CIPM Exam Questions
295 real CIPM exam questions with expert-verified answers and explanations. Page 3 of 6.
- Question #101
SCENARIO Please use the following to answer the next question: Martin Briseño is the director of human resources at the Canyon City location of the U.S. hotel chain Pacific Suites....
- Question #102
SCENARIO Please use the following to answer the next question: Martin Briseño is the director of human resources at the Canyon City location of the U.S. hotel chain Pacific Suites....
- Question #103
SCENARIO Please use the following to answer the next question: Martin Briseño is the director of human resources at the Canyon City location of the U.S. hotel chain Pacific Suites....
- Question #104
SCENARIO Please use the following to answer the next question: Martin Briseño is the director of human resources at the Canyon City location of the U.S. hotel chain Pacific Suites....
- Question #105
SCENARIO Please use the following to answer the next question: Martin Briseño is the director of human resources at the Canyon City location of the U.S. hotel chain Pacific Suites....
- Question #106
A Human Resources director at a company reported that a laptop containing employee payroll data was lost on the train. Which action should the company take IMMEDIATELY?
- Question #107
Read the following steps: - Perform frequent data back-ups. - Perform test restorations to verify integrity of backed-up data. - Maintain backed-up data offline or on separate serv...
- Question #108
The General Data Protection Regulation (GDPR) specifies fines that may be levied against data controllers for certain infringements. Which of the following will be subject to admin...
- Question #109
SCENARIO Please use the following to answer the next question. Manasa is a product manager at Omnipresent Omnimedia, where she is responsible for leading the development of the com...
- Question #110
What is the main purpose in notifying data subjects of a data breach?
- Question #111
Under the General Data Protection Regulation (GDPR), which situation would be LEAST likely to require a Data Protection Impact Assessment (DPIA)?
- Question #112
Under the General Data Protection Regulation (GDPR), which of the following situations would LEAST likely require a controller to notify a data subject?
- Question #113
SCENARIO Please use the following to answer the next question: Penny has recently joined Ace Space, a company that sells homeware accessories online, as its new privacy officer. Th...
- Question #114
SCENARIO Please use the following to answer the next question: Penny has recently joined Ace Space, a company that sells homeware accessories online, as its new privacy officer. Th...
- Question #115
SCENARIO Please use the following to answer the next question: Penny has recently joined Ace Space, a company that sells homeware accessories online, as its new privacy officer. Th...
- Question #116
Which of the documents below assists the Privacy Manager in identifying and responding to a request from an individual about what personal information the organization holds about...
- Question #117
Which of the following is the optimum first step to take when creating a Privacy Officer governance model?
- Question #118
Which of the following helps build trust with customers and stakeholders?
- Question #119
Which of the following is NOT an important factor to consider when developing a data retention policy?
- Question #120
When supporting the business and data privacy program expanding into a new jurisdiction, it is important to do all of the following EXCEPT?
- Question #121
When building a data privacy program, what is a good starting point to understand the scope of privacy program needs?
- Question #122
Which of the following actions is NOT required during a data privacy diligence process for Merger & Acquisition (M&A) deals?
- Question #123
When devising effective employee policies to address a particular issue, which of the following should be included in the first draft?
- Question #124
Your company wants to convert paper records that contain customer personal information into electronic form, upload the records into a new third-party marketing tool and then merge...
- Question #125
A minimum requirement for carrying out a Data Protection Impact Assessment (DPIA) would include?
- Question #126
Which of the following best supports implementing controls to bring privacy policies into effect?
- Question #127
What is most critical when outsourcing data destruction service?
- Question #128
Data retention and destruction policies should meet all of the following requirements EXCEPT?
- Question #129
What is least likely to be achieved by implementing a Data Lifecycle Management (DLM) program?
- Question #130
There are different forms of monitoring available for organizations to consider when aligning with their privacy program goals. Which of the following forms of monitoring is best d...
- Question #131
Which will best assist you in quickly identifying weaknesses in your network and storage?
- Question #132
Which of the following is NOT a type of privacy program metric?
- Question #133
How do privacy audits differ from privacy assessments?
- Question #134
An organization's internal audit team should do all of the following EXCEPT?
- Question #135
"Respond" in the privacy operational lifecycle includes which of the following?
- Question #136
If your organization has a recurring issue with colleagues not reporting personal data breaches, all of the following are advisable to do EXCEPT?
- Question #137
Which of the following information must be provided by the data controller when complying with GDPR "right to be informed" requirements?
- Question #138
A Data Privacy Officer (DPO) who posts privacy message reminders on posters and on company video screens throughout the office to reinforce the organization's privacy message is fu...
- Question #139
The primary purpose of privacy awareness activities is to?
- Question #140
SCENARIO Please use the following to answer the next question: Your organization, the Chicago (U.S.)-based Society for Urban Greenspace, has used the same vendor to operate all asp...
- Question #141
Which of the following controls are generally NOT part of a Privacy Impact Assessment (PIA) review?
- Question #142
When developing a privacy program and selecting a program sponsor or "champion" the most important consideration should be?
- Question #143
All of the following are components of a data collection notice EXCEPT?
- Question #144
SCENARIO Please use the following to answer the next question: Penny has recently joined Ace Space, a company that sells homeware accessories online, as its new privacy officer. Th...
- Question #145
Which of the following is least relevant to establishing a culture of data privacy at a company?
- Question #146
A Privacy Program Framework is an implementation roadmap that does all of the following EXCEPT?
- Question #147
SCENARIO Please use the following to answer the next question: Hi Zoe, Thank you so much for your email. I am so glad you have jumped right into your new position as our in-house p...
- Question #148
SCENARIO Please use the following to answer the next question: Hi Zoe, Thank you so much for your email. I am so glad you have jumped right into your new position as our in-house p...
- Question #149
SCENARIO Please use the following to answer the next question: Hi Zoe, Thank you so much for your email. I am so glad you have jumped right into your new position as our in-house p...
- Question #150
SCENARIO Please use the following to answer the next question: Hi Zoe, Thank you so much for your email. I am so glad you have jumped right into your new position as our in-house p...