CIPP-US Exam Questions
225 real CIPP-US exam questions with expert-verified answers and explanations. Page 2 of 5.
- Question #51Data Breaches
Under state breach notification laws, which is NOT typically included in the definition of personal information?
personal information definitionbreach notificationstate privacy lawstriggering data elements - Question #52Introduction to the US Privacy Environment
Which of the following best describes what a "private right of action" is?
private right of actionlegal remediesenforcement mechanisms - Question #53Introduction to the US Privacy Environment
Which of the following is NOT a principle found in the APEC Privacy Framework?
APEC Privacy Frameworkinternational privacy principlesPrivacy by Design - Question #54Limits on Private-Sector Collection and Use of Data
What is the most important action an organization can take to comply with the FTC position on retroactive changes to a privacy policy?
FTC enforcementprivacy policy changesretroactive consentaffirmative consent - Question #55Sector-Specific Laws
Federal laws establish which of the following requirements for collecting personal information of minors under the age of 13?
COPPAparental consentchildren's privacyminors under 13 - Question #56Data Breaches
If an organization maintains data classified as high sensitivity in the same system as data classified as low sensitivity, which of the following is the most likely outcome?
data classificationbreach impact severitydata segregationrisk management - Question #57Introduction to the US Privacy Environment
Which of the following best describes the ASIA-Pacific Economic Cooperation (APEC) principles?
APEC Privacy Frameworkinternational frameworkscommercial sector privacy - Question #58State Privacy Laws
Which of the following became the first state to pass a law specifically regulating the practices of data brokers?
data brokersVermontstate-specific regulationfirst-mover legislation - Question #59Limits on Private-Sector Collection and Use of Data
Acme Student Loan Company has developed an artificial intelligence algorithm that determines whether an individual is likely to pay their bill or default. A person who is determine...
AI automated decisionsprotected classesdiscriminatory algorithmsFCRA - Question #60Workplace Privacy
Global Manufacturing Co's Human Resources department recently purchased a new software tool. This tool helps evaluate future candidates for executive roles by scanning emails to se...
workplace monitoringemail surveillanceemployee noticeHR technology - Question #61Health, Financial & Marketing Privacy
Which of the following would NOT constitute an exception to the authorization requirement under the HIPAA Privacy Rule?
HIPAA Privacy Ruleauthorization exceptionstreatment payment operationsbilling - Question #62Introduction to the US Privacy Environment
What type of material is exempt from an individual's right to disclosure under the Privacy Act?
Privacy Act of 1974exemptionscriminal law enforcementfederal records - Question #63Workplace Privacy
Which of the following best describes an employer's privacy-related responsibilities to an employee who has left the workplace?
former employeesemployment records retentionpost-employment obligationsdata security - Question #64Workplace Privacy
All of the following common law torts are relevant to employee privacy under US law EXCEPT?
common law tortsemployee privacyintrusion upon seclusionconversion - Question #65Workplace Privacy
Which law provides employee benefits, but often mandates the collection of medical information?
FMLAmedical information collectionemployee benefitsmandatory disclosure - Question #66State Privacy Laws
John, a California resident, receives notification that a major corporation with $500 million in annual revenue has experienced a data breach. John's personal information in their...
CCPAprivate right of actiondata breachstatutory damages - Question #67Data Breaches
Smith Memorial Healthcare (SMH) is a hospital network headquartered in New York and operating in 7 other states. SMH uses an electronic medical record to enter and track informatio...
HIPAA breach notificationmulti-state complianceOCR notificationstate breach laws - Question #68State Privacy Laws
Sarah lives in San Francisco, California. Based on a dramatic increase in unsolicited commercial emails, Sarah believes that a major social media platform with over 50 million user...
CCPAright to deletionconsumer rightsCalifornia - Question #69Limits on Private-Sector Collection and Use of Data
Which of the following is an example of federal preemption?
federal preemptionCAN-SPAM Actemail marketingstate law preemption - Question #70Health, Financial & Marketing Privacy
Which of these organizations would be required to provide its customers with an annual privacy notice?
GLBAannual privacy noticefinancial institutionsnonpublic personal information - Question #71Health, Financial & Marketing Privacy
Which entity within the Department of Health and Human Services (HHS) is the primary enforcer of the Health Insurance Portability and Accountability Act (HIPAA) "Privacy Rule"?
HIPAAPrivacy RuleOffice for Civil RightsHHS enforcement - Question #72Workplace Privacy
Which of the following best describes how federal anti-discrimination laws protect the privacy of private-sector employees in the United States?
anti-discrimination lawsemployee data collectionworkplace privacyemployment screening - Question #73State Privacy Laws
Even when dealing with an organization subject to the CCPA, California residents are NOT legally entitled to request that the organization do what?
CCPACPRAconsumer rightsdata correction - Question #74Government Enforcement
Which of the following accurately describes the purpose of a particular federal enforcement agency?
