CIPP-US Exam Questions
225 real CIPP-US exam questions with expert-verified answers and explanations. Page 3 of 5.
- Question #101State Privacy Laws
One of the most significant elements of Senate Bill No. 260 relating to Internet privacy is the introduction of what term into Nevada law?
Nevada lawdata brokersinternet privacystate legislation - Question #102Workplace Privacy
SCENARIO Please use the following to answer the next question: Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Cele...
ADAemployee screeningdisability discriminationinterview process - Question #103State Privacy Laws
Your company, an online store selling digital keys to video games, has received a data access request from an individual. Specifically, the individual wants access to her recent pu...
CCPAdata access requestidentity verificationconsumer rights - Question #104State Privacy Laws
Which of the following would NOT be regulated by the Illinois Biometnc Information Pnvacy Act (BIPA)?
BIPAbiometric dataphotographsIllinois law - Question #105Workplace Privacy
SCENARIO Please use the following to answer the next question: Felicia has spent much of her adult life overseas, and has just recently returned to the U.S. to help her friend Cele...
BYODemployee monitoringpersonal devicesworkplace privacy - Question #106Health, Financial & Marketing Privacy
What privacy concept grants a consumer the right to view and correct errors on his or her credit report?
access rightscredit reportFCRAconsumer rights - Question #107Health, Financial & Marketing Privacy
A company's employee wellness portal offers an app to track exercise activity via users' mobile devices. Which of the following design techniques would most effectively inform user...
privacy noticeapp designdata collection transparencywellness program - Question #108Health, Financial & Marketing Privacy
Under the Fair Credit Reporting Act (FCRA), what must a person who is denied employment based upon his credit history receive?
FCRAadverse actionemployment denialcredit history - Question #109Workplace Privacy
Which statement is FALSE regarding the provisions of the Employee Polygraph Protection Act of 1988 (EPPA)?
EPPApolygraph testingemployee rightspsychological testing - Question #110Workplace Privacy
U.S. federal laws protect individuals from employment discriminaton based on all of the following EXCEPT?
employment discriminationprotected classesfederal employment lawEEOC - Question #111Introduction to the US Privacy Environment
Which statute is considered part of U.S. federal privacy law?
FCRAfederal privacy lawUS privacy statutessector-specific law - Question #112Introduction to the US Privacy Environment
In 2012, the White House and the FTC both issued reports advocating a new approach to privacy enforcement that can best be described as what?
FTCcomprehensive privacy frameworkWhite House 2012notice and choice - Question #113Government Enforcement
The FTC often negotiates consent decrees with companies found to be in violation of privacy principles. How does this benefit both parties involved?
FTC consent decreessettlementsenforcement mechanismslitigation avoidance - Question #114Introduction to the US Privacy Environment
When developing a company privacy program, which of the following relationships will most help a privacy professional develop useful guidance for the organization?
privacy program developmentstakeholder engagementorganizational relationshipscross-departmental - Question #115Sector-Specific Laws
The Family Educational Rights and Privacy Act (FERPA) requires schools to do all of the following EXCEPT?
FERPAeducational recordsdirectory informationstudent rights - Question #116Limits on Private-Sector Collection and Use of Data
Chanel Hair Studio is a busy high-end hair salon. In an effort to maximize efficiency of its operations and reduce wait times for appointments, Chanel decides to implement artifici...
social media data collectionnotice requirementsAI profilingunfair practices - Question #117Workplace Privacy
Which of the following laws is NOT involved in the regulation of employee background checks?
employee background checksFCRAGLBACivil Rights Act - Question #118Government Enforcement
In 2011, the FTC announced a settlement with Google regarding its social networking service Google Buzz. The FTC alleged that in the process of launching the service, the company d...
FTC settlementGoogle BuzzSafe Harbordeceptive practices - Question #119Workplace Privacy
A financial services company install "bossware" software on its employees' remote computers to monitor performance. The software logs screenshots, mouse movements, and keystrokes t...
intrusion upon seclusionworkplace monitoringbosswarewebcam surveillance - Question #120Data Breaches
The CFO of a pharmaceutical company is duped by a phishing email and discloses many of the company's employee personnel files to an online predator. The files include employee cont...
phishing breachstate law remediesUDAPpersonnel files - Question #121Introduction to the US Privacy Environment
A company based in United States receives information about its UK subsidiary's employees in connection with the centralized HR service it provides. How can the UK company ensure a...
UK GDPRstandard contractual clausescross-border data transferBCRs - Question #122State Privacy Laws
Which of the following state laws has an entity exemption for organizations subject to the Gramm- Leach-Bliley Act (GLBA)?
GLBA exemptionCPRAentity exemptionsstate privacy laws - Question #123Health, Financial & Marketing Privacy
When designing contact tracing apps in relation to COVID-19 or any other diagnosed virus, all of the following privacy measures should be considered EXCEPT?
contact tracinghealth dataprivacy by designuse limitations - Question #124Workplace Privacy
SCENARIO Please use the following to answer the next question: Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to th...
employee monitoringemployment contractworkplace surveillance policyinsider threat - Question #125Data Breaches
Once a breach has been definitively established, which task should be prioritized next?
breach notificationincident responsebreach response priorityaffected party notice - Question #126Health, Financial & Marketing Privacy
SCENARIO Please use the following to answer the next question: Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. Miraculous normal...
