CIPP-US Exam Questions
225 real CIPP-US exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51
Under state breach notification laws, which is NOT typically included in the definition of personal information?
- Question #52
Which of the following best describes what a "private right of action" is?
- Question #53
Which of the following is NOT a principle found in the APEC Privacy Framework?
- Question #54
What is the most important action an organization can take to comply with the FTC position on retroactive changes to a privacy policy?
- Question #55
Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?
- Question #56
If an organization maintains data classified as high sensitivity in the same system as data classified as low sensitivity, which of the following is the most likely outcome?
- Question #57
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
- Question #58
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
- Question #59
Acme Student Loan Company has developed an artificial intelligence algorithm that determines whether an individual is likely to pay their bill or default. A person who is determine...
- Question #60
Global Manufacturing Co's Human Resources department recently purchased a new software tool. This tool helps evaluate future candidates for executive roles by scanning emails to se...
- Question #61
Which of the following would NOT constitute an exception to the authorization requirement under the HIPAA Privacy Rule?
- Question #62
What type of material is exempt from an individual's right to disclosure under the Privacy Act?
- Question #63
Which of the following best describes an employer's privacy-related responsibilities to an employee who has left the workplace?
- Question #64
All of the following common law torts are relevant to employee privacy under US law EXCEPT?
- Question #65
Which law provides employee benefits, but often mandates the collection of medical information?
- Question #66
John, a California resident, receives notification that a major corporation with $500 million in annual revenue has experienced a data breach. John's personal information in their...
- Question #67
Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operating in 7 other states. SMH uses an electronic medical record to enter and track informatio...
- Question #68
Sarah lives in San Francisco, California. Based on a dramatic increase in unsolicited commercial emails, Sarah believes that a major social media platform with over 50 million user...
- Question #69
Which of the following is an example of federal preemption?
- Question #70
Which of these organizations would be required to provide its customers with an annual privacy notice?
- Question #71
Which entity within the Department of Health and Human Services (HHS) is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA) "Privacy Rule"?
- Question #72
Which of the following best describes how federal anti-discrimination laws protect the privacy of private-sector employees in the United States?
- Question #73
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?
- Question #74
Which of the following accurately describes the purpose of a particular federal enforcement agency?
- Question #75
SCENARIO Please use the following to answer the next question: When there was a data breach involving customer personal and financial information at a large retail store, the compa...
- Question #76
SCENARIO Please use the following to answer the next question: When there was a data breach involving customer personal and financial information at a large retail store, the compa...
- Question #77
SCENARIO Please use the following to answer the next question: When there was a data breach involving customer personal and financial information at a large retail store, the compa...
- Question #78
SCENARIO Please use the following to answer the next question: Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your...
- Question #79
Under the California Consumer Privacy Act (as amended by the California Pnvacy Rights Act), a consumer may Initiate a civil action against a business for?
- Question #80
A California resident has created an account on your company's online food delivery platform and placed several orders in the past month Later she submits a data subject request to...
- Question #81
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from mar...
- Question #82
In a case of civil litigation, what might a defendant who is being sued for distributing an employee's private information face?
- Question #83
The U.S. Supreme Court has recognized an individual's right to privacy over personal issues, such as contraception, by acknowledging which of the following?
- Question #84
Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?
- Question #85
In March 2012, the FTC released a privacy report that outlined three core principles for companies handling consumer data. Which was NOT one of these principles?
- Question #86
What is a key way that the Gramm-Leach-Bliley Act (GLBA) prevents unauthorized access into a person's back account?
- Question #87
In what way is the Controlling the Assault of Non-Solicited Pornography and Marketing (CAN- SPAM) Act intended to help consumers?
- Question #88
SCENARIO Please use the following to answer the next question: Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy p...
- Question #89
SCENARIO Please use the following to answer the next question: Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy p...
- Question #90
Which of the following statements is most accurate in regard to data breach notifications under federal and state laws:
- Question #91
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?
- Question #92
Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusing on placing privacy professionals in roles at major companies. Job candidates create onli...
- Question #93
SCENARIO Please use the following to answer the next question: Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has m...
- Question #94
SCENARIO Please use the following to answer the next question: Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has m...
- Question #95
Which federal agency plays a role in privacy policy, but does NOT have regulatory authority?
- Question #96
Which of the following is NOT one of three broad categories of products offered by data brokers, as identified by the U.S. Federal Trade Commission (FTC)?
- Question #97
What information did the Red Flag Program Clarification Act of 2010 add to the original Red Flags rule?
- Question #98
Although an employer may have a strong incentive or legal obligation to monitor employees' conduct or behavior, some excessive monitoring may be considered an intrusion on employee...
- Question #99
Which of the following became the first state to pass a law specifically regulating the collection of biometric data?
- Question #100
SCENARIO Please use the following to answer the next question: Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Cele...