FTC authorityfederal enforcement agenciesNISTCISA - Question #75Data Breaches
SCENARIO Please use the following to answer the next question: When there was a data breach involving customer personal and financial information at a large retail store, the compa...
data breach typesaccess controlsunauthorized accessinternal threat - Question #76Limits on Private-Sector Collection and Use of Data
SCENARIO Please use the following to answer the next question: When there was a data breach involving customer personal and financial information at a large retail store, the compa...
data retentionFTC principlesdata minimizationconsumer rights - Question #77Data Breaches
SCENARIO Please use the following to answer the next question: When there was a data breach involving customer personal and financial information at a large retail store, the compa...
access controlsprivacy programbreach preventiondata governance - Question #78Sector-Specific Laws
SCENARIO Please use the following to answer the next question: Matt went into his son's bedroom one evening and found him stretched out on his bed typing on his laptop. "Doing your...
COPPAchildren's privacyonline data collectionage threshold - Question #79State Privacy Laws
Under the California Consumer Privacy Act (as amended by the California Pnvacy Rights Act), a consumer may Initiate a civil action against a business for?
CCPACPRAprivate right of actionsecurity breach - Question #80State Privacy Laws
A California resident has created an account on your company's online food delivery platform and placed several orders in the past month Later she submits a data subject request to...
CPRAdata subject access rightsinferencesexceptions - Question #81Government Enforcement
Matt was concerned. He doubted if it was legal for the marketer to collect information from his son in the way that it was. Then he noticed several other commercial emails from mar...
UDAPCOPPA enforcementstate enforcementchildren's marketing - Question #82Government Enforcement
In a case of civil litigation, what might a defendant who is being sued for distributing an employee's private information face?
civil litigationinjunctionremediesemployee privacy - Question #83Introduction to the U.S. Privacy Environment
The U.S. Supreme Court has recognized an individual's right to privacy over personal issues, such as contraception, by acknowledging which of the following?
constitutional privacypenumbra doctrinedue processSupreme Court - Question #84Limits on Private-Sector Collection and Use of Data
Based on the 2012 Federal Trade Commission report "Protecting Consumer Privacy in an Era of Rapid Change", which of the following directives is most important for businesses?
FTC 2012 reportPrivacy by Designconsumer privacy frameworkproduct development - Question #85Limits on Private-Sector Collection and Use of Data
In March 2012, the FTC released a privacy report that outlined three core principles for companies handling consumer data. Which was NOT one of these principles?
FTC privacy frameworkPrivacy by Designtransparencyconsumer choice - Question #86Health, Financial & Marketing Privacy
What is a key way that the Gramm-Leach-Bliley Act (GLBA) prevents unauthorized access into a person's back account?
GLBAaccount number disclosurefinancial privacypretexting - Question #87Health, Financial & Marketing Privacy
In what way is the Controlling the Assault of Non-Solicited Pornography and Marketing (CAN- SPAM) Act intended to help consumers?
CAN-SPAMemail marketingopt-outcommercial email - Question #88State Privacy Laws
SCENARIO Please use the following to answer the next question: Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy p...
CCPApersonal information definitionbusiness contact informationB2B data - Question #89Limits on Private-Sector Collection and Use of Data
SCENARIO Please use the following to answer the next question: Otto is preparing a report to his Board of Directors at Filtration Station, where he is responsible for the privacy p...
vendor managementcloud providercontractual compliancedata processor oversight - Question #90Data Breaches
Which of the following statements is most accurate in regard to data breach notifications under federal and state laws:
data breach notificationfederal lawstate lawFTC - Question #91Health, Financial & Marketing Privacy
What consumer service was the Fair Credit Reporting Act (FCRA) originally intended to provide?
FCRAcredit reportingconsumer rightscredit correction - Question #92Data Breaches
Privacy Is Hiring Inc., a CA-based company, is an online specialty recruiting firm focusing on placing privacy professionals in roles at major companies. Job candidates create onli...
data breach notificationencryptionCalifornia lawcredit card data - Question #93Health, Financial & Marketing Privacy
SCENARIO Please use the following to answer the next question: Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has m...
Dodd-FrankCFPBabusive practicesFCRA - Question #94Health, Financial & Marketing Privacy
SCENARIO Please use the following to answer the next question: Noah is trying to get a new job involving the management of money. He has a poor personal credit rating, but he has m...
FACTADisposal RuleGLBAcredit reporting - Question #95Introduction to the U.S. Privacy Environment
Which federal agency plays a role in privacy policy, but does NOT have regulatory authority?
federal agenciesregulatory authorityprivacy policyDepartment of Commerce - Question #96Limits on Private-Sector Collection and Use of Data
Which of the following is NOT one of three broad categories of products offered by data brokers, as identified by the U.S. Federal Trade Commission (FTC)?
data brokersFTCconsumer dataproduct categories - Question #97Health, Financial & Marketing Privacy
What information did the Red Flag Program Clarification Act of 2010 add to the original Red Flags rule?
Red Flags RuleFACTAcreditor definitionidentity theft - Question #98Workplace Privacy
Although an employer may have a strong incentive or legal obligation to monitor employees' conduct or behavior, some excessive monitoring may be considered an intrusion on employee...
employee monitoringworkplace surveillancevideo monitoringprivacy intrusion - Question #99State Privacy Laws
Which of the following became the first state to pass a law specifically regulating the collection of biometric data?
biometric dataBIPAIllinoisstate privacy laws - Question #100Workplace Privacy
SCENARIO Please use the following to answer the next question: Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Cele...
polygraph testsemployee screeningconsentbackground checks