CIPM Exam Questions
295 real CIPM exam questions with expert-verified answers and explanations. Page 4 of 6.
- Question #151
Which of the following changes typically does NOT require a Privacy Impact Assessment (PIA)?
- Question #152
A Privacy Threshold Analysis (PTA), Privacy Impact Assessment (PIA) and Data Protection Impact Assessment (DPIA) are conducted during what phase of a System Development Life Cycle...
- Question #153
Which privacy principles and guidelines helped form the basis for the EU Data Protection Directive and The General Data Protection Regulation (GDPR)?
- Question #154
Protection from threats to facilities, systems that process and store electronic copies, and IT work/equipment locations best describes which category of security control?
- Question #155
A company has started developing a privacy program. The Data Protection Officer (DPO) has been working long hours to develop cohesive procedures and processes; however, he failed t...
- Question #156
SCENARIO Please use the following to answer the next question: Felicity is the Chief Executive Officer (CEO) of an international clothing company that does business in several coun...
- Question #157
SCENARIO Please use the following to answer the next question: Felicity is the Chief Executive Officer (CEO) of an international clothing company that does business in several coun...
- Question #158
SCENARIO Please use the following to answer the next question: Felicity is the Chief Executive Officer (CEO) of an international clothing company that does business in several coun...
- Question #159
SCENARIO Please use the following to answer the next question: Felicity is the Chief Executive Officer (CEO) of an international clothing company that does business in several coun...
- Question #160
Integrating privacy requirements into functional areas across the organization happens at which stage of the privacy operational lifecycle?
- Question #161
Which item below best represents how a Privacy Group can effectively communicate with functional areas?
- Question #162
What is the most secure standard for disposition of a hard drive containing personal data?
- Question #163
Which of the following would NOT be beneficial in integrating privacy requirements and representation into functional areas across an organization?
- Question #164
Which of the following is a common disadvantage of a third-party audit?
- Question #165
SCENARIO Please use the following to answer the next question: Jonathan recently joined a healthcare payment processing solutions company as a senior privacy manager. One morning,...
- Question #166
SCENARIO Please use the following to answer the next question: Jonathan recently joined a healthcare payment processing solutions company as a senior privacy manager. One morning,...
- Question #167
SCENARIO Please use the following to answer the next question: Jonathan recently joined a healthcare payment processing solutions company as a senior privacy manager. One morning,...
- Question #168
Internal audits add value to the privacy program primarily though what?
- Question #169
The owner of an ice cream store has decided to begin accepting credit and debit cards for payment. To comply with industry standards, the owner will need to do which of the followi...
- Question #170
You are the Privacy Officer (PO) at a University. Recently, the police have contacted you as they suspect that one of your students is using a library computer to commit financial...
- Question #171
What is the name for the privacy strategy model that describes delegated decision making?
- Question #172
Which aspect of a privacy program can best aid an organization's response time to a Data Subject Access Request (DSAR)?
- Question #173
All of the following are components of a data collection notice EXCEPT identification of?
- Question #174
Under the General Data Protection Regulation (GDPR), what obligation does a data controller or processor have after appointing a Data Protection Officer (DPO)?
- Question #175
Under the European Data Protection Board (formerly Article 29 Working Party), which Processing operation would require a Data Protection Impact Assessment (DPIA)?
- Question #176
What is the Privacy Officer's first action after being told that her firm is planning to sell its credit card processing business?
- Question #177
SCENARIO Please use the following to answer the next question: You were recently hired by InStyle Data Corp. as a privacy manager to help InStyle Data Corp. became compliant with a...
- Question #178
SCENARIO Please use the following to answer the next question: You were recently hired by InStyle Data Corp. as a privacy manager to help InStyle Data Corp. became compliant with a...
- Question #179
SCENARIO Please use the following to answer the next question: You were recently hired by InStyle Data Corp. as a privacy manager to help InStyle Data Corp. became compliant with a...
- Question #180
The least useful metric for optimizing the design of your data subject request workflow is tracking the number of data subjects who?
- Question #181
During a merger and acquisition, the most comprehensive review of privacy risks and gaps occurs when conducting what activity?
- Question #182
When vetting third-party processors of data protected by the General Data Protection Regulation (GDPR), why is it important to know the physical location of stored personal data fr...
- Question #183
Which of the following conditions will definitely trigger a Data Protection Impact Assessment (DPIA)?
- Question #184
Which of the following information must be provided by the data controller when complying with the General Data Protection Regulation (GDPR) "right to access" requirements?
- Question #185
Post-liquidation, a company that has acquired assets would require separate consent from a data subject if personally identifiable data were being retained for which purpose?
- Question #186
Training and awareness metrics in a privacy program are necessary to?
- Question #187
A "right to erasure" request could be rejected if the processing of personal data is for?
- Question #188
A marketing team regularly exports spreadsheets to use for analysis including customer name, birthdate and home address. These spreadsheets are routinely shared between members of...
- Question #189
The best way to help ensure that reasonable and appropriate security measures are in place to protect personal data is to establish?
- Question #190
As the Data Protection Officer (DPO) for the growing company, Vision 3468, what would be the most cost effective way to monitor changes in laws and regulations?
- Question #191
All the following are responsibilities of a privacy program manager EXCEPT:
- Question #192
Relating to Privacy Law, which term can best be defined as being able to prove that an organization is acting and demonstrating compliance with applicable laws?
- Question #193
Relating to Privacy Law, which term can best be defined as to guide a privacy function toward compliance with legal obligations and the organization's business objectives and goals...
- Question #194
Regarding privacy governance, which of the following describes where an organization stands on privacy?
- Question #195
In which component of privacy governance does an organization identify what personal information is processed and determine privacy obligations?
- Question #196
Which component of privacy governance is defined as the organization's approach to communicating and obtaining support for the privacy program?
- Question #197
During which component of Privacy Governance might a company gain buy-in to a new privacy program by conducting interviews and establishing program sponsors throughout the organiza...
- Question #198
Which privacy team model gives the most freedom of flexibility and a sense of ownership while allowing everyone to learn what works best for them, but it takes the most time to imp...
- Question #199
Assuming that a candidate is qualified, which requirements must be met when appointing a Data Protection Officer?
- Question #200
Which of the following data assessments is described as, 揳n analysis of the privacy risks associated with processing personal information in relation to a project, product, or serv...