CIPP-US Exam Questions
225 real CIPP-US exam questions with expert-verified answers and explanations. Page 4 of 5.
- Question #151Sector-Specific Laws
Which of the following most accurately describes the regulatory status ot pandemic contact- tracing apps in the United States?
contact tracinghealth appsregulatory patchworkpandemic privacy - Question #152State Privacy Laws
Which power was NOT granted to the California Privacy Protection Agency by the California Privacy Rights Act (CPRA)?
CPRACalifornia Privacy Protection AgencyCCPA enforcementregulatory authority - Question #153State Privacy Laws
Which of the following data elements is most likely to be subject to comprehensive state data security and privacy laws?
state data security lawsSSN protectionfinancial datacovered data elements - Question #154Health, Financial & Marketing Privacy
More than half of U S. states require telemarketers to do which of the following?
telemarketingstate registrationmarketing regulationsstate requirements - Question #155Workplace Privacy
In the US, II is a best practice (and in some states a requirement) to conduct a data protection assessment in which instance?
data protection assessmentemployee monitoringworkplace surveillancestate requirements - Question #156State Privacy Laws
What is the purpose of a cure provision in a stale data privacy law?
cure provisionstate privacy enforcementviolation remediationcompliance timeframe - Question #157Introduction to the US Privacy Environment
Which of the following definitions best defines privacy as cited in the text and related to privacy law?
privacy definitionindividual autonomyfoundational conceptsprivacy law - Question #158Government Enforcement
In most cases, the FTC settles disputes through consent decrees and consent orders. What is the maximum length of a consent decree?
FTCconsent decreeenforcement durationFTC Act - Question #159Introduction to the US Privacy Environment
Which step in developing an Information Management Program involves distributing privacy policies and privacy notices?
information management programprivacy noticesprivacy policiesprogram lifecycle - Question #160Introduction to the US Privacy Environment
Regarding data information management, which of the following tasks can help with compliance audits, quickly comply with legal discovery requests, and ensure data is stored efficie...
data classificationcompliance auditlegal discoverydata management - Question #161Introduction to the US Privacy Environment
Which of the following would NOT fall under the jurisdiction of the GDPR?
GDPRterritorial jurisdictionEU privacy lawinternational scope - Question #162Data Breaches
Which form of malicious online threat targets an individual user and pretends to be a legitimate party, such as a bank, to steal personal data?
spear phishingsocial engineeringphishing attackscybersecurity threats - Question #163Health, Financial & Marketing Privacy
Which of the following entities is the PRIMARY enforcer of the HIPAA Privacy Rule and can assess civil monetary penalties?
HIPAAPrivacy RuleOffice for Civil Rightscivil monetary penalties - Question #164Government Enforcement
Which jurisdiction must courts have in order to hear a particular case?
personal jurisdictionsubject matter jurisdictioncourt jurisdictionlegal procedure - Question #165Sector-Specific Laws
Which authority supervises and enforces laws regarding advertising to children via the Internet?
COPPAFTCchildren's online privacyinternet advertising - Question #166Government Enforcement
According to Section 5 of the FTC Act, self-regulation primarily involves a company's right to do what?
FTC Act Section 5self-regulationindustry code of conductunfair practices - Question #167Government Enforcement
Which was NOT one of the five priority areas listed by the Federal Trade Commission in its 2012 report, "Protecting Consumer Privacy in an Era of Rapid Change: Recommendations for...
FTC 2012 reportconsumer privacyprivacy policy prioritiesDo Not Track - Question #168Introduction to the US Privacy Environment
The "Consumer Privacy Bill of Rights" presented in a 2012 Obama administration report is generally based on?
Consumer Privacy Bill of Rightsfair information practicesObama administrationprivacy framework - Question #169Government Enforcement
What is a legal document approved by a judge that formalizes an agreement between a governmental agency and an adverse party called?
consent decreejudicial agreementregulatory settlementFTC enforcement - Question #170Introduction to the US Privacy Environment
Read this notice: Our website uses cookies. Cookies allow us to identify the computer or device you're using to access the site, but they don't identify you personally. For instruc...
cookiesimplied consentopt-outnotice - Question #171Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical...
privacy programdata securitypersonal informationorganizational governance - Question #172Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical...
privacy programpolicy implementationcompliance riskunrealistic goals - Question #173Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical...
privacy policyimplementation consistencyorganizational governanceprivacy program - Question #174Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: Cheryl is the sole owner of Fitness Coach, Inc., a medium-sized company that helps individuals realize their physical...
privacy program developmentinformation governanceorganizational privacyconsultant role - Question #175Introduction to the US Privacy Environment
According to the FTC Report of 2012, what is the main goal of Privacy by Design?
