CIPM Exam Questions
295 real CIPM exam questions with expert-verified answers and explanations. Page 5 of 6.
- Question #201
Which privacy assessment describes a process designed to identify risks arising out of the processing of personal data and to minimize these risks as much and as early as possible....
- Question #202
Which type of data assessment must be completed according to the European Data Protection Board when evaluating or scoring an individual to determine his or her economic situation?
- Question #203
Information Security is about preserving and protecting information regarding:
- Question #204
All the following statements are TRUE regarding data processing vendors and vendor selection EXCEPT:
- Question #205
Which elements should be included in an organizations privacy policy?
- Question #206
All the following statements regarding privacy policies are true, EXCEPT:
- Question #207
What is the best way to understand the location, use and importance of personal data within an organization?
- Question #208
What are you doing if you succumb to "overgeneralization" when analyzing data from metrics?
- Question #209
In addition to regulatory requirements and business practices, what important factors must a global privacy strategy consider?
- Question #210
What have experts identified as an important trend in privacy program development?
- Question #211
SCENARIO Please use the following to answer the next question: Manasa is a product manager at Omnipresent Omnimedia, where she is responsible for leading the development of the com...
- Question #212
SCENARIO Please use the following to answer the next question: Manasa is a product manager at Omnipresent Omnimedia, where she is responsible for leading the development of the com...
- Question #213
SCENARIO Please use the following to answer the next question: Manasa is a product manager at Omnipresent Omnimedia, where she is responsible for leading the development of the com...
- Question #214
SCENARIO Please use the following to answer the next question: Manasa is a product manager at Omnipresent Omnimedia, where she is responsible for leading the development of the com...
- Question #215
Which statement is FALSE regarding the use of technical security controls?
- Question #216
An organization's privacy officer was just notified by the benefits manager that she accidentally sent out the retirement enrollment report of all employees to a wrong vendor. Whic...
- Question #217
Within privacy laws and regulations, which of the following is a voluntary code of conduct?
- Question #218
Which of the following laws has the purpose of finding a balance between the free flow of data and the protection of the fundamental rights and freedoms of those to whom the data r...
- Question #219
Which article of the GDPR defines the territorial scope of the GDPR?
- Question #220
All the following are TRUE concerning data assessments EXCEPT:
- Question #221
SCENARIO Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found...
- Question #222
SCENARIO Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found...
- Question #223
SCENARIO Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found...
- Question #224
SCENARIO Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found...
- Question #225
SCENARIO Please use the following to answer the next question: Henry Home Furnishings has built high-end furniture for nearly forty years. However, the new owner, Anton, has found...
- Question #226
Why were the nongovernmental privacy organizations, Electronic Frontier Foundation (EFF) and Electronic Privacy Information Center (EPIC), established?
- Question #227
What is the main function of the Asia-Pacific Economic Cooperation Privacy Framework?
- Question #228
Which of the following is TRUE about the Data Protection Impact Assessment (DPIA) process as required under the General Data Protection Regulation (GDPR)?
- Question #229
SCENARIO Please use the following to answer the next question: John is the new privacy officer at the prestigious international law firm - A&M LLP. A&M LLP is very proud of its rep...
- Question #230
In privacy protection, what is a "covered entity"?
- Question #231
Which of the following best describes proper compliance for an international organization using Binding Corporate Rules (BCRs) as a controller or processor?
- Question #232
SCENARIO Please use the following to answer the next question: Richard McAdams recently graduated law school and decided to return to the small town of Lexington, Virginia to help...
- Question #233
Which of the following is TRUE of a privacy program with decentralized governance?
- Question #234
SCENARIO Please use the following to answer the next question: Liam is the newly appointed IT Compliance Manager at Mesa, a US-based outdoor clothing brand with a global E-commerce...
- Question #235
SCENARIO Please use the following to answer the next question: Liam is the newly appointed IT Compliance Manager at Mesa, a US-based outdoor clothing brand with a global E-commerce...
- Question #236
SCENARIO Please use the following to answer the next question: Liam is the newly appointed IT Compliance Manager at Mesa, a US-based outdoor clothing brand with a global E-commerce...
- Question #237
SCENARIO Please use the following to answer the next question: Liam is the newly appointed IT Compliance Manager at Mesa, a US-based outdoor clothing brand with a global E-commerce...
- Question #238
Under the General Data Protection Regulation (GDPR), international data transfer is allowed using the mechanisms in all of the following scenarios EXCEPT between companies who?
- Question #239
Which of the following is NOT an important factor to consider when developing a data retention policy?
- Question #240
Which of the following is legally binding and enforceable?
- Question #241
Formosa International operates in 20 different countries including the United States and France. What organizational approach would make complying with a number of different regula...
- Question #242
The most direct way to ensure you are effectively communicating your privacy mission throughout your organization is to?
- Question #243
If done correctly, how can a Data Protection Impact Assessment (DPIA) create a win/win scenario for organizations and individuals?
- Question #244
Which of the following is NOT recommended for effective Identity Access Management?
- Question #245
You would like to better understand how your organization can demonstrate compliance with international privacy standards and identify gaps for remediation. What steps could you ta...
- Question #246
If your organization has a recurring issue with colleagues not reporting personal data breaches, all of the following are advisable to do EXCEPT?
- Question #247
SCENARIO Please use the following to answer the next question: Today is your first day at a fast growing international real estate firm headquartered in New York, with offices in C...
- Question #248
SCENARIO Please use the following to answer the next question: Today is your first day at a fast growing international real estate firm headquartered in New York, with offices in C...
- Question #249
SCENARIO Please use the following to answer the next question: Today is your first day at a fast growing international real estate firm headquartered in New York, with offices in C...
- Question #250
Which of the following forms of monitoring is best described as 'auditing' when aligning with privacy program goals?