CIPM Exam Questions
295 real CIPM exam questions with expert-verified answers and explanations. Page 6 of 6.
- Question #251
A systems audit uncovered a shared drive folder containing sensitive employee data with no access controls and therefore was available for all employees to view. What is the first...
- Question #252
While trying to e-mail her manager, an employee has e-mailed a list of all the company's customers, including their bank details, to an employee with the same name at a different c...
- Question #253
You have just taken on the role of Data Governance Director at an energy corporation based in London, England. The company has been trading for over 25 years and you soon team that...
- Question #254
You have just taken on the role of Data Governance Director at an energy corporation based in London, England. The company has been trading for over 25 years and you soon team that...
- Question #255
You have just taken on the role of Data Governance Director at an energy corporation based in London, England. The company has been trading for over 25 years and you soon team that...
- Question #256
When developing a privacy program and selecting a program sponsor or "champion" the most important consideration should be that they?
- Question #257
Implementation of a Privacy Program Framework (PPF) requires that you do all of the following EXCEPT?
- Question #258
Which of the following is least relevant to establishing a culture of data privacy at a company?
- Question #259
The following are examples of Privacy by Design (PbD) EXCEPT?
- Question #260
Which of the following helps build trust with customers and stakeholders?
- Question #261
Which of the following is the most likely way an independent privacy organization might work to promote sound privacy practices?
- Question #262
Which is the best first step in establishing a baseline regarding privacy in an organization?
- Question #263
What are the advantages for a company that chooses a hybrid of centralized and decentralized management practices?
- Question #264
Which of the following is least likely to address individual program needs and specific organizational goals identified in privacy framework development?
- Question #265
Creating a privacy governance model for an organization that is required to appoint data protection officers under the GDPR poses what additional challenge?
- Question #266
When developing a privacy program and selecting a program sponsor or "champion" the least important consideration should be that they?
- Question #267
In the European Union, the GDPR gives Supervisory Authorities the right to which of the following actions?
- Question #268
Understanding the sensitivity of personal data that an organization holds is a crucial step for a privacy professional attempting to do what?
- Question #269
All of the following are components of a data collection notice EXCEPT identification of?
- Question #270
When implementing an organization's privacy program, what right should be granted to the data subject?
- Question #271
All of the following are environmental controls EXCEPT?
- Question #272
Which of the following is an example of Privacy by Design (PhD)?
- Question #273
What is the key privacy objective in undertaking an evaluation of technical controls?
- Question #274
The purpose of a data flow map is to help an organization do all of the following EXCEPT?
- Question #275
Which of the following is NOT recommended for effective Identity Access Management?
- Question #276
Which of the following is NOT a main technical data control area?
- Question #277
Which of the following is a physical control that can limit privacy risk?
- Question #278
SCENARIO Please use the following to answer the next question: Liam is the newly appointed IT Compliance Manager at Mesa, a US-based outdoor clothing brand with a global E-commerce...
- Question #279
Under the General Data Protection Regulation (GDPR), what are the obligations of a processor that engages a sub-processor?
- Question #280
When conducting due diligence during an acquisition, what should a privacy professional avoid?
- Question #281
SCENARIO Please use the following to answer the next question: You were recently hired by InStyle Data Corp. as a privacy manager to help InStyle Data Corp. became compliant with a...
- Question #282
SCENARIO Please use the following to answer the next question: You were recently hired by InStyle Data Corp. as a privacy manager to help InStyle Data Corp. became compliant with a...
- Question #283
Integrating privacy requirements into functional areas across the organization happens at which stage of the privacy operational life cycle?
- Question #284
Under the GDPR, when the applicable lawful basis for the processing of personal data is a legal obligation with which the controller must comply, which right can the data subject e...
- Question #285
Under the European Data Protection Board, which Processing operation would require a Data Protection Impact Assessment (DPIA)?
- Question #286
Under Article 35 of the GDPR, a data controller must take a risk-based approach to determine whether to complete?
- Question #287
As the Data Protection Officer (DPO) for the growing company, Vision 7165, what would be the most cost effective way to monitor changes in laws and regulations?
- Question #288
After an incident, all of the following are potential objectives for improvements to the way an organization handles breach management, EXCEPT?
- Question #289
Your company provides a SaaS tool for B2B services and does not interact with individual consumers. A client's current employee reaches out with a right to delete request, what is...
- Question #290
In regards to the collection of personal data conducted by an organization, what must the data subject be allowed to do?
- Question #291
Your marketing team wants to know why they need a check box for their SMS opt-in. You explain it is part of the consumer's right to?
- Question #292
Which of the following information is NOT required to be provided by the data controller when complying with GDPR "right to access" requirements?
- Question #293
You're managing the internal privacy mailbox and are notified that a sales team member recently sent emails to their clients that included an excel spreadsheet of their client data...
- Question #294
When a data breach incident has occurred, the first priority is to determine?
- Question #295
An online retailer detects an incident involving customer shopping history but no keys have been compromised. The Privacy Office is most concerned when it also involves?