Privacy by DesignFTCprivacy frameworkdevelopment process - Question #176Introduction to the US Privacy Environment
What is the main reason some supporters of the European approach to privacy are skeptical about self- regulation of privacy practices?
self-regulationEuropean privacyindustry enforcementregulatory framework - Question #177Health, Financial & Marketing Privacy
Which legislation provides privacy provisions for the exemption of disclosure of certain biomedical information, securing remote access to view PHI, prohibiting the blocking of inf...
21st Century Cures ActPHIhealth privacybiomedical information - Question #178Health, Financial & Marketing Privacy
Who is responsible for notifying consumers when adverse action is taken based on information in a consumer credit report?
FCRAadverse actioncredit reportconsumer notification - Question #179Health, Financial & Marketing Privacy
Which two FCRA rules were added with the Fair and Accurate Credit Transitions Act in 2003?
FACTADisposal RuleRed Flags RuleFCRA - Question #180Sector-Specific Laws
According to the Children's Online Privacy Protection Rule, all the following would be considered personal information EXCEPT:
COPPApersonal information definitionchildren's privacystreaming services - Question #181Sector-Specific Laws
Which statement is TRUE regarding Sarah and Robert under COPPA?
COPPAage thresholdapplicabilitychildren's privacy - Question #182Sector-Specific Laws
One of Don's concerns is the easy access to pornography on the internet today. He does not want his children viewing pornography either purposely or accidentally. Which statement i...
COPPAparental controlschild protectiononline content - Question #183Sector-Specific Laws
Don understands that some location-based services simply enhance the user experience. Others, such as daily fantasy sports applications that allow sports betting, require that loca...
location-based serviceschildren's privacyparental controlsmobile devices - Question #184Sector-Specific Laws
Robert has been having some arguments with another boy at school. The other boy has posted a picture semi-nude picture of Robert on social media that he took in the boy's locker ro...
COPPAsocial media content removalminor's privacyFTC enforcement - Question #185Introduction to the US Privacy Environment
What is the main purpose of the Global Privacy Enforcement Network?
Global Privacy Enforcement Networkinternational cooperationprivacy authoritiesenforcement - Question #186Sector-Specific Laws
In 2014, Google was alleged to have violated the Family Educational Rights and Privacy Act (FERPA) through its Apps for Education suite of tools. For what specific practice did stu...
FERPAGoogle Apps for Educationemail scanningstudent records - Question #187Government Enforcement
Which venture would be subject to the requirements of Section 5 of the Federal Trade Commission Act?
FTC Act Section 5commercial activitiesunfair deceptive practicesFTC jurisdiction - Question #188Introduction to the US Privacy Environment
An organization self-certified under Privacy Shield must, upon request by an individual, do what?
Privacy Shieldself-certificationthird-party disclosureindividual rights - Question #189Government Enforcement
Which of the following federal agencies does NOT enforce the Disposal Rule under the Fair and Accurate Credit Transactions Act (FACTA)?
FACTADisposal Ruleenforcement agenciesHHS exemption - Question #190Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent le...
data flow diagramsEU-US data transfersupervisory authority investigationcross-border data transfer - Question #191Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent le...
EU-US data transferinvestigation evidencemarketing personnel interviewssupervisory authority - Question #192Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent le...
data processordata controllerGDPR rolesEU-US data transfer - Question #193Introduction to the US Privacy Environment
SCENARIO Please use the following to answer the next question: A US-based startup company is selling a new gaming application. One day, the CEO of the company receives an urgent le...
right to be forgottenGDPRdata subject rightsEU data protection - Question #194Health, Financial & Marketing Privacy
Which of the following requires financial institutions to maintain security controls to protect personal consumer information for both electronic and paper records, and requires in...
Safeguards RuleGLBAfinancial institution securityinformation security program - Question #195Health, Financial & Marketing Privacy
General health records data for private schools who accept no federal funding are subject to:
HIPAAprivate school health recordscovered entitiesFERPA - Question #196Health, Financial & Marketing Privacy
The criteria for an existing business relationship, as defined by TSR, includes:
Telemarketing Sales Ruleexisting business relationshipTSRtelemarketing - Question #197Health, Financial & Marketing Privacy
Who has the right to private action regarding violations of the CAN-SPAM Act?
CAN-SPAM Actprivate actionunsolicited emailISP rights - Question #198Health, Financial & Marketing Privacy
What was the primary reason for the creation of HIPAA?
HIPAAelectronic healthcare paymentslegislative historyhealthcare efficiency - Question #199Health, Financial & Marketing Privacy
Lawrence works for a healthcare provider, which of the following healthcare entities covered by HIPAA (prior to HITECH) includes third-party organizations that host, handle, or pro...
HIPAA covered entitieshealthcare clearinghousesbusiness associatesHITECH - Question #200Health, Financial & Marketing Privacy
Which of the following scenarios would NOT be covered under HIPAA?
HIPAA coveragecovered entitiesPHIhealthcare providers