next question: John is the new privacy officer at the prestigious international law firm - A&M LLP. A&M LLP is very proud of its rep...
- Question #3
SCENARIO Please use the following to answer the next question: John is the new privacy officer at the prestigious international law firm - A&M LLP. A&M LLP is very proud of its rep...
- Question #4
SCENARIO Please use the following to answer the next question: Richard McAdams recently graduated law school and decided to return to the small town of Lexington, Virginia to help...
- Question #5
SCENARIO Please use the following to answer the next question: Richard McAdams recently graduated law school and decided to return to the small town of Lexington, Virginia to help...
- Question #6
SCENARIO Please use the following to answer the next question: Richard McAdams recently graduated law school and decided to return to the small town of Lexington, Virginia to help...
- Question #7
What should be the first major goal of a company developing a new privacy program?
- Question #8
Which is TRUE about the scope and authority of data protection oversight authorities?
- Question #9
What should a privacy professional keep in mind when selecting which metrics to collect?
- Question #10
SCENARIO Please use the following to answer the next question: Amira is thrilled about the sudden expansion of NatGen. As the joint Chief Executive Officer (CEO) with her long-time...
- Question #11
SCENARIO Please use the following to answer the next question: Amira is thrilled about the sudden expansion of NatGen. As the joint Chief Executive Officer (CEO) with her long-time...
- Question #12
SCENARIO Please use the following to answer the next question: Amira is thrilled about the sudden expansion of NatGen. As the joint Chief Executive Officer (CEO) with her long-time...
- Question #13
SCENARIO Please use the following to answer the next question: Amira is thrilled about the sudden expansion of NatGen. As the joint Chief Executive Officer (CEO) with her long-time...
- Question #14
If an organization maintains a separate ethics office, to whom would its officer typically report to in order to retain the greatest degree of independence?
- Question #15
What is a key feature of the privacy metric template adapted from the National Institute of Standards and Technology (NIST)?
- Question #16
What United States federal law requires financial institutions to declare their personal data collection practices?
- Question #17
SCENARIO Please use the following to answer the next question: As the Director of data protection for Consolidated Records Corporation, you are justifiably pleased with your accomp...
- Question #18
SCENARIO Please use the following to answer the next question: As the Director of data protection for Consolidated Records Corporation, you are justifiably pleased with your accomp...
- Question #19
SCENARIO Please use the following to answer the next question: As the Director of data protection for Consolidated Records Corporation, you are justifiably pleased with your accomp...
- Question #20
SCENARIO Please use the following to answer the next question: As the Director of data protection for Consolidated Records Corporation, you are justifiably pleased with your accomp...
- Question #21
SCENARIO Please use the following to answer the next question: As the Director of data protection for Consolidated Records Corporation, you are justifiably pleased with your accomp...
- Question #22
SCENARIO Please use the following to answer the next question: As the Director of data protection for Consolidated Records Corporation, you are justifiably pleased with your accomp...
- Question #23
Which of the following indicates you have developed the right privacy framework for your organization?
- Question #24
Rationalizing requirements in order to comply with the various privacy requirements required by applicable law and regulation does NOT include which of the following?
- Question #25
What is the name for the privacy strategy model that describes delegated decision making?
- Question #26
Which of the following controls does the PCI DSS framework NOT require?
- Question #27
Which of the following privacy frameworks are legally binding?
- Question #28
Which of the following is an example of Privacy by Design (PbD)?
- Question #29
In regards to the collection of personal data conducted by an organization, what must the data subject be allowed to do?
- Question #30
SCENARIO Please use the following to answer the next question: It's just what you were afraid of. Without consulting you, the information technology director at your organization l...
- Question #31
SCENARIO Please use the following to answer the next question: It's just what you were afraid of. Without consulting you, the information technology director at your organization l...
- Question #32
SCENARIO Please use the following to answer the next question: It's just what you were afraid of. Without consulting you, the information technology director at your organization l...
- Question #33
SCENARIO Please use the following to answer the next question: It's just what you were afraid of. Without consulting you, the information technology director at your organization l...
- Question #34
Which is NOT an influence on the privacy environment external to an organization?
- Question #35
How are individual program needs and specific organizational goals identified in privacy framework development?
- Question #36
SCENARIO Please use the following to answer the next question: Natalia, the Chief Financial Officer (CFO) of the Nationwide Grill restaurant chain, had never seen her fellow execut...
- Question #37
SCENARIO Please use the following to answer the next question: Natalia, the Chief Financial Officer (CFO) of the Nationwide Grill restaurant chain, had never seen her fellow execut...
- Question #38
SCENARIO Please use the following to answer the next question: Natalia, the Chief Financial Officer (CFO) of the Nationwide Grill restaurant chain, had never seen her fellow execut...
- Question #39
SCENARIO Please use the following to answer the next question: Natalia, the Chief Financial Officer (CFO) of the Nationwide Grill restaurant chain, had never seen her fellow execut...
- Question #40
Formosa International operates in 20 different countries including the United States and France. What organizational approach would make complying with a number of different regula...
- Question #41
When implementing Privacy by Design (PbD), what would NOT be a key consideration?
- Question #42
For an organization that has just experienced a data breach, what might be the least relevant metric for a company's privacy and governance team?
- Question #43
In which situation would a Privacy Impact Assessment (PIA) be the least likely to be required?
- Question #44
Under the General Data Protection Regulation (GDPR), what must be included in a written agreement between the controller and processor in relation to processing conducted on the co...
- Question #45
SCENARIO Please use the following to answer the next question: Perhaps Jack Kelly should have stayed in the U.S. He enjoys a formidable reputation inside the company, Special Handl...
- Question #46
SCENARIO Please use the following to answer the next question: Perhaps Jack Kelly should have stayed in the U.S. He enjoys a formidable reputation inside the company, Special Handl...
- Question #47
SCENARIO Please use the following to answer the next question: Perhaps Jack Kelly should have stayed in the U.S. He enjoys a formidable reputation inside the company, Special Handl...
- Question #48
You would like your organization to be independently audited to demonstrate compliance with international privacy standards and to identify gaps for remediation. Which type of audi...
- Question #49
An organization's business continuity plan or disaster recovery plan does NOT typically include what?
- Question #50
SCENARIO Please use the following to answer the next question: Edufox has hosted an annual convention of users of its famous e-learning software platform, and over time, it has bec...