HIPAABusiness Associate Agreementtelehealthcloud services - Question #127Data Breaches
Which of the following conditions would NOT be sufficient to excuse an entity from providing breach notification under state law?
breach notification safe harborencryptionstate law exemptionsdata access vs exfiltration - Question #128State Privacy Laws
The use of cookies on a website by a service provider is generally not deemed a `sale' of personal information by CCPA, as long as which of the following conditions is met?
CCPAsale of personal informationservice provider exemptioncookies - Question #129Sector-Specific Laws
Under the Driver's Privacy Protection Act (DPPA), which of the following parties would require consent of an individual in order to obtain his or her Department of Motor Vehicle in...
DPPADMV recordspermitted disclosuresmarketing consent - Question #130Government Enforcement
Which of the following federal agencies does NOT have regulatory authority related to privacy?
federal agenciesregulatory authorityprivacy enforcementagency jurisdiction - Question #131Introduction to the U.S. Privacy Environment
Which of the following practices is NOT a key component of a data ethics framework?
data ethicsdata governanceauditingautomated decision-making - Question #132Government Enforcement
What was unique about the action that the Federal Trade Commission took against B.J.'s Wholesale Club in 2005?
FTC enforcementunfairness doctrinedata securitySection 5 - Question #133State Privacy Laws
Mega Corp. is a U.S.-based business with employees in California, Virginia, and Colorado. Which of the following must Mega Corp. comply with in regard to its human resources data?
CPRAVCDPAColorado Privacy Actemployee data - Question #134State Privacy Laws
Which of the following privacy rights is NOT available under the Colorado Privacy Act?
Colorado Privacy Actconsumer rightssensitive datadata subject rights - Question #135State Privacy Laws
SuperMart is a large Nevada-based business that has recently determined it sells what constitutes "covered information" under Nevada's privacy law, Senate Bill 260. Which of the fo...
Nevada SB 260opt-out of salecovered informationstate privacy law - Question #136Health, Financial & Marketing Privacy
Under GLBA. which of these organizations would not be required to provide its customers with an annual privacy notice?
GLBAannual privacy noticefinancial institutionsnotice exceptions - Question #137Limits on Private-Sector Collection and Use of Data
The concept of data portability refers to what?
data portabilityconsumer rightspersonal data reuseindividual rights - Question #138Limits on Private-Sector Collection and Use of Data
Which of the following is NOT a common challenge large organizations face when implementing data portability?
data portabilityimplementation challengestechnical compatibilitythird-party data - Question #139Introduction to the U.S. Privacy Environment
Under the EU-US Data Privacy Framework, what must participating organizations provide to individuals in regard to complaints and disputes?
EU-US Data Privacy Frameworkindependent recourse mechanismdispute resolutioncross-border transfer - Question #140Health, Financial & Marketing Privacy
SCENARIO Please use the following to answer the next question: Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. Miraculous normal...
HIPAAcovered entitybusiness associatetelehealth - Question #141Health, Financial & Marketing Privacy
SCENARIO Please use the following to answer the next question: Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. Miraculous normal...
HIPAAbusiness associate oversightcovered entity obligationsBAA - Question #142Health, Financial & Marketing Privacy
SCENARIO Please use the following to answer the next question: Miraculous Healthcare is a large medical practice with multiple locations in California and Nevada. Miraculous normal...
HIPAAbusiness associateCCPAdata deletion request - Question #143Health, Financial & Marketing Privacy
What consumer protection did the Fair and Accurate Credit Transactions Act (FACTA) require?
FACTAcredit card truncationFCRAconsumer protection - Question #144Health, Financial & Marketing Privacy
Which of the following would best provide a sufficient consumer disclosure under the Fair Credit Reporting Act (FCRA) prior to a consumer report being obtained for employment purpo...
FCRAemployment screeningconsumer reportstandalone notice - Question #145Workplace Privacy
SCENARIO Please use the following to answer the next question: Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to th...
biometric dataIllinois BIPAworkplace surveillancestate biometric laws - Question #146Government and Court Access to Private-Sector Information
SCENARIO Please use the following to answer the next question: Jane is a U.S. citizen and a senior software engineer at California-based Jones Labs, a major software supplier to th...
FISAgovernment surveillanceelectronic communicationsforeign intelligence - Question #147Sector-Specific Laws
According to the Family Educational Rights and Privacy Act (FERPA). when can a school disclose records without a student's consent?
FERPAstudent recordsconsent exceptionseducational records - Question #148Limits on Private-Sector Collection and Use of Data
A software company wants to use web scraping to collect personal data from professional networking websites in order to train an artificial intelligence program to evaluate Job app...
web scrapingAI training dataPII minimizationlegal liability - Question #149Limits on Private-Sector Collection and Use of Data
Due to cookie deprecation, businesses will be required to simplify their tracking practices by doing what?
cookie deprecationthird-party cookiestracking practicesdata minimization - Question #150Government and Court Access to Private-Sector Information
The Clarifying Lawful Overseas Use of Data (CLOUD) Act is primarily intended to do which of the following?
CLOUD Actlaw enforcement data accesscross-border dataoverseas